CVE detail
CVE-2026-34714
Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 25.6 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
12 source links · newest first
- CVE-2026-34714Microsoft MSRC
Information published.
vendormsrc.microsoft.comApr 8, 2026, 8:37 AM Developers can spend days using fuzzing tools to find security weaknesses in code. Alternatively, they can simply ask an LLM to do the job for them in seconds. The catch: LLMs are evolving so rapidly that this convenience might come with hidden dangers. The latest example is from researcher Hung Nguyen from AI red teaming […]
newswww.csoonline.comApr 1, 2026, 5:51 PM- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34714.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comMar 30, 2026, 7:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2453139bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comMar 30, 2026, 7:16 PM - https://access.redhat.com/security/cve/CVE-2026-34714access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 30, 2026, 7:16 PM - http://www.openwall.com/lists/oss-security/2026/04/03/6www.openwall.com
No excerpt available.
Exploitwww.openwall.comMar 30, 2026, 7:16 PM - http://www.openwall.com/lists/oss-security/2026/04/02/5www.openwall.com
No excerpt available.
Exploitwww.openwall.comMar 30, 2026, 7:16 PM - http://www.openwall.com/lists/oss-security/2026/04/02/4www.openwall.com
No excerpt available.
Exploitwww.openwall.comMar 30, 2026, 7:16 PM - https://www.openwall.com/lists/oss-security/2026/03/30/3www.openwall.com
No excerpt available.
Exploitwww.openwall.comMar 30, 2026, 7:16 PM No excerpt available.
Exploitgithub.comMar 30, 2026, 7:16 PMNo excerpt available.
Exploitgithub.comMar 30, 2026, 7:16 PMNo excerpt available.
Exploitgithub.comMar 30, 2026, 7:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-55895CVSS 5.7 · Medium
Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s:NetrwLocalRmFile() in the netrw plugin (runtime/pack/dist/…
- CVE-2026-46483CVSS 3.6 · Low
Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimuntar() in runtime/autoload/tar.vim when decompressing .tgz…
- CVE-2026-44656CVSS 4.6 · Medium
Vim is an open source, command line text editor. Prior to version 9.2.0435, an OS command injection vulnerability exists in Vim's :find command-line completion. When the path opti…
- CVE-2026-42307CVSS 4.4 · Medium
Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists in the netrw standard plugin bundled with Vim. By inducing…
- CVE-2026-41411CVSS 6.6 · Medium
Vim is an open source, command line text editor. Prior to 9.2.0357, A command injection vulnerability exists in Vim's tag file processing. When resolving a tag, the filename field…
- CVE-2026-34982CVSS 8.2 · High
Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file…