CVE-2026-47162: Vim netrw Code Injection Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-47162 is a code injection vulnerability in Vim’s netrw plugin, specifically within the NetrwBookHistSave() function. A crafted directory name can trigger arbitrary Vimscript execution, potentially allowing an attacker to run malicious code in the context of the user running Vim. This is relevant to cloud environments where Vim is commonly used on Linux-based virtual machines and containers for editing configuration files. Security Architect’s Take: Audit your Linux VM and container base images to identify Vim versions in use and apply vendor patches promptly. Consider enforcing policy to restrict or replace Vim with minimal editors in production environments where netrw functionality is unnecessary, reducing the attack surface. ...

13 June 2025 Â· ZX Cloud Security

CVE-2026-47167: Vim Vimscript Code Injection Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-47167 is a code injection vulnerability in Vim’s built-in cucumber filetype plugin, where a specially crafted step-definition regular expression can trigger arbitrary Vimscript execution. This affects developers and engineers who open untrusted files in Vim, potentially allowing an attacker to execute code in the context of the user’s session. While not directly an Azure service vulnerability, Microsoft has published this advisory likely due to its relevance to Azure developer tooling and cloud-hosted development environments. ...

13 June 2025 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. Learn more