CVE-2026-79079
An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components
- Published Sep 21, 2026
- CVSS 7.8 high
- 0.2% chance of exploitation in the next 30 days (EPSS)