CVE-2026-96269
GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symbol-shorthands affects the intern and unintern functions. This affects the default configuration; no particular user settings are required to trigger it.
- Published Sep 22, 2026
- CVSS 7.5 high
- 0.1% chance of exploitation in the next 30 days (EPSS)