Michał Majchrowicz discovered that Vim's zip plugin could overwrite arbitrary files. An attacker could possibly use this issue to delete sensitive data or execute arbitrary code. This issue only affected Ubuntu 24.04 LTS and Ubuntu 25.10. (CVE-2026-35177)
It was discovered that Vim's netbeans interface did not properly sanitize certain strings. An attacker could possibly use this issue to execute arbitrary commands. (CVE-2026-39881)
2:8.2.3995-1ubuntu2.282:9.1.0016-1ubuntu7.122:9.1.0967-1ubuntu6.32:7.4.052-1ubuntu3.1+esm252:7.4.1689-3ubuntu1.5+esm312:8.0.1453-1ubuntu1.13+esm162:8.1.2269-1ubuntu5.32+esm4