github.com RCE Vulnerability in Knowns LSP Configuration
Article Content
- •CVE-2026-86540 allows arbitrary code execution via insecure LSP configuration.
- •Vulnerability affects any project using Knowns LSP with unvalidated binary paths.
- •No active exploitation reported, but the vulnerability is critical with a CVSS of 8.5.
An Arbitrary Code Execution (ACE) vulnerability, CVE-2026-86540, has been identified in the Knowns Language Server Protocol (LSP) detection pipeline. The flaw arises from the system's failure to validate the.binary field in the.knowns/config.json file, allowing execution of attacker-controlled binaries. This vulnerability can be exploited by opening a malicious or compromised repository, leading to immediate execution of malicious code. The payload is executed twice per session, enabling a fully unauthenticated Remote Code Execution chain when combined with existing Config Overwrite vulnerabilities. The vulnerability is categorized as due to its potential for, with a CVSS score of 8.5. As of now, there are no reports of in the wild, but the flaw remains. Security professionals are advised to review their configurations and apply necessary mitigations.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-86540 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What systems are affected?
Is there a patch available?
How can I mitigate this vulnerability?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…