Skip to content

CVE-2026-72718

CVE

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
September 2, 2026
Last Seen
September 27, 2026
API
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A critical arbitrary command execution vulnerability (CVE-2026-72718) has been identified in the Goose CLI tool used in Fedora 43, 44, and 45. The flaw allows attackers to execute arbitrary commands via the `goose review` command. CISA has confirmed that this vulnerability is being actively exploite...

A series of vulnerabilities, termed GitSpawn, have been disclosed affecting multiple AI coding agents, including Claude Code, Codex, and Cursor. These flaws allow malicious Git configurations to execute arbitrary code on a developer's machine without user interaction or approval. The vulnerabilities...

Public Exploits

Checking GitHub for proof-of-concept code…