
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0777 is a remote code execution vulnerability in Xmind caused by insufficient UI warning when handling attachments, classified under CWE-356 (Product UI does not Warn User of Unsafe Actions). It was reported to the vendor on September 22, 2025, and publicly disclosed as a 0-day advisory by the Zero Day Initiative (ZDI) on February 6, 2026, after the vendor failed to respond adequately. The vulnerability was subsequently mitigated in Xmind version 26.02, confirmed by the vendor on February 10, 2026. It carries a CVSS v3.0 base score of 7.8 (High) (ZDI Advisory).
The root cause of this vulnerability (CWE-356) lies in Xmind's attachment handling logic, where the application's user interface fails to present any warning or confirmation prompt when a user opens a potentially unsafe attachment embedded in a malicious Xmind file or accessed via a malicious page. An attacker crafts a malicious Xmind file or web page containing a dangerous attachment; when the victim opens it, the lack of UI safeguards allows the attachment to execute arbitrary code silently in the context of the current user. No privileges are required on the attacker's side, but user interaction — specifically opening the malicious file or visiting the malicious page — is a prerequisite for exploitation (ZDI Advisory).
Successful exploitation grants an attacker arbitrary code execution in the context of the currently logged-in user, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker could read sensitive files, modify or delete data, install malware, or use the compromised endpoint as a pivot point for lateral movement within a network. The scope is limited to the local user context, but the breadth of damage depends on the victim's privileges (ZDI Advisory).
This vulnerability was published as a 0-day advisory by ZDI on February 6, 2026, after the vendor did not provide a timely fix during the coordinated disclosure window. No public exploit code or weaponized exploit kit has been confirmed; the ZDI advisory itself does not contain reproduction steps or exploit code. The EPSS score is 0.061% (low probability of near-term exploitation), and there is no evidence of in-the-wild exploitation or CISA KEV catalog listing as of the time of this report. The vulnerability was discovered and reported by researcher AspiringYoungMan (ZDI Advisory).
%APPDATA%, %TEMP%, or equivalent directories on macOS/Linux.cmd.exe, powershell.exe, bash, python, or other interpreters) shortly after opening a .xmind file.The vendor confirmed that the vulnerability was mitigated in Xmind version 26.02, released on or around February 10, 2026; users should update to this version or later immediately via the official download page at https://xmind.com/download. As a temporary workaround prior to patching, ZDI recommends restricting interaction with the Xmind application and avoiding opening Xmind files from untrusted or unknown sources. Organizations should also consider applying application allowlisting to prevent unauthorized code execution from within productivity applications (ZDI Advisory).
The vulnerability was covered by several security news aggregators and community platforms including VulDB, Systemtek, and The Hacker Wire following the ZDI 0-day disclosure. A Loginsoft threat intelligence roundup on Medium referenced the vulnerability as part of the week's notable zero-day disclosures. Social media posts on Mastodon and Bluesky by The Hacker Wire noted the 0-day status of the advisory. No formal vendor public statement beyond the private confirmation to ZDI has been identified (ZDI Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."