Cyber Resilience
← All news

[UPDATE] [hoch] Evince: Schwachstelle ermöglicht Codeausführung

CERT-Bund rates a code-execution flaw in Evince high (WID-SEC-2026-1641). Patch when your Linux distro ships the fix — GNOME desktop users in any size shop are in scope.
Sources (19)
What this means for you — CISO:Review CERT-Bund WID-SEC-2026-1641 (Evince) and WID-SEC-2026-2300 (RHEL plexus-utils) and patch affected Linux desktop and RHEL systems where those components are deployed.
What this means for you — Lean IT orgs:If you run Linux desktops with Evince or Red Hat Enterprise Linux, apply the available updates; Windows/macOS or cloud-only setups are unaffected.
What this means for you — MSP:Inventory client estates for Evince on Linux workstations and RHEL hosts with plexus-utils; schedule the vendor updates where present.
What this means for you — Researcher:CERT-Bund flags remote code execution in Evince and user-rights code execution via plexus-utils on RHEL — see WID-SEC-2026-1641 and WID-SEC-2026-2300 for advisory detail.