CVE•Published 2026-05-22•Modified 2026-07-23•1 article on news•4 live references•NVD data
CVE-2026-9264
Vulnerability data via NVD (ingested)
CVSS v3.1
9.3
CRITICAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS percentile
14
Exploit Prediction Scoring System · top 86% of all CVEs
Weaknesses (CWE)
Description
A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through maliciously crafted SKP files. The vulnerability stems from improper input sanitization in the component options window, enabling attackers to execute arbitrary system commands and read local files without user interaction by exploiting an embedded Internet Explorer 11 browser.
Timeline
Published 2026-05-22
Modified 2026-07-23
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
More intel sources (5)
Shodan report
vuln:CVE-2026-9264Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2026-9264Censys host search filtered to this CVE id.
grep.app
CVE-2026-9264Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2026-9264GitHub code search for direct mentions.
Google dork
"CVE-2026-9264" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.
Known PoCs on GitHub (8)
CVE-2026-92648 repos
lintsinghua/DeepAuditPython
DeepAudit:人人拥有的 AI 黑客战队,让漏洞挖掘触手可及。国内首个开源的代码漏洞挖掘多智能体系统。小白一键部署运行,自主协作审计 + 自动化沙箱 PoC 验证。支持 Ollama 私有部署 ,一键生成报告。支持中转站。让安全不再昂贵,让审计不再复杂。
Threekiii/Awesome-POCJava
一个漏洞 PoC 知识库。A knowledge base for vulnerability PoCs(Proof of Concept), with 1k+ vulnerabilities.
eeeeeeeeee-code/POCunknown
备份的漏洞库,3月开始我们来维护
zulloper/cve-pocPython
CVE POC repo 자동 수집기
trganda/starrlistPython
List of awesome starred repositories
GODofExploit/exploit-arsenalPython
420 standalone Python-3 (stdlib-only) CVE exploits, each live-validated end-to-end against real vulnerable software with a write-up and a real-run screenshot. 102 in the CISA KEV c…
opendr-io/causalityJupyter Notebook
The difference between exploitation prediction and detection is akin to the difference between detecting a missile launch or a detonation. Every avoided exploitation cycle saves hu…
J1ezds/Vulnerability-Wiki-pageHTML
这是一个每天同步Vulnerability-Wiki中docs-base中内容的项目