Get real-time updates on Telegram
CVE-2026-27739: @angular-devkit/build-angular (exact versions not specified); +10 more affected products
CVE-2026-27739 affects @angular-devkit/build-angular. EPSS 0.00516 (percentile 0.41854), scored 2026-10-05. Fixed version: 18.2.21-tuxcare.2. Fixed version: 18.2.21-tuxcare.2. Fixed version: 18.2.21-tuxcare.2. Fixed version: 18.2.21-tuxcare.2. Fixed version: 18.2.21-tuxcare.2. Fixed version: 18.2.21-tuxcare.2. Fixed version: 18.2.21-tuxcare.2. Fixed version: 18.2.21-tuxcare.2. Fixed version: 18.2.21-tuxcare.2. Fixed version: 18.2.21-tuxcare.2. Fixed version: 18.2.21-tuxcare.2. Fixed version: 17.3.17-tuxcare.3. Fixed version: 17.3.17-tuxcare.3. Fixed version: 17.3.17-tuxcare.3.
Affected technology
@angular-devkit/build-angular · Exact affected versions not specified by the source
Vendor not specified by the source
@angular-devkit/core · Exact affected versions not specified by the source
Vendor not specified by the source
@angular-devkit/schematics · Exact affected versions not specified by the source
Vendor not specified by the source
@angular-devkit/schematics-cli · Exact affected versions not specified by the source
Vendor not specified by the source
@angular/build · Exact affected versions not specified by the source
Vendor not specified by the source
@angular/cli · Exact affected versions not specified by the source
Vendor not specified by the source
@angular/create · Exact affected versions not specified by the source
Vendor not specified by the source
@angular/pwa · Exact affected versions not specified by the source
Vendor not specified by the source
@angular/ssr · Exact affected versions not specified by the source
Vendor not specified by the source
@ngtools/webpack · Exact affected versions not specified by the source
Vendor not specified by the source
@schematics/angular · Exact affected versions not specified by the source
Vendor not specified by the source
@angular-devkit/build-angular · Exact affected versions not specified by the source
Vendor not specified by the source
@angular-devkit/core · Exact affected versions not specified by the source
Vendor not specified by the source
@angular-devkit/schematics · Exact affected versions not specified by the source
Vendor not specified by the source
@angular-devkit/schematics-cli · Exact affected versions not specified by the source
Vendor not specified by the source
@angular/cli · Exact affected versions not specified by the source
Vendor not specified by the source
@angular/create · Exact affected versions not specified by the source
Vendor not specified by the source
@angular/pwa · Exact affected versions not specified by the source
Vendor not specified by the source
@angular/ssr · Exact affected versions not specified by the source
Vendor not specified by the source
@ngtools/webpack · Exact affected versions not specified by the source
Vendor not specified by the source
@schematics/angular · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
What an attacker can do
The source does not specify what an attacker can achieve.
- Product
- @angular-devkit/build-angular
- CCR priority
- 0.1 /100 (P5)
- EPSS
- 0.00516 · percentile 0.41939 · 2026-10-06
- KEV
- no
Provenance
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-07 11:53:15.413517+00:00 UTC
- OSV.dev · Source record · observed 2026-10-07 03:19:31.921362+00:00 UTC
- OSV.dev · Source record · observed 2026-10-07 03:19:31.921362+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-27739.html