Skip to content

Data collected

CVEs Live

Linux vulnerabilities exploited in the wild

The Linux CVEs that CISA lists as exploited, newest first. Only confirmed exploitation appears here, each with its EPSS and the CVSS as published.

Build snapshot collected · KEV catalog 2026.10.02 · EPSS of 2 Oct 2026 · not a live feed: collected once, at build time

31
flaws with confirmed attacks
2
used by ransomware
1.8%
of the whole catalog

12 vulnerabilities · newest first.Showing the entries bundled with this page while the full catalog loads.

RSS of KEV additions
  1. CVE-2025-39682Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Linux · Kernel

    Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · NVD

    Attack probability (EPSS)

    2.88%86th pct

    KEV dates

    added due
  2. CVE-2025-39964Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Linux · Kernel

    Linux Kernel Race Condition Vulnerability

    Severity

    5.5MEDIUMCVSS 3.1 · NVD

    Attack probability (EPSS)

    1.00%61th pct

    KEV dates

    added due
  3. CVE-2026-53266Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Linux · Kernel

    Linux Kernel Out-of-Bounds Write Vulnerability

    Severity

    8.8HIGHCVSS 3.1 · 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Attack probability (EPSS)

    0.83%56th pct

    KEV dates

    added due
  4. CVE-2026-53362Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Linux · Kernel

    Linux Kernel Unspecified Vulnerability

    Severity

    7.8HIGHCVSS 3.1 · 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Attack probability (EPSS)

    0.71%52th pct

    KEV dates

    added due
  5. CVE-2022-0995Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Linux · Kernel

    Linux Kernel Out-of-Bounds Write Vulnerability

    Severity

    7.8HIGHCVSS 3.1 · NVD

    Attack probability (EPSS)

    8.79%95th pct

    KEV dates

    added due
  6. CVE-2022-0492Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Linux · Kernel

    Linux Kernel Improper Authentication Vulnerability

    Severity

    7.8HIGHCVSS 3.1 · NVD

    Attack probability (EPSS)

    5.53%93th pct

    KEV dates

    added due
  7. CVE-2026-31431Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Linux · Kernel

    Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability

    Severity

    7.8HIGHCVSS 3.1 · 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Attack probability (EPSS)

    3.44%89th pct

    KEV dates

    added due
  8. CVE-2018-14634Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Linux · Kernel

    Linux Kernel Integer Overflow Vulnerability

    Severity

    7.8HIGHCVSS 3.0 · NVD

    Attack probability (EPSS)

    14.7%97th pct

    KEV dates

    added due
  9. CVE-2021-22555Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Linux · Kernel

    Linux Kernel Heap Out-of-Bounds Write Vulnerability

    Severity

    7.8HIGHCVSS 3.1 · NVD

    Attack probability (EPSS)

    78.7%99.6th pct

    KEV dates

    added due
  10. CVE-2025-38352Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Linux · Kernel

    Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability

    Severity

    7.8HIGHCVSS 3.1 · 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Attack probability (EPSS)

    1.29%69th pct

    KEV dates

    added due
  11. CVE-2023-0386Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Linux · Kernel

    Linux Kernel Improper Ownership Management Vulnerability

    Severity

    7.8HIGHCVSS 3.1 · NVD

    Attack probability (EPSS)

    7.88%95th pct

    KEV dates

    added due
  12. CVE-2024-53197Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Linux · Kernel

    Linux Kernel Out-of-Bounds Access Vulnerability

    Severity

    7.8HIGHCVSS 3.1 · CISA-ADP

    Attack probability (EPSS)

    3.56%89th pct

    KEV dates

    added due

Linux products in the catalog

Among the most recent entries, the products that appear most often are:

  • Kernel12 entries

Product names are the ones CISA uses in the catalog. To check a specific Linux CVE that is not on this page, use the CVE lookup: it shows the record, the affected versions and the EPSS score even when the CVE is not in KEV.

Fixed versions and workarounds are published by the vendor: linux-cve-announce mailing list.

Other vendors

Questions

How many Linux vulnerabilities are known to be exploited?

The CISA KEV catalog, version 2026.10.02, lists 31 Linux vulnerabilities as of 3 Oct 2026. CISA marks 2 of them as known to be used in ransomware campaigns.

What is the most recent Linux entry in KEV?

CVE-2025-39682 (Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability), added on 18 Sep 2026 with a due date of 21 Sep 2026 for US federal agencies, as of the collection of 3 Oct 2026.

Does this page list every Linux CVE?

No. It lists only the Linux CVEs that CISA has confirmed as exploited. Linux publishes many more CVEs that are not in KEV; look up any of them by identifier in the CVE lookup to see its record and EPSS score.

In what order should Linux vulnerabilities be patched?

Everything on this page is already confirmed as exploited, so all of it is urgent where the product is in use. Within the list, entries marked with known ransomware use and those with the highest EPSS come first in the "Risk" order; internet-facing systems should go before internal ones.

Related sections