Exploitation timeline
Threadlinqs has recorded 8 Canonical CVEs published between and . The busiest month was 2026-07 (2 new CVEs). 5 of them (63%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 8 of 8 tracked Canonical CVEs.
- CVE-2022-0543critical 10KEVRansomwareEPSS 94.4%
- CVE-2020-1472medium 5.5KEVRansomwareEPSS 94.4%
- CVE-2016-5195high 7KEVRansomwareEPSS 93.9%
- CVE-2021-4034high 7.8KEVEPSS 87.8%
- CVE-2023-0386high 7.8KEVEPSS 7.9%
- CVE-2026-11386critical 9EPSS 0.3%
- CVE-2026-77113medium 6.7EPSS 0.2%
- CVE-2026-8933high 7.8EPSS 0.1%
Products affected
Threadlinqs normalises CPE and CNA product records across all 8 CVEs; 10 distinct Canonical products are affected. The most frequently affected:
- Ubuntu Linux 5 CVEs
- Ubuntu 22.04 LTS 2 CVEs
- Ubuntu 24.04 LTS 2 CVEs
- Ubuntu 26.04 LTS 2 CVEs
- Apport 1 CVE
- Ubuntu 14.04 LTS 1 CVE
- Ubuntu 16.04 LTS 1 CVE
- Ubuntu 18.04 LTS 1 CVE
- Ubuntu 20.04 LTS 1 CVE
- ubuntu-pro-client (ubuntu-advantage-tools) 1 CVE
Threat activity
45 tracked threat campaigns reference Canonical products or exploit Canonical CVEs; the 25 most recent are listed.
- CVE-2025-39682 — Linux Kernel net/tls rx_list Zero-Length Record Use-After-Free Added to CISA KEV CatalogCRITICAL
- "LPE Quartet": Public Exploits Released for Four Linux Kernel Local-Root Flaws (DirtyAH6, TUNderflow, PPPoEject, DiagSpill)HIGH
- Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling ObservedHIGH
- Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged)HIGH
- CVE-2025-37947: Out-of-Bounds Write in Linux ksmbd Kernel SMB Server Enables Local Privilege EscalationHIGH
- Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)CRITICAL
- EtherHiding: Blockchain-Based C2 on Polygon Fuels ClickFix Backdoor + Banking-Trojan Extension Campaign Adopted by Criminal, North Korean, and Iran-Linked ActorsHIGH
- Rhysida Ransomware Claims Berlin State Government Breach Ahead of September ElectionHIGH
- LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)HIGH
- SCTPhantom (CVE-2026-64564): 18-Year-Old Use-After-Free in Linux Kernel SCTP ASCONF Handling Enables Local Privilege EscalationHIGH
- OVSWrap (CVE-2026-64531): Linux kernel Open vSwitch datapath 16-bit nla_len wraparound local privilege escalation with public PoC targeting ~800 x86-64 kernel buildsHIGH
- CVE-2026-31431: Linux Local Privilege Escalation Actively Exploited by UMBRAL BISON Within 24 Hours of DisclosureHIGH
- CVE-2026-53264: AI-Assisted Discovery of Linux Kernel net/sched Use-After-Free Enabling Local Root Privilege EscalationHIGH
- CVE-2026-8933: Race Condition in Ubuntu snap-confine Enables Local Privilege Escalation to RootHIGH
- Critical Ubuntu Pro Client Vulnerability Enables Root Code Execution via Contract Server Spoofing (CVE-2026-11386)CRITICAL
- F5OS / Traffix SDC Information Disclosure (CVE-2026-46333) — Linux Kernel ptrace/pidfd_getfd Race Condition, Public PoC (CHARON)HIGH
- CVE-2026-46215: Linux Kernel DRM GEM_CHANGE_HANDLE Use-After-Free Local Root Privilege EscalationHIGH
- Forgotten UEFI Shims Undermine Secure Boot (CVE-2026-8863, CVE-2026-10797)HIGH
- Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate DDoS, Hack-and-Leak, and Credential-Theft Campaigns (Handala, 313 Team, Cyber Fattah, Dark Storm, Keymous+, and Affiliated Personas)MEDIUM
- Linux Kernel FUSE Page-Cache Buffer Overflow (CVE-2026-31694) Enables Local Privilege EscalationHIGH
- CVE-2026-53359 ("Januscape") - 16-Year-Old Linux KVM Shadow MMU Use-After-Free Exploited as Zero-DayHIGH
- DirtyClone Linux Kernel Local Privilege Escalation via __pskb_copy_fclone() (CVE-2026-43503)HIGH
- Linux Kernel act_pedit COW Out-of-Bounds Write Enables Local Privilege Escalation to Root (CVE-2026-46331)HIGH
- DirtyClone (CVE-2026-43503): Linux Kernel Packet-Cloning Page-Cache Write Enables Local Privilege Escalation to Root via IPsec ESPHIGH
- Linux Kernel act_pedit Partial Copy-on-Write Page-Cache Corruption Local Privilege Escalation (CVE-2026-46331, "pedit COW")HIGH
Threat actors targeting Canonical
Named threat actors attributed to campaigns that involve Canonical products or CVEs, with the number of linked campaigns:
How to prioritise Canonical patching
This order follows the data Threadlinqs holds for Canonical, not a generic severity checklist:
- 5 of 8 Canonical CVEs (63%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2022-0543, CVE-2020-1472, CVE-2016-5195.
- 3 CVEs are known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are CVE-2026-11386 (0.3%), CVE-2026-77113 (0.2%), CVE-2026-8933 (0.1%).
- 2 CVEs score Critical and 4 High on CVSS v3 (maximum 10, average 7.7); sequence these after KEV and high-EPSS items.
- 1 CVE has a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.