# Canonical vulnerabilities & exploitation

**CISA KEV** · **Ransomware**

> As of 2026-10-05, Threadlinqs tracks 8 Canonical CVEs, 5 in the CISA Known Exploited Vulnerabilities catalog, 3 used in ransomware campaigns, linked to 45 tracked threat campaigns and 10 named threat actors.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 8 Canonical CVEs published between 2016-11-15 and 2026-08-15. The busiest month was 2026-07 (2 new CVEs). 5 of them (63%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 8 of 8 tracked Canonical CVEs.

- [CVE-2022-0543](https://intel.threadlinqs.com/cve/CVE-2022-0543) — CRITICAL 10 · KEV · Ransomware · EPSS 94.4% · 2022-02-18
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472) — MEDIUM 5.5 · KEV · Ransomware · EPSS 94.4% · 2020-08-17
- [CVE-2016-5195](https://intel.threadlinqs.com/cve/CVE-2016-5195) — HIGH 7 · KEV · Ransomware · EPSS 93.9% · 2016-11-10
- [CVE-2021-4034](https://intel.threadlinqs.com/cve/CVE-2021-4034) — HIGH 7.8 · KEV · EPSS 87.8% · 2022-01-28
- [CVE-2023-0386](https://intel.threadlinqs.com/cve/CVE-2023-0386) — HIGH 7.8 · KEV · EPSS 7.9% · 2023-03-22
- [CVE-2026-11386](https://intel.threadlinqs.com/cve/CVE-2026-11386) — CRITICAL 9 · EPSS 0.3% · 2026-07-16
- [CVE-2026-77113](https://intel.threadlinqs.com/cve/CVE-2026-77113) — MEDIUM 6.7 · EPSS 0.2% · 2026-08-20
- [CVE-2026-8933](https://intel.threadlinqs.com/cve/CVE-2026-8933) — HIGH 7.8 · EPSS 0.1% · 2026-07-21

## Products affected

Threadlinqs normalises CPE and CNA product records across all 8 CVEs; 10 distinct Canonical products are affected. The most frequently affected:

- Ubuntu Linux — 5 CVEs
- Ubuntu 22.04 LTS — 2 CVEs
- Ubuntu 24.04 LTS — 2 CVEs
- Ubuntu 26.04 LTS — 2 CVEs
- Apport — 1 CVE
- Ubuntu 14.04 LTS — 1 CVE
- Ubuntu 16.04 LTS — 1 CVE
- Ubuntu 18.04 LTS — 1 CVE
- Ubuntu 20.04 LTS — 1 CVE
- ubuntu-pro-client (ubuntu-advantage-tools) — 1 CVE

## Threat activity

45 tracked threat campaigns reference Canonical products or exploit Canonical CVEs; the 25 most recent are listed.

- [CVE-2025-39682 — Linux Kernel net/tls rx_list Zero-Length Record Use-After-Free Added to CISA KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2570) — CRITICAL — 2026-09-18
- ["LPE Quartet": Public Exploits Released for Four Linux Kernel Local-Root Flaws (DirtyAH6, TUNderflow, PPPoEject, DiagSpill)](https://intel.threadlinqs.com/threat/TL-2026-2572) — HIGH — 2026-09-18
- [Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observed](https://intel.threadlinqs.com/threat/TL-2026-2546) — HIGH — 2026-09-17
- [Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged)](https://intel.threadlinqs.com/threat/TL-2026-2514) — HIGH — 2026-09-15
- [CVE-2025-37947: Out-of-Bounds Write in Linux ksmbd Kernel SMB Server Enables Local Privilege Escalation](https://intel.threadlinqs.com/threat/TL-2026-2477) — HIGH — 2026-09-13
- [Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)](https://intel.threadlinqs.com/threat/TL-2026-2357) — CRITICAL — 2026-09-06
- [EtherHiding: Blockchain-Based C2 on Polygon Fuels ClickFix Backdoor + Banking-Trojan Extension Campaign Adopted by Criminal, North Korean, and Iran-Linked Actors](https://intel.threadlinqs.com/threat/TL-2026-2273) — HIGH — 2026-09-01
- [Rhysida Ransomware Claims Berlin State Government Breach Ahead of September Election](https://intel.threadlinqs.com/threat/TL-2026-2206) — HIGH — 2026-08-29
- [LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)](https://intel.threadlinqs.com/threat/TL-2026-2094) — HIGH — 2026-08-21
- [SCTPhantom (CVE-2026-64564): 18-Year-Old Use-After-Free in Linux Kernel SCTP ASCONF Handling Enables Local Privilege Escalation](https://intel.threadlinqs.com/threat/TL-2026-1949) — HIGH — 2026-08-09
- [OVSWrap (CVE-2026-64531): Linux kernel Open vSwitch datapath 16-bit nla_len wraparound local privilege escalation with public PoC targeting ~800 x86-64 kernel builds](https://intel.threadlinqs.com/threat/TL-2026-1887) — HIGH — 2026-08-05
- [CVE-2026-31431: Linux Local Privilege Escalation Actively Exploited by UMBRAL BISON Within 24 Hours of Disclosure](https://intel.threadlinqs.com/threat/TL-2026-1831) — HIGH — 2026-08-03
- [CVE-2026-53264: AI-Assisted Discovery of Linux Kernel net/sched Use-After-Free Enabling Local Root Privilege Escalation](https://intel.threadlinqs.com/threat/TL-2026-1744) — HIGH — 2026-07-28
- [CVE-2026-8933: Race Condition in Ubuntu snap-confine Enables Local Privilege Escalation to Root](https://intel.threadlinqs.com/threat/TL-2026-1633) — HIGH — 2026-07-22
- [Critical Ubuntu Pro Client Vulnerability Enables Root Code Execution via Contract Server Spoofing (CVE-2026-11386)](https://intel.threadlinqs.com/threat/TL-2026-1564) — CRITICAL — 2026-07-20
- [F5OS / Traffix SDC Information Disclosure (CVE-2026-46333) — Linux Kernel ptrace/pidfd_getfd Race Condition, Public PoC (CHARON)](https://intel.threadlinqs.com/threat/TL-2026-1503) — HIGH — 2026-07-18
- [CVE-2026-46215: Linux Kernel DRM GEM_CHANGE_HANDLE Use-After-Free Local Root Privilege Escalation](https://intel.threadlinqs.com/threat/TL-2026-1504) — HIGH — 2026-07-18
- [Forgotten UEFI Shims Undermine Secure Boot (CVE-2026-8863, CVE-2026-10797)](https://intel.threadlinqs.com/threat/TL-2026-1298) — HIGH — 2026-07-14
- [Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate DDoS, Hack-and-Leak, and Credential-Theft Campaigns (Handala, 313 Team, Cyber Fattah, Dark Storm, Keymous+, and Affiliated Personas)](https://intel.threadlinqs.com/threat/TL-2026-1309) — MEDIUM — 2026-07-14
- [Linux Kernel FUSE Page-Cache Buffer Overflow (CVE-2026-31694) Enables Local Privilege Escalation](https://intel.threadlinqs.com/threat/TL-2026-1177) — HIGH — 2026-07-10
- [CVE-2026-53359 ("Januscape") - 16-Year-Old Linux KVM Shadow MMU Use-After-Free Exploited as Zero-Day](https://intel.threadlinqs.com/threat/TL-2026-1189) — HIGH — 2026-07-10
- [DirtyClone Linux Kernel Local Privilege Escalation via __pskb_copy_fclone() (CVE-2026-43503)](https://intel.threadlinqs.com/threat/TL-2026-0962) — HIGH — 2026-06-27
- [Linux Kernel act_pedit COW Out-of-Bounds Write Enables Local Privilege Escalation to Root (CVE-2026-46331)](https://intel.threadlinqs.com/threat/TL-2026-0964) — HIGH — 2026-06-27
- [DirtyClone (CVE-2026-43503): Linux Kernel Packet-Cloning Page-Cache Write Enables Local Privilege Escalation to Root via IPsec ESP](https://intel.threadlinqs.com/threat/TL-2026-0947) — HIGH — 2026-06-26
- [Linux Kernel act_pedit Partial Copy-on-Write Page-Cache Corruption Local Privilege Escalation (CVE-2026-46331, "pedit COW")](https://intel.threadlinqs.com/threat/TL-2026-0951) — HIGH — 2026-06-26

## Threat actors targeting Canonical

Named threat actors attributed to campaigns that involve Canonical products or CVEs, with the number of linked campaigns:

- [Rhysida](https://intel.threadlinqs.com/actor/Rhysida) — 2 campaigns
- [Black Basta](https://intel.threadlinqs.com/actor/Black%20Basta) — 1 campaign
- [BlackBasta](https://intel.threadlinqs.com/actor/BlackBasta) — 1 campaign
- [Handala Hack](https://intel.threadlinqs.com/actor/Handala%20Hack) — 1 campaign
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 1 campaign
- [PCPJack](https://intel.threadlinqs.com/actor/PCPJack) — 1 campaign
- [Qilin](https://intel.threadlinqs.com/actor/Qilin) — 1 campaign
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 1 campaign
- [Vanilla Tempest](https://intel.threadlinqs.com/actor/Vanilla%20Tempest) — 1 campaign
- [Void Manticore](https://intel.threadlinqs.com/actor/Void%20Manticore) — 1 campaign

## How to prioritise Canonical patching

This order follows the data Threadlinqs holds for Canonical, not a generic severity checklist:

- 5 of 8 Canonical CVEs (63%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with [CVE-2022-0543](https://intel.threadlinqs.com/cve/CVE-2022-0543), [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472), [CVE-2016-5195](https://intel.threadlinqs.com/cve/CVE-2016-5195).
- 3 CVEs are known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are [CVE-2026-11386](https://intel.threadlinqs.com/cve/CVE-2026-11386) (0.3%), [CVE-2026-77113](https://intel.threadlinqs.com/cve/CVE-2026-77113) (0.2%), [CVE-2026-8933](https://intel.threadlinqs.com/cve/CVE-2026-8933) (0.1%).
- 2 CVEs score Critical and 4 High on CVSS v3 (maximum 10, average 7.7); sequence these after KEV and high-EPSS items.
- 1 CVE has a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/canonical
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
