Exploitation timeline
Threadlinqs has recorded 26 Debian CVEs published between and . The busiest month was 2023-04 (2 new CVEs). 25 of them (96%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 26 of 26 tracked Debian CVEs.
- CVE-2017-8291high 7.8KEVEPSS 97%
- CVE-2022-0543critical 10KEVRansomwareEPSS 94.4%
- CVE-2020-1472medium 5.5KEVRansomwareEPSS 94.4%
- CVE-2021-44228critical 10KEVRansomwareEPSS 94.4%
- CVE-2016-5195high 7KEVRansomwareEPSS 93.9%
- CVE-2025-49113critical 9.9KEVEPSS 91.6%
- CVE-2026-24061critical 9.8KEVEPSS 88%
- CVE-2023-5631medium 6.1KEVEPSS 83.4%
- CVE-2023-43770medium 6.1KEVEPSS 80.4%
- CVE-2021-38003high 8.8KEVEPSS 68.3%
- CVE-2020-35730medium 6.1KEVEPSS 64.8%
- CVE-2021-44026critical 9.8KEVEPSS 64%
- CVE-2024-9680critical 9.8KEVRansomwareEPSS 30.8%
- CVE-2023-2033high 8.8KEVEPSS 25.2%
- CVE-2023-41993high 8.8KEVEPSS 24.4%
- CVE-2023-0386high 7.8KEVEPSS 7.9%
- CVE-2021-37976medium 6.5KEVEPSS 7.7%
- CVE-2021-37973critical 9.6KEVEPSS 6.5%
- CVE-2021-38000medium 6.1KEVEPSS 4.5%
- CVE-2023-20867low 3.9KEVEPSS 2.7%
- CVE-2023-3079high 8.8KEVEPSS 2.1%
- CVE-2021-30952high 7.8KEVEPSS 1.2%
- CVE-2023-2136critical 9.6KEVEPSS 0.7%
- CVE-2023-42917high 8.8KEVEPSS 0.1%
- CVE-2023-42916medium 6.5KEVEPSS 0%
- CVE-2019-12111high 7.5EPSS 3.4%
Products affected
Threadlinqs normalises CPE and CNA product records across all 26 CVEs; 1 distinct Debian product is affected. The most frequently affected:
- Linux 26 CVEs
Threat activity
61 tracked threat campaigns reference Debian products or exploit Debian CVEs; the 25 most recent are listed.
- Debian Trixie kernel update DSA-6528-1 patches 1,000+ Linux kernel CVEs (privilege escalation, DoS, information leaks)HIGH
- AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)HIGH
- Lazarus Exploits CVE-2026-68820 Zero-Day via Malicious PDF Viewer in Operation Dream Job Against Defense IndustryCRITICAL
- CVE-2025-39682 — Linux Kernel net/tls rx_list Zero-Length Record Use-After-Free Added to CISA KEV CatalogCRITICAL
- Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling ObservedHIGH
- Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged)HIGH
- CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit MalwareCRITICAL
- CVE-2025-37947: Out-of-Bounds Write in Linux ksmbd Kernel SMB Server Enables Local Privilege EscalationHIGH
- VLC Media Player: Integer Overflow in AllocatePicture (CVE-2026-56711) and RTSP Heap Out-of-Bounds Read (CVE-2026-73324)HIGH
- Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)CRITICAL
- DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD Files with Defense Mil-Spec ReferencesCRITICAL
- Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON Steganographic Webshell in Multi-Country Espionage CampaignHIGH
- EtherHiding: Blockchain-Based C2 on Polygon Fuels ClickFix Backdoor + Banking-Trojan Extension Campaign Adopted by Criminal, North Korean, and Iran-Linked ActorsHIGH
- Rhysida Ransomware Claims Berlin State Government Breach Ahead of September ElectionHIGH
- LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)HIGH
- Russia (GRU Unit 26165 / APT28) Runs Multi-Vector Surveillance, Intimidation, Sabotage and Cyber Espionage Campaign Against Europe's Ukraine Defence Supply ChainHIGH
- Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820 (AFD.sys) and Two Publicly Disclosed Zero-Days (CVE-2026-62832 "LegacyHive", CVE-2026-72971)CRITICAL
- SCTPhantom (CVE-2026-64564): 18-Year-Old Use-After-Free in Linux Kernel SCTP ASCONF Handling Enables Local Privilege EscalationHIGH
- Larva-26005 APT Campaign: Xctdoor and CRAT Backdoors Targeting South Korea (2020–2026)CRITICAL
- CVE-2026-64561 — Zapscape: KVM/x86 Shadow MMU Use-After-Free Allows L1 Guest Escape to Linux HostHIGH
- OVSWrap (CVE-2026-64531): Linux kernel Open vSwitch datapath 16-bit nla_len wraparound local privilege escalation with public PoC targeting ~800 x86-64 kernel buildsHIGH
- CVE-2026-53264: AI-Assisted Discovery of Linux Kernel net/sched Use-After-Free Enabling Local Root Privilege EscalationHIGH
- Operation RoundPress: TA458 Deploys SpyPress Malware via Half-Click Webmail Zero-Days (CVE-2025-27915, CVE-2025-3929, CVE-2026-8496)CRITICAL
- CVE-2026-32746: Pre-Auth BSS Buffer Overflow in GNU inetutils telnetd LINEMODE SLC HandlingHIGH
- F5OS / Traffix SDC Information Disclosure (CVE-2026-46333) — Linux Kernel ptrace/pidfd_getfd Race Condition, Public PoC (CHARON)HIGH
Threat actors targeting Debian
Named threat actors attributed to campaigns that involve Debian products or CVEs, with the number of linked campaigns:
How to prioritise Debian patching
This order follows the data Threadlinqs holds for Debian, not a generic severity checklist:
- 25 of 26 Debian CVEs (96%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2017-8291, CVE-2022-0543, CVE-2020-1472.
- 5 CVEs are known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are CVE-2019-12111 (3.4%).
- 8 CVEs score Critical and 10 High on CVSS v3 (maximum 10, average 8); sequence these after KEV and high-EPSS items.
- 3 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.