# Debian vulnerabilities & exploitation

**CISA KEV** · **Ransomware**

> As of 2026-10-05, Threadlinqs tracks 26 Debian CVEs, 25 in the CISA Known Exploited Vulnerabilities catalog, 5 used in ransomware campaigns, linked to 61 tracked threat campaigns and 12 named threat actors.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 26 Debian CVEs published between 2016-11-15 and 2026-01-15. The busiest month was 2023-04 (2 new CVEs). 25 of them (96%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 26 of 26 tracked Debian CVEs.

- [CVE-2017-8291](https://intel.threadlinqs.com/cve/CVE-2017-8291) — HIGH 7.8 · KEV · EPSS 97% · 2017-04-27
- [CVE-2022-0543](https://intel.threadlinqs.com/cve/CVE-2022-0543) — CRITICAL 10 · KEV · Ransomware · EPSS 94.4% · 2022-02-18
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472) — MEDIUM 5.5 · KEV · Ransomware · EPSS 94.4% · 2020-08-17
- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228) — CRITICAL 10 · KEV · Ransomware · EPSS 94.4% · 2021-12-10
- [CVE-2016-5195](https://intel.threadlinqs.com/cve/CVE-2016-5195) — HIGH 7 · KEV · Ransomware · EPSS 93.9% · 2016-11-10
- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113) — CRITICAL 9.9 · KEV · EPSS 91.6% · 2025-06-02
- [CVE-2026-24061](https://intel.threadlinqs.com/cve/CVE-2026-24061) — CRITICAL 9.8 · KEV · EPSS 88% · 2026-01-21
- [CVE-2023-5631](https://intel.threadlinqs.com/cve/CVE-2023-5631) — MEDIUM 6.1 · KEV · EPSS 83.4% · 2023-10-18
- [CVE-2023-43770](https://intel.threadlinqs.com/cve/CVE-2023-43770) — MEDIUM 6.1 · KEV · EPSS 80.4% · 2023-09-22
- [CVE-2021-38003](https://intel.threadlinqs.com/cve/CVE-2021-38003) — HIGH 8.8 · KEV · EPSS 68.3% · 2021-11-23
- [CVE-2020-35730](https://intel.threadlinqs.com/cve/CVE-2020-35730) — MEDIUM 6.1 · KEV · EPSS 64.8% · 2020-12-28
- [CVE-2021-44026](https://intel.threadlinqs.com/cve/CVE-2021-44026) — CRITICAL 9.8 · KEV · EPSS 64% · 2021-11-19
- [CVE-2024-9680](https://intel.threadlinqs.com/cve/CVE-2024-9680) — CRITICAL 9.8 · KEV · Ransomware · EPSS 30.8% · 2024-10-09
- [CVE-2023-2033](https://intel.threadlinqs.com/cve/CVE-2023-2033) — HIGH 8.8 · KEV · EPSS 25.2% · 2023-04-14
- [CVE-2023-41993](https://intel.threadlinqs.com/cve/CVE-2023-41993) — HIGH 8.8 · KEV · EPSS 24.4% · 2023-09-21
- [CVE-2023-0386](https://intel.threadlinqs.com/cve/CVE-2023-0386) — HIGH 7.8 · KEV · EPSS 7.9% · 2023-03-22
- [CVE-2021-37976](https://intel.threadlinqs.com/cve/CVE-2021-37976) — MEDIUM 6.5 · KEV · EPSS 7.7% · 2021-10-08
- [CVE-2021-37973](https://intel.threadlinqs.com/cve/CVE-2021-37973) — CRITICAL 9.6 · KEV · EPSS 6.5% · 2021-10-08
- [CVE-2021-38000](https://intel.threadlinqs.com/cve/CVE-2021-38000) — MEDIUM 6.1 · KEV · EPSS 4.5% · 2021-11-23
- [CVE-2023-20867](https://intel.threadlinqs.com/cve/CVE-2023-20867) — LOW 3.9 · KEV · EPSS 2.7% · 2023-06-13
- [CVE-2023-3079](https://intel.threadlinqs.com/cve/CVE-2023-3079) — HIGH 8.8 · KEV · EPSS 2.1% · 2023-06-05
- [CVE-2021-30952](https://intel.threadlinqs.com/cve/CVE-2021-30952) — HIGH 7.8 · KEV · EPSS 1.2% · 2021-08-24
- [CVE-2023-2136](https://intel.threadlinqs.com/cve/CVE-2023-2136) — CRITICAL 9.6 · KEV · EPSS 0.7% · 2023-04-19
- [CVE-2023-42917](https://intel.threadlinqs.com/cve/CVE-2023-42917) — HIGH 8.8 · KEV · EPSS 0.1% · 2023-11-30
- [CVE-2023-42916](https://intel.threadlinqs.com/cve/CVE-2023-42916) — MEDIUM 6.5 · KEV · EPSS 0% · 2023-11-30
- [CVE-2019-12111](https://intel.threadlinqs.com/cve/CVE-2019-12111) — HIGH 7.5 · EPSS 3.4% · 2019-05-15

## Products affected

Threadlinqs normalises CPE and CNA product records across all 26 CVEs; 1 distinct Debian product is affected. The most frequently affected:

- Linux — 26 CVEs

## Threat activity

61 tracked threat campaigns reference Debian products or exploit Debian CVEs; the 25 most recent are listed.

- [Debian Trixie kernel update DSA-6528-1 patches 1,000+ Linux kernel CVEs (privilege escalation, DoS, information leaks)](https://intel.threadlinqs.com/threat/TL-2026-2849) — HIGH — 2026-09-29
- [AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)](https://intel.threadlinqs.com/threat/TL-2026-2558) — HIGH — 2026-09-18
- [Lazarus Exploits CVE-2026-68820 Zero-Day via Malicious PDF Viewer in Operation Dream Job Against Defense Industry](https://intel.threadlinqs.com/threat/TL-2026-2561) — CRITICAL — 2026-09-18
- [CVE-2025-39682 — Linux Kernel net/tls rx_list Zero-Length Record Use-After-Free Added to CISA KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2570) — CRITICAL — 2026-09-18
- [Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observed](https://intel.threadlinqs.com/threat/TL-2026-2546) — HIGH — 2026-09-17
- [Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged)](https://intel.threadlinqs.com/threat/TL-2026-2514) — HIGH — 2026-09-15
- [CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit Malware](https://intel.threadlinqs.com/threat/TL-2026-2474) — CRITICAL — 2026-09-13
- [CVE-2025-37947: Out-of-Bounds Write in Linux ksmbd Kernel SMB Server Enables Local Privilege Escalation](https://intel.threadlinqs.com/threat/TL-2026-2477) — HIGH — 2026-09-13
- [VLC Media Player: Integer Overflow in AllocatePicture (CVE-2026-56711) and RTSP Heap Out-of-Bounds Read (CVE-2026-73324)](https://intel.threadlinqs.com/threat/TL-2026-2464) — HIGH — 2026-09-12
- [Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)](https://intel.threadlinqs.com/threat/TL-2026-2357) — CRITICAL — 2026-09-06
- [DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD Files with Defense Mil-Spec References](https://intel.threadlinqs.com/threat/TL-2026-2364) — CRITICAL — 2026-09-06
- [Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON Steganographic Webshell in Multi-Country Espionage Campaign](https://intel.threadlinqs.com/threat/TL-2026-2325) — HIGH — 2026-09-04
- [EtherHiding: Blockchain-Based C2 on Polygon Fuels ClickFix Backdoor + Banking-Trojan Extension Campaign Adopted by Criminal, North Korean, and Iran-Linked Actors](https://intel.threadlinqs.com/threat/TL-2026-2273) — HIGH — 2026-09-01
- [Rhysida Ransomware Claims Berlin State Government Breach Ahead of September Election](https://intel.threadlinqs.com/threat/TL-2026-2206) — HIGH — 2026-08-29
- [LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)](https://intel.threadlinqs.com/threat/TL-2026-2094) — HIGH — 2026-08-21
- [Russia (GRU Unit 26165 / APT28) Runs Multi-Vector Surveillance, Intimidation, Sabotage and Cyber Espionage Campaign Against Europe's Ukraine Defence Supply Chain](https://intel.threadlinqs.com/threat/TL-2026-2031) — HIGH — 2026-08-16
- [Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820 (AFD.sys) and Two Publicly Disclosed Zero-Days (CVE-2026-62832 "LegacyHive", CVE-2026-72971)](https://intel.threadlinqs.com/threat/TL-2026-1987) — CRITICAL — 2026-08-11
- [SCTPhantom (CVE-2026-64564): 18-Year-Old Use-After-Free in Linux Kernel SCTP ASCONF Handling Enables Local Privilege Escalation](https://intel.threadlinqs.com/threat/TL-2026-1949) — HIGH — 2026-08-09
- [Larva-26005 APT Campaign: Xctdoor and CRAT Backdoors Targeting South Korea (2020–2026)](https://intel.threadlinqs.com/threat/TL-2026-1908) — CRITICAL — 2026-08-06
- [CVE-2026-64561 — Zapscape: KVM/x86 Shadow MMU Use-After-Free Allows L1 Guest Escape to Linux Host](https://intel.threadlinqs.com/threat/TL-2026-1919) — HIGH — 2026-08-06
- [OVSWrap (CVE-2026-64531): Linux kernel Open vSwitch datapath 16-bit nla_len wraparound local privilege escalation with public PoC targeting ~800 x86-64 kernel builds](https://intel.threadlinqs.com/threat/TL-2026-1887) — HIGH — 2026-08-05
- [CVE-2026-53264: AI-Assisted Discovery of Linux Kernel net/sched Use-After-Free Enabling Local Root Privilege Escalation](https://intel.threadlinqs.com/threat/TL-2026-1744) — HIGH — 2026-07-28
- [Operation RoundPress: TA458 Deploys SpyPress Malware via Half-Click Webmail Zero-Days (CVE-2025-27915, CVE-2025-3929, CVE-2026-8496)](https://intel.threadlinqs.com/threat/TL-2026-2579) — CRITICAL — 2026-07-23
- [CVE-2026-32746: Pre-Auth BSS Buffer Overflow in GNU inetutils telnetd LINEMODE SLC Handling](https://intel.threadlinqs.com/threat/TL-2026-1515) — HIGH — 2026-07-19
- [F5OS / Traffix SDC Information Disclosure (CVE-2026-46333) — Linux Kernel ptrace/pidfd_getfd Race Condition, Public PoC (CHARON)](https://intel.threadlinqs.com/threat/TL-2026-1503) — HIGH — 2026-07-18

## Threat actors targeting Debian

Named threat actors attributed to campaigns that involve Debian products or CVEs, with the number of linked campaigns:

- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 3 campaigns
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 3 campaigns
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 3 campaigns
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 3 campaigns
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 3 campaigns
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 2 campaigns
- [Rhysida](https://intel.threadlinqs.com/actor/Rhysida) — 2 campaigns
- [UNK_MassTraction](https://intel.threadlinqs.com/actor/UNK_MassTraction) — 2 campaigns
- [Black Basta](https://intel.threadlinqs.com/actor/Black%20Basta) — 1 campaign
- [BlackBasta](https://intel.threadlinqs.com/actor/BlackBasta) — 1 campaign
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 1 campaign
- [Cytrox](https://intel.threadlinqs.com/actor/Cytrox) — 1 campaign

## How to prioritise Debian patching

This order follows the data Threadlinqs holds for Debian, not a generic severity checklist:

- 25 of 26 Debian CVEs (96%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with [CVE-2017-8291](https://intel.threadlinqs.com/cve/CVE-2017-8291), [CVE-2022-0543](https://intel.threadlinqs.com/cve/CVE-2022-0543), [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472).
- 5 CVEs are known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are [CVE-2019-12111](https://intel.threadlinqs.com/cve/CVE-2019-12111) (3.4%).
- 8 CVEs score Critical and 10 High on CVSS v3 (maximum 10, average 8); sequence these after KEV and high-EPSS items.
- 3 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/debian
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
