Exploitation timeline
Threadlinqs has recorded 20 Fedoraproject CVEs published between and . The busiest month was 2021-11 (3 new CVEs). 19 of them (95%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 20 of 20 tracked Fedoraproject CVEs.
- CVE-2020-1472medium 5.5KEVRansomwareEPSS 94.4%
- CVE-2021-44228critical 10KEVRansomwareEPSS 94.4%
- CVE-2016-5195high 7KEVRansomwareEPSS 93.9%
- CVE-2022-0847high 7.8KEVEPSS 92.8%
- CVE-2023-5631medium 6.1KEVEPSS 83.4%
- CVE-2021-38003high 8.8KEVEPSS 68.3%
- CVE-2020-35730medium 6.1KEVEPSS 64.8%
- CVE-2021-44026critical 9.8KEVEPSS 64%
- CVE-2023-2033high 8.8KEVEPSS 25.2%
- CVE-2023-41993high 8.8KEVEPSS 24.4%
- CVE-2021-37976medium 6.5KEVEPSS 7.7%
- CVE-2021-37973critical 9.6KEVEPSS 6.5%
- CVE-2021-38000medium 6.1KEVEPSS 4.5%
- CVE-2023-20867low 3.9KEVEPSS 2.7%
- CVE-2023-3079high 8.8KEVEPSS 2.1%
- CVE-2021-30952high 7.8KEVEPSS 1.2%
- CVE-2023-2136critical 9.6KEVEPSS 0.7%
- CVE-2023-42917high 8.8KEVEPSS 0.1%
- CVE-2023-42916medium 6.5KEVEPSS 0%
- CVE-2023-29483high 7EPSS 1.9%
Products affected
Threadlinqs normalises CPE and CNA product records across all 20 CVEs; 1 distinct Fedoraproject product is affected. The most frequently affected:
- Fedora 20 CVEs
Threat activity
29 tracked threat campaigns reference Fedoraproject products or exploit Fedoraproject CVEs; the 25 most recent are listed.
- Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti UniFi OS Flaws to Steal Government DataCRITICAL
- "LPE Quartet": Public Exploits Released for Four Linux Kernel Local-Root Flaws (DirtyAH6, TUNderflow, PPPoEject, DiagSpill)HIGH
- Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling ObservedHIGH
- Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged)HIGH
- CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit MalwareCRITICAL
- Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)CRITICAL
- DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD Files with Defense Mil-Spec ReferencesCRITICAL
- Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON Steganographic Webshell in Multi-Country Espionage CampaignHIGH
- Rhysida Ransomware Claims Berlin State Government Breach Ahead of September ElectionHIGH
- LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)HIGH
- Chinese-speaking threat group UAT-10147 uses agentic AI to automate exploitation of internet-facing web serversHIGH
- Russia (GRU Unit 26165 / APT28) Runs Multi-Vector Surveillance, Intimidation, Sabotage and Cyber Espionage Campaign Against Europe's Ukraine Defence Supply ChainHIGH
- RefluXFS: Linux Kernel XFS Copy-on-Write Race Condition Local Privilege Escalation (CVE-2026-64600)HIGH
- F5OS / Traffix SDC Information Disclosure (CVE-2026-46333) — Linux Kernel ptrace/pidfd_getfd Race Condition, Public PoC (CHARON)HIGH
- Forgotten UEFI Shims Undermine Secure Boot (CVE-2026-8863, CVE-2026-10797)HIGH
- Aquatic Panda (Earth Lusca) APT - Log4Shell Exploitation and Multi-Platform Backdoor Campaigns Targeting 17 CountriesCRITICAL
- Linux Kernel LPE Surge: Copy Fail (CVE-2026-31431), Dirty Frag/Fragnesia (CVE-2026-43284/CVE-2026-43500/CVE-2026-46300), and CrackArmor AppArmor Flaws vs. Defense-in-Depth MitigationsHIGH
- PinTheft — Linux Kernel RDS Zerocopy FOLL_PIN Refcount Imbalance Chained With io_uring Fixed Buffers For Page-Cache Overwrite And Local Root (Public PoC, Arch Linux Default-Affected)HIGH
- DirtyDecrypt / DirtyCBC — Linux Kernel rxgk Root LPE with Public PoC (CVE-2026-31635)HIGH
- SHADOW-AETHER-040 & SHADOW-AETHER-064 — Agentic AI-Driven Intrusion Campaigns Targeting LATAM Government and Financial Sectors (Vibe Hacking)CRITICAL
- Linux Kernel 'Dirty Frag' Universal Local Privilege Escalation — xfrm-ESP & RxRPC Page-Cache Write (No CVE, Public PoC)CRITICAL
- Kyber Ransomware: Post-Quantum Hybrid Encryption Operation Targeting Windows & VMware ESXiCRITICAL
- Hack-for-Hire Espionage Campaign Targeting MENA Civil Society via Predator/Intellexa Mercenary SpywareHIGH
- APT41/Silver Dragon Expanding Enterprise Attack Surface — Google Drive C2, AppDomain Hijacking, Cloud/Supply Chain TargetingHIGH
- UNC3886 Zero-Day Rootkit Campaign Targeting Singaporean Telecommunications — ORB Network C2, Fortinet/VMware Exploitation, Covert Infrastructure PersistenceCRITICAL
Threat actors targeting Fedoraproject
Named threat actors attributed to campaigns that involve Fedoraproject products or CVEs, with the number of linked campaigns:
How to prioritise Fedoraproject patching
This order follows the data Threadlinqs holds for Fedoraproject, not a generic severity checklist:
- 19 of 20 Fedoraproject CVEs (95%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2020-1472, CVE-2021-44228, CVE-2016-5195.
- 3 CVEs are known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are CVE-2023-29483 (1.9%).
- 4 CVEs score Critical and 9 High on CVSS v3 (maximum 10, average 7.7); sequence these after KEV and high-EPSS items.
- 2 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.