# Fedoraproject vulnerabilities & exploitation

**CISA KEV** · **Ransomware**

> As of 2026-10-05, Threadlinqs tracks 20 Fedoraproject CVEs, 19 in the CISA Known Exploited Vulnerabilities catalog, 3 used in ransomware campaigns, linked to 29 tracked threat campaigns and 12 named threat actors.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 20 Fedoraproject CVEs published between 2016-11-15 and 2024-04-15. The busiest month was 2021-11 (3 new CVEs). 19 of them (95%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 20 of 20 tracked Fedoraproject CVEs.

- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472) — MEDIUM 5.5 · KEV · Ransomware · EPSS 94.4% · 2020-08-17
- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228) — CRITICAL 10 · KEV · Ransomware · EPSS 94.4% · 2021-12-10
- [CVE-2016-5195](https://intel.threadlinqs.com/cve/CVE-2016-5195) — HIGH 7 · KEV · Ransomware · EPSS 93.9% · 2016-11-10
- [CVE-2022-0847](https://intel.threadlinqs.com/cve/CVE-2022-0847) — HIGH 7.8 · KEV · EPSS 92.8% · 2022-03-07
- [CVE-2023-5631](https://intel.threadlinqs.com/cve/CVE-2023-5631) — MEDIUM 6.1 · KEV · EPSS 83.4% · 2023-10-18
- [CVE-2021-38003](https://intel.threadlinqs.com/cve/CVE-2021-38003) — HIGH 8.8 · KEV · EPSS 68.3% · 2021-11-23
- [CVE-2020-35730](https://intel.threadlinqs.com/cve/CVE-2020-35730) — MEDIUM 6.1 · KEV · EPSS 64.8% · 2020-12-28
- [CVE-2021-44026](https://intel.threadlinqs.com/cve/CVE-2021-44026) — CRITICAL 9.8 · KEV · EPSS 64% · 2021-11-19
- [CVE-2023-2033](https://intel.threadlinqs.com/cve/CVE-2023-2033) — HIGH 8.8 · KEV · EPSS 25.2% · 2023-04-14
- [CVE-2023-41993](https://intel.threadlinqs.com/cve/CVE-2023-41993) — HIGH 8.8 · KEV · EPSS 24.4% · 2023-09-21
- [CVE-2021-37976](https://intel.threadlinqs.com/cve/CVE-2021-37976) — MEDIUM 6.5 · KEV · EPSS 7.7% · 2021-10-08
- [CVE-2021-37973](https://intel.threadlinqs.com/cve/CVE-2021-37973) — CRITICAL 9.6 · KEV · EPSS 6.5% · 2021-10-08
- [CVE-2021-38000](https://intel.threadlinqs.com/cve/CVE-2021-38000) — MEDIUM 6.1 · KEV · EPSS 4.5% · 2021-11-23
- [CVE-2023-20867](https://intel.threadlinqs.com/cve/CVE-2023-20867) — LOW 3.9 · KEV · EPSS 2.7% · 2023-06-13
- [CVE-2023-3079](https://intel.threadlinqs.com/cve/CVE-2023-3079) — HIGH 8.8 · KEV · EPSS 2.1% · 2023-06-05
- [CVE-2021-30952](https://intel.threadlinqs.com/cve/CVE-2021-30952) — HIGH 7.8 · KEV · EPSS 1.2% · 2021-08-24
- [CVE-2023-2136](https://intel.threadlinqs.com/cve/CVE-2023-2136) — CRITICAL 9.6 · KEV · EPSS 0.7% · 2023-04-19
- [CVE-2023-42917](https://intel.threadlinqs.com/cve/CVE-2023-42917) — HIGH 8.8 · KEV · EPSS 0.1% · 2023-11-30
- [CVE-2023-42916](https://intel.threadlinqs.com/cve/CVE-2023-42916) — MEDIUM 6.5 · KEV · EPSS 0% · 2023-11-30
- [CVE-2023-29483](https://intel.threadlinqs.com/cve/CVE-2023-29483) — HIGH 7 · EPSS 1.9% · 2024-04-11

## Products affected

Threadlinqs normalises CPE and CNA product records across all 20 CVEs; 1 distinct Fedoraproject product is affected. The most frequently affected:

- Fedora — 20 CVEs

## Threat activity

29 tracked threat campaigns reference Fedoraproject products or exploit Fedoraproject CVEs; the 25 most recent are listed.

- [Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti UniFi OS Flaws to Steal Government Data](https://intel.threadlinqs.com/threat/TL-2026-2619) — CRITICAL — 2026-09-22
- ["LPE Quartet": Public Exploits Released for Four Linux Kernel Local-Root Flaws (DirtyAH6, TUNderflow, PPPoEject, DiagSpill)](https://intel.threadlinqs.com/threat/TL-2026-2572) — HIGH — 2026-09-18
- [Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observed](https://intel.threadlinqs.com/threat/TL-2026-2546) — HIGH — 2026-09-17
- [Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged)](https://intel.threadlinqs.com/threat/TL-2026-2514) — HIGH — 2026-09-15
- [CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit Malware](https://intel.threadlinqs.com/threat/TL-2026-2474) — CRITICAL — 2026-09-13
- [Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)](https://intel.threadlinqs.com/threat/TL-2026-2357) — CRITICAL — 2026-09-06
- [DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD Files with Defense Mil-Spec References](https://intel.threadlinqs.com/threat/TL-2026-2364) — CRITICAL — 2026-09-06
- [Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON Steganographic Webshell in Multi-Country Espionage Campaign](https://intel.threadlinqs.com/threat/TL-2026-2325) — HIGH — 2026-09-04
- [Rhysida Ransomware Claims Berlin State Government Breach Ahead of September Election](https://intel.threadlinqs.com/threat/TL-2026-2206) — HIGH — 2026-08-29
- [LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)](https://intel.threadlinqs.com/threat/TL-2026-2094) — HIGH — 2026-08-21
- [Chinese-speaking threat group UAT-10147 uses agentic AI to automate exploitation of internet-facing web servers](https://intel.threadlinqs.com/threat/TL-2026-2096) — HIGH — 2026-08-21
- [Russia (GRU Unit 26165 / APT28) Runs Multi-Vector Surveillance, Intimidation, Sabotage and Cyber Espionage Campaign Against Europe's Ukraine Defence Supply Chain](https://intel.threadlinqs.com/threat/TL-2026-2031) — HIGH — 2026-08-16
- [RefluXFS: Linux Kernel XFS Copy-on-Write Race Condition Local Privilege Escalation (CVE-2026-64600)](https://intel.threadlinqs.com/threat/TL-2026-1629) — HIGH — 2026-07-22
- [F5OS / Traffix SDC Information Disclosure (CVE-2026-46333) — Linux Kernel ptrace/pidfd_getfd Race Condition, Public PoC (CHARON)](https://intel.threadlinqs.com/threat/TL-2026-1503) — HIGH — 2026-07-18
- [Forgotten UEFI Shims Undermine Secure Boot (CVE-2026-8863, CVE-2026-10797)](https://intel.threadlinqs.com/threat/TL-2026-1298) — HIGH — 2026-07-14
- [Aquatic Panda (Earth Lusca) APT - Log4Shell Exploitation and Multi-Platform Backdoor Campaigns Targeting 17 Countries](https://intel.threadlinqs.com/threat/TL-2026-0986) — CRITICAL — 2026-06-28
- [Linux Kernel LPE Surge: Copy Fail (CVE-2026-31431), Dirty Frag/Fragnesia (CVE-2026-43284/CVE-2026-43500/CVE-2026-46300), and CrackArmor AppArmor Flaws vs. Defense-in-Depth Mitigations](https://intel.threadlinqs.com/threat/TL-2026-2424) — HIGH — 2026-05-29
- [PinTheft — Linux Kernel RDS Zerocopy FOLL_PIN Refcount Imbalance Chained With io_uring Fixed Buffers For Page-Cache Overwrite And Local Root (Public PoC, Arch Linux Default-Affected)](https://intel.threadlinqs.com/threat/TL-2026-0543) — HIGH — 2026-05-21
- [DirtyDecrypt / DirtyCBC — Linux Kernel rxgk Root LPE with Public PoC (CVE-2026-31635)](https://intel.threadlinqs.com/threat/TL-2026-0524) — HIGH — 2026-05-18
- [SHADOW-AETHER-040 & SHADOW-AETHER-064 — Agentic AI-Driven Intrusion Campaigns Targeting LATAM Government and Financial Sectors (Vibe Hacking)](https://intel.threadlinqs.com/threat/TL-2026-0498) — CRITICAL — 2026-05-12
- [Linux Kernel 'Dirty Frag' Universal Local Privilege Escalation — xfrm-ESP & RxRPC Page-Cache Write (No CVE, Public PoC)](https://intel.threadlinqs.com/threat/TL-2026-0483) — CRITICAL — 2026-05-08
- [Kyber Ransomware: Post-Quantum Hybrid Encryption Operation Targeting Windows & VMware ESXi](https://intel.threadlinqs.com/threat/TL-2026-0412) — CRITICAL — 2026-04-22
- [Hack-for-Hire Espionage Campaign Targeting MENA Civil Society via Predator/Intellexa Mercenary Spyware](https://intel.threadlinqs.com/threat/TL-2026-0333) — HIGH — 2026-04-08
- [APT41/Silver Dragon Expanding Enterprise Attack Surface — Google Drive C2, AppDomain Hijacking, Cloud/Supply Chain Targeting](https://intel.threadlinqs.com/threat/TL-2026-0292) — HIGH — 2026-03-27
- [UNC3886 Zero-Day Rootkit Campaign Targeting Singaporean Telecommunications — ORB Network C2, Fortinet/VMware Exploitation, Covert Infrastructure Persistence](https://intel.threadlinqs.com/threat/TL-2026-0221) — CRITICAL — 2026-03-13

## Threat actors targeting Fedoraproject

Named threat actors attributed to campaigns that involve Fedoraproject products or CVEs, with the number of linked campaigns:

- [Rhysida](https://intel.threadlinqs.com/actor/Rhysida) — 2 campaigns
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1 campaign
- [Black Basta](https://intel.threadlinqs.com/actor/Black%20Basta) — 1 campaign
- [BlackBasta](https://intel.threadlinqs.com/actor/BlackBasta) — 1 campaign
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 1 campaign
- [Cytrox](https://intel.threadlinqs.com/actor/Cytrox) — 1 campaign
- [DragonForce](https://intel.threadlinqs.com/actor/DragonForce) — 1 campaign
- [Earth Lusca](https://intel.threadlinqs.com/actor/Earth%20Lusca) — 1 campaign
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 1 campaign
- [Kapibala](https://intel.threadlinqs.com/actor/Kapibala) — 1 campaign
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 1 campaign
- [Qilin](https://intel.threadlinqs.com/actor/Qilin) — 1 campaign

## How to prioritise Fedoraproject patching

This order follows the data Threadlinqs holds for Fedoraproject, not a generic severity checklist:

- 19 of 20 Fedoraproject CVEs (95%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472), [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228), [CVE-2016-5195](https://intel.threadlinqs.com/cve/CVE-2016-5195).
- 3 CVEs are known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are [CVE-2023-29483](https://intel.threadlinqs.com/cve/CVE-2023-29483) (1.9%).
- 4 CVEs score Critical and 9 High on CVSS v3 (maximum 10, average 7.7); sequence these after KEV and high-EPSS items.
- 2 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/fedoraproject
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
