# GNU vulnerabilities & exploitation

**CISA KEV**

> As of 2026-10-05, Threadlinqs tracks 7 GNU CVEs, 2 in the CISA Known Exploited Vulnerabilities catalog, linked to 3 tracked threat campaigns.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 7 GNU CVEs published between 2014-09-15 and 2026-09-15. The busiest month was 2026-09 (3 new CVEs). 2 of them (29%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 7 of 7 tracked GNU CVEs.

- [CVE-2014-6271](https://intel.threadlinqs.com/cve/CVE-2014-6271) — CRITICAL 9.8 · KEV · EPSS 100% · 2014-09-24
- [CVE-2026-24061](https://intel.threadlinqs.com/cve/CVE-2026-24061) — CRITICAL 9.8 · KEV · EPSS 88% · 2026-01-21
- [CVE-2026-32746](https://intel.threadlinqs.com/cve/CVE-2026-32746) — CRITICAL 9.8 · EPSS 23.7% · 2026-03-13
- [CVE-2026-56968](https://intel.threadlinqs.com/cve/CVE-2026-56968) — LOW 3.7 · EPSS 0.2% · 2026-06-23
- [CVE-2026-90829](https://intel.threadlinqs.com/cve/CVE-2026-90829) — MEDIUM 5.3 · EPSS 0.2% · 2026-09-14
- [CVE-2026-90830](https://intel.threadlinqs.com/cve/CVE-2026-90830) — MEDIUM 5.3 · EPSS 0.2% · 2026-09-14
- [CVE-2026-90831](https://intel.threadlinqs.com/cve/CVE-2026-90831) — MEDIUM 5.3 · EPSS 0.2% · 2026-09-14

## Products affected

Threadlinqs normalises CPE and CNA product records across all 7 CVEs; 4 distinct GNU products are affected. The most frequently affected:

- Binutils — 3 CVEs
- Inetutils — 2 CVEs
- Bash — 1 CVE
- SASL — 1 CVE

## Threat activity

3 tracked threat campaigns reference GNU products or exploit GNU CVEs:

- [Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON Steganographic Webshell in Multi-Country Espionage Campaign](https://intel.threadlinqs.com/threat/TL-2026-2325) — HIGH — 2026-09-04
- [CVE-2026-32746: Pre-Auth BSS Buffer Overflow in GNU inetutils telnetd LINEMODE SLC Handling](https://intel.threadlinqs.com/threat/TL-2026-1515) — HIGH — 2026-07-19
- [SolarWinds Access Rights Manager (ARM) Systemic Deserialization RCE — 17 CVEs, 6 Unauth SYSTEM RCE, Access Control Paradox](https://intel.threadlinqs.com/threat/TL-2026-0016) — CRITICAL — 2026-02-02

## How to prioritise GNU patching

This order follows the data Threadlinqs holds for GNU, not a generic severity checklist:

- 2 of 7 GNU CVEs (29%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with [CVE-2014-6271](https://intel.threadlinqs.com/cve/CVE-2014-6271), [CVE-2026-24061](https://intel.threadlinqs.com/cve/CVE-2026-24061).
- Outside KEV, the highest EPSS scores are [CVE-2026-32746](https://intel.threadlinqs.com/cve/CVE-2026-32746) (23.7%), [CVE-2026-56968](https://intel.threadlinqs.com/cve/CVE-2026-56968) (0.2%), [CVE-2026-90829](https://intel.threadlinqs.com/cve/CVE-2026-90829) (0.2%).
- 3 CVEs score Critical and 0 High on CVSS v3 (maximum 9.8, average 7); sequence these after KEV and high-EPSS items.
- 2 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/gnu
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
