Exploitation timeline
Threadlinqs has recorded 6 HashiCorp CVEs published between and . The busiest month was 2026-07 (3 new CVEs). None of them is listed in CISA KEV yet.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 6 of 6 tracked HashiCorp CVEs.
- CVE-2026-16498critical 10EPSS 0.5%
- CVE-2026-14869high 8.6EPSS 0.4%
- CVE-2026-16496high 8.9EPSS 0.4%
- CVE-2026-105816high 8EPSS 0.3%
- CVE-2026-89322high 7.2EPSS 0.3%
- CVE-2026-105818medium 5.9EPSS 0.1%
Products affected
Threadlinqs normalises CPE and CNA product records across all 6 CVEs; 3 distinct HashiCorp products are affected. The most frequently affected:
- Tooling 3 CVEs
- Vault 3 CVEs
- Vault Enterprise 3 CVEs
Threat activity
5 tracked threat campaigns reference HashiCorp products or exploit HashiCorp CVEs:
- Suspected TraderTraitor Group Uses Trojanized Terraform Provider to Deliver Cross-Platform FLATROOF and ROOFDECK MalwareHIGH
- DPRK-Linked Graphalgo Campaign Abuses HashiCorp Terraform Registry with Malicious Providers and Go Modules to Deliver Go RAT with Slack and Arbitrum Sepolia Blockchain C2HIGH
- Jade Sleet (North Korea) Compromises Indian IT Provider via FLATROOF and ROOFDECK macOS BackdoorsHIGH
- August 2026 Patch Roundup: 11 Critical/High CVEs in Veeam VSPC (CVE-2026-58073, CVSS 9.5), HashiCorp Terraform MCP Server (CVE-2026-16498, CVSS 10.0), and DjangoCRITICAL
- Quasar Linux (QLNX) — Sophisticated Linux RAT With LD_PRELOAD Rootkit, PAM Backdoor & DevOps Credential Harvesting (Backdoor.Linux.QLNX.A)HIGH
Threat actors targeting HashiCorp
Named threat actors attributed to campaigns that involve HashiCorp products or CVEs, with the number of linked campaigns:
How to prioritise HashiCorp patching
This order follows the data Threadlinqs holds for HashiCorp, not a generic severity checklist:
- No HashiCorp CVE is in CISA KEV yet, so rank by exploit probability instead.
- Outside KEV, the highest EPSS scores are CVE-2026-16498 (0.5%), CVE-2026-14869 (0.4%), CVE-2026-16496 (0.4%).
- 1 CVE scores Critical and 4 High on CVSS v3 (maximum 10, average 8.1); sequence these after KEV and high-EPSS items.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-10 and refresh daily.