# HashiCorp vulnerabilities & exploitation

> As of 2026-10-10, Threadlinqs tracks 6 HashiCorp CVEs, 0 in the CISA Known Exploited Vulnerabilities catalog, linked to 5 tracked threat campaigns and 5 named threat actors.

**Data as of:** 2026-10-10

## Exploitation timeline

Threadlinqs has recorded 6 HashiCorp CVEs published between 2026-07-15 and 2026-10-15. The busiest month was 2026-07 (3 new CVEs). None of them is listed in CISA KEV yet.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 6 of 6 tracked HashiCorp CVEs.

- [CVE-2026-16498](https://intel.threadlinqs.com/cve/CVE-2026-16498) — CRITICAL 10 · EPSS 0.5% · 2026-07-28
- [CVE-2026-14869](https://intel.threadlinqs.com/cve/CVE-2026-14869) — HIGH 8.6 · EPSS 0.4% · 2026-07-28
- [CVE-2026-16496](https://intel.threadlinqs.com/cve/CVE-2026-16496) — HIGH 8.9 · EPSS 0.4% · 2026-07-28
- [CVE-2026-105816](https://intel.threadlinqs.com/cve/CVE-2026-105816) — HIGH 8 · EPSS 0.3% · 2026-10-07
- [CVE-2026-89322](https://intel.threadlinqs.com/cve/CVE-2026-89322) — HIGH 7.2 · EPSS 0.3% · 2026-10-07
- [CVE-2026-105818](https://intel.threadlinqs.com/cve/CVE-2026-105818) — MEDIUM 5.9 · EPSS 0.1% · 2026-10-07

## Products affected

Threadlinqs normalises CPE and CNA product records across all 6 CVEs; 3 distinct HashiCorp products are affected. The most frequently affected:

- Tooling — 3 CVEs
- Vault — 3 CVEs
- Vault Enterprise — 3 CVEs

## Threat activity

5 tracked threat campaigns reference HashiCorp products or exploit HashiCorp CVEs:

- [Suspected TraderTraitor Group Uses Trojanized Terraform Provider to Deliver Cross-Platform FLATROOF and ROOFDECK Malware](https://intel.threadlinqs.com/threat/TL-2026-3071) — HIGH — 2026-10-09
- [DPRK-Linked Graphalgo Campaign Abuses HashiCorp Terraform Registry with Malicious Providers and Go Modules to Deliver Go RAT with Slack and Arbitrum Sepolia Blockchain C2](https://intel.threadlinqs.com/threat/TL-2026-2635) — HIGH — 2026-09-23
- [Jade Sleet (North Korea) Compromises Indian IT Provider via FLATROOF and ROOFDECK macOS Backdoors](https://intel.threadlinqs.com/threat/TL-2026-2599) — HIGH — 2026-09-21
- [August 2026 Patch Roundup: 11 Critical/High CVEs in Veeam VSPC (CVE-2026-58073, CVSS 9.5), HashiCorp Terraform MCP Server (CVE-2026-16498, CVSS 10.0), and Django](https://intel.threadlinqs.com/threat/TL-2026-1891) — CRITICAL — 2026-08-05
- [Quasar Linux (QLNX) — Sophisticated Linux RAT With LD_PRELOAD Rootkit, PAM Backdoor & DevOps Credential Harvesting (Backdoor.Linux.QLNX.A)](https://intel.threadlinqs.com/threat/TL-2026-0456) — HIGH — 2026-05-04

## Threat actors targeting HashiCorp

Named threat actors attributed to campaigns that involve HashiCorp products or CVEs, with the number of linked campaigns:

- [Jade Sleet](https://intel.threadlinqs.com/actor/Jade%20Sleet) — 2 campaigns
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 1 campaign
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1 campaign
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 1 campaign
- [TraderTraitor](https://intel.threadlinqs.com/actor/TraderTraitor) — 1 campaign

## How to prioritise HashiCorp patching

This order follows the data Threadlinqs holds for HashiCorp, not a generic severity checklist:

- No HashiCorp CVE is in CISA KEV yet, so rank by exploit probability instead.
- Outside KEV, the highest EPSS scores are [CVE-2026-16498](https://intel.threadlinqs.com/cve/CVE-2026-16498) (0.5%), [CVE-2026-14869](https://intel.threadlinqs.com/cve/CVE-2026-14869) (0.4%), [CVE-2026-16496](https://intel.threadlinqs.com/cve/CVE-2026-16496) (0.4%).
- 1 CVE scores Critical and 4 High on CVSS v3 (maximum 10, average 8.1); sequence these after KEV and high-EPSS items.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-10 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/hashicorp
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
