Exploitation timeline
Threadlinqs has recorded 70 Linux CVEs published between and . The busiest month was 2026-07 (31 new CVEs). 14 of them (20%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 60 of 70 tracked Linux CVEs.
- CVE-2016-5195high 7KEVRansomwareEPSS 93.9%
- CVE-2022-0847high 7.8KEVEPSS 92.8%
- CVE-2023-0386high 7.8KEVEPSS 7.9%
- CVE-2026-31431high 7.8KEVEPSS 4%
- CVE-2024-53197high 7.8KEVEPSS 3.6%
- CVE-2024-53104high 7.8KEVEPSS 3.4%
- CVE-2023-3079high 8.8KEVEPSS 2.1%
- CVE-2025-6554high 8.1KEVEPSS 0.9%
- CVE-2025-14174high 8.8KEVEPSS 0.9%
- CVE-2024-50302medium 5.5KEVEPSS 0.8%
- CVE-2026-3910high 8.8KEVEPSS 0.6%
- CVE-2026-53362high 7.8KEVEPSS 0.5%
- CVE-2026-3909high 8.8KEVEPSS 0.3%
- CVE-2026-2441high 8.8KEVEPSS 0.3%
- CVE-2026-43500high 7.8EPSS 27%
- CVE-2026-43284high 8.8EPSS 25.6%
- CVE-2026-64530critical 9.8EPSS 0.5%
- CVE-2026-64600high 7.8EPSS 0.5%
- CVE-2026-80844EPSS 0.4%
- CVE-2012-0038medium 5.5EPSS 0.4%
- CVE-2026-46331EPSS 0.3%
- CVE-2026-74730EPSS 0.2%
- CVE-2026-64508EPSS 0.2%
- CVE-2026-74722EPSS 0.2%
- CVE-2026-74725EPSS 0.2%
- CVE-2026-74732EPSS 0.2%
- CVE-2026-74724EPSS 0.2%
- CVE-2026-74721EPSS 0.2%
- CVE-2026-74723EPSS 0.2%
- CVE-2026-74729EPSS 0.2%
- CVE-2026-74731EPSS 0.2%
- CVE-2026-74733EPSS 0.2%
- CVE-2026-64529EPSS 0.2%
- CVE-2026-64524EPSS 0.2%
- CVE-2026-64185EPSS 0.2%
- CVE-2026-64518EPSS 0.2%
- CVE-2026-64519EPSS 0.2%
- CVE-2026-64528EPSS 0.2%
- CVE-2026-64172high 7.1EPSS 0.2%
- CVE-2026-64521EPSS 0.2%
- CVE-2026-64522EPSS 0.2%
- CVE-2026-64178high 8.8EPSS 0.2%
- CVE-2026-64170EPSS 0.2%
- CVE-2026-64173EPSS 0.2%
- CVE-2026-64181high 7.8EPSS 0.2%
- CVE-2026-64179EPSS 0.2%
- CVE-2026-64507EPSS 0.2%
- CVE-2026-64527EPSS 0.2%
- CVE-2026-64180EPSS 0.2%
- CVE-2026-64182EPSS 0.2%
- CVE-2026-64184EPSS 0.2%
- CVE-2026-64169EPSS 0.2%
- CVE-2026-64525EPSS 0.2%
- CVE-2026-64186EPSS 0.2%
- CVE-2026-64520EPSS 0.2%
- CVE-2026-64523EPSS 0.2%
- CVE-2026-64171EPSS 0.1%
- CVE-2024-14040high 7.8EPSS 0.1%
- CVE-2026-43503high 8.8EPSS 0.1%
- CVE-2026-31694high 7.8EPSS 0.1%
Products affected
Threadlinqs normalises CPE and CNA product records across all 70 CVEs; 2 distinct Linux products are affected. The most frequently affected:
- Linux 48 CVEs
- Kernel 22 CVEs
Threat activity
71 tracked threat campaigns reference Linux products or exploit Linux CVEs; the 25 most recent are listed.
- Spectre-v2 Branch Target Reuse (BTR) Attack Leaks Linux Kernel Memory Despite Existing Defenses (CVE-2026-64507, CVE-2026-64508)HIGH
- Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE CVE-2026-20079, CVE-2026-76460; SonicWall SMA 1000 CVE-2026-83548/83549; Linux Kernel CopyFail CVE-2026-31431)CRITICAL
- Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti UniFi OS Flaws to Steal Government DataCRITICAL
- CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables SNAT Privilege Escalation, and AF_ALG Race Condition (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964)CRITICAL
- CVE-2025-39682 — Linux Kernel net/tls rx_list Zero-Length Record Use-After-Free Added to CISA KEV CatalogCRITICAL
- "LPE Quartet": Public Exploits Released for Four Linux Kernel Local-Root Flaws (DirtyAH6, TUNderflow, PPPoEject, DiagSpill)HIGH
- Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged)HIGH
- Hyadina Rebrands Beast Ransomware as 'GodDamn' and Uses PoisonX Signed Kernel Driver to Disable Endpoint DefensesCRITICAL
- Serbian Authorities Deploy Pegasus and NoviSpy Spyware Against Journalists, Opposition Politicians, and Student ProtestersHIGH
- EtherHiding: Blockchain-Based C2 on Polygon Fuels ClickFix Backdoor + Banking-Trojan Extension Campaign Adopted by Criminal, North Korean, and Iran-Linked ActorsHIGH
- Auto-Color Linux Backdoor Reverse-Engineered: Root-Level LD_PRELOAD Persistence and Encrypted C2HIGH
- CVE-2026-53362 ("ipv6_frag_escape"): Linux Kernel IPv6 Fragmentation Flaw Enables Container-to-Host Privilege Escalation, Actively Exploited — Added to CISA KEVHIGH
- LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)HIGH
- Chinese-speaking threat group UAT-10147 uses agentic AI to automate exploitation of internet-facing web serversHIGH
- 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2CRITICAL
- CVE-2026-64561 — Zapscape: KVM/x86 Shadow MMU Use-After-Free Allows L1 Guest Escape to Linux HostHIGH
- OVSWrap (CVE-2026-64531): Linux kernel Open vSwitch datapath 16-bit nla_len wraparound local privilege escalation with public PoC targeting ~800 x86-64 kernel buildsHIGH
- CVE-2026-31431: Linux Local Privilege Escalation Actively Exploited by UMBRAL BISON Within 24 Hours of DisclosureHIGH
- CVE-2026-53264: AI-Assisted Discovery of Linux Kernel net/sched Use-After-Free Enabling Local Root Privilege EscalationHIGH
- UT Dallas Study: Multi-Patch CVE Fixes Leave Open Source Exposed to N-Day Exploitation WindowsMEDIUM
- Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and EdgeHIGH
- RefluXFS: Linux Kernel XFS Copy-on-Write Race Condition Local Privilege Escalation (CVE-2026-64600)HIGH
- Forbidden Hyena Adopts AI-Generated BlackReaperRAT and Milkyway (Blackout Locker) Ransomware in Telegram-C2 CampaignHIGH
- F5OS / Traffix SDC Information Disclosure (CVE-2026-46333) — Linux Kernel ptrace/pidfd_getfd Race Condition, Public PoC (CHARON)HIGH
- Krybit Ransomware — Babuk-Derived RaaS Operation Emerges with Double ExtortionHIGH
Threat actors targeting Linux
Named threat actors attributed to campaigns that involve Linux products or CVEs, with the number of linked campaigns:
How to prioritise Linux patching
This order follows the data Threadlinqs holds for Linux, not a generic severity checklist:
- 14 of 70 Linux CVEs (20%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2016-5195, CVE-2022-0847, CVE-2023-0386.
- 1 CVE is known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are CVE-2026-43500 (27%), CVE-2026-43284 (25.6%), CVE-2026-64530 (0.5%).
- 1 CVE scores Critical and 28 High on CVSS v3 (maximum 9.8, average 7.7); sequence these after KEV and high-EPSS items.
- 11 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.