# Linux vulnerabilities & exploitation

**CISA KEV** · **Ransomware**

> As of 2026-10-05, Threadlinqs tracks 70 Linux CVEs, 14 in the CISA Known Exploited Vulnerabilities catalog, 1 used in ransomware campaigns, linked to 71 tracked threat campaigns and 12 named threat actors.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 70 Linux CVEs published between 2012-05-15 and 2026-09-15. The busiest month was 2026-07 (31 new CVEs). 14 of them (20%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 60 of 70 tracked Linux CVEs.

- [CVE-2016-5195](https://intel.threadlinqs.com/cve/CVE-2016-5195) — HIGH 7 · KEV · Ransomware · EPSS 93.9% · 2016-11-10
- [CVE-2022-0847](https://intel.threadlinqs.com/cve/CVE-2022-0847) — HIGH 7.8 · KEV · EPSS 92.8% · 2022-03-07
- [CVE-2023-0386](https://intel.threadlinqs.com/cve/CVE-2023-0386) — HIGH 7.8 · KEV · EPSS 7.9% · 2023-03-22
- [CVE-2026-31431](https://intel.threadlinqs.com/cve/CVE-2026-31431) — HIGH 7.8 · KEV · EPSS 4% · 2026-04-22
- [CVE-2024-53197](https://intel.threadlinqs.com/cve/CVE-2024-53197) — HIGH 7.8 · KEV · EPSS 3.6% · 2024-12-27
- [CVE-2024-53104](https://intel.threadlinqs.com/cve/CVE-2024-53104) — HIGH 7.8 · KEV · EPSS 3.4% · 2024-12-02
- [CVE-2023-3079](https://intel.threadlinqs.com/cve/CVE-2023-3079) — HIGH 8.8 · KEV · EPSS 2.1% · 2023-06-05
- [CVE-2025-6554](https://intel.threadlinqs.com/cve/CVE-2025-6554) — HIGH 8.1 · KEV · EPSS 0.9% · 2025-06-30
- [CVE-2025-14174](https://intel.threadlinqs.com/cve/CVE-2025-14174) — HIGH 8.8 · KEV · EPSS 0.9% · 2025-12-12
- [CVE-2024-50302](https://intel.threadlinqs.com/cve/CVE-2024-50302) — MEDIUM 5.5 · KEV · EPSS 0.8% · 2024-11-19
- [CVE-2026-3910](https://intel.threadlinqs.com/cve/CVE-2026-3910) — HIGH 8.8 · KEV · EPSS 0.6% · 2026-03-13
- [CVE-2026-53362](https://intel.threadlinqs.com/cve/CVE-2026-53362) — HIGH 7.8 · KEV · EPSS 0.5% · 2026-07-04
- [CVE-2026-3909](https://intel.threadlinqs.com/cve/CVE-2026-3909) — HIGH 8.8 · KEV · EPSS 0.3% · 2026-03-13
- [CVE-2026-2441](https://intel.threadlinqs.com/cve/CVE-2026-2441) — HIGH 8.8 · KEV · EPSS 0.3% · 2026-02-13
- [CVE-2026-43500](https://intel.threadlinqs.com/cve/CVE-2026-43500) — HIGH 7.8 · EPSS 27% · 2026-05-11
- [CVE-2026-43284](https://intel.threadlinqs.com/cve/CVE-2026-43284) — HIGH 8.8 · EPSS 25.6% · 2026-05-08
- [CVE-2026-64530](https://intel.threadlinqs.com/cve/CVE-2026-64530) — CRITICAL 9.8 · EPSS 0.5% · 2026-07-26
- [CVE-2026-64600](https://intel.threadlinqs.com/cve/CVE-2026-64600) — HIGH 7.8 · EPSS 0.5% · 2026-07-23
- [CVE-2026-80844](https://intel.threadlinqs.com/cve/CVE-2026-80844) — EPSS 0.4% · 2026-09-04
- [CVE-2012-0038](https://intel.threadlinqs.com/cve/CVE-2012-0038) — MEDIUM 5.5 · EPSS 0.4% · 2012-05-17
- [CVE-2026-46331](https://intel.threadlinqs.com/cve/CVE-2026-46331) — EPSS 0.3% · 2026-06-16
- [CVE-2026-74730](https://intel.threadlinqs.com/cve/CVE-2026-74730) — EPSS 0.2% · 2026-08-22
- [CVE-2026-64508](https://intel.threadlinqs.com/cve/CVE-2026-64508) — EPSS 0.2% · 2026-07-25
- [CVE-2026-74722](https://intel.threadlinqs.com/cve/CVE-2026-74722) — EPSS 0.2% · 2026-08-22
- [CVE-2026-74725](https://intel.threadlinqs.com/cve/CVE-2026-74725) — EPSS 0.2% · 2026-08-22
- [CVE-2026-74732](https://intel.threadlinqs.com/cve/CVE-2026-74732) — EPSS 0.2% · 2026-08-22
- [CVE-2026-74724](https://intel.threadlinqs.com/cve/CVE-2026-74724) — EPSS 0.2% · 2026-08-22
- [CVE-2026-74721](https://intel.threadlinqs.com/cve/CVE-2026-74721) — EPSS 0.2% · 2026-08-22
- [CVE-2026-74723](https://intel.threadlinqs.com/cve/CVE-2026-74723) — EPSS 0.2% · 2026-08-22
- [CVE-2026-74729](https://intel.threadlinqs.com/cve/CVE-2026-74729) — EPSS 0.2% · 2026-08-22
- [CVE-2026-74731](https://intel.threadlinqs.com/cve/CVE-2026-74731) — EPSS 0.2% · 2026-08-22
- [CVE-2026-74733](https://intel.threadlinqs.com/cve/CVE-2026-74733) — EPSS 0.2% · 2026-08-22
- [CVE-2026-64529](https://intel.threadlinqs.com/cve/CVE-2026-64529) — EPSS 0.2% · 2026-07-25
- [CVE-2026-64524](https://intel.threadlinqs.com/cve/CVE-2026-64524) — EPSS 0.2% · 2026-07-25
- [CVE-2026-64185](https://intel.threadlinqs.com/cve/CVE-2026-64185) — EPSS 0.2% · 2026-07-19
- [CVE-2026-64518](https://intel.threadlinqs.com/cve/CVE-2026-64518) — EPSS 0.2% · 2026-07-25
- [CVE-2026-64519](https://intel.threadlinqs.com/cve/CVE-2026-64519) — EPSS 0.2% · 2026-07-25
- [CVE-2026-64528](https://intel.threadlinqs.com/cve/CVE-2026-64528) — EPSS 0.2% · 2026-07-25
- [CVE-2026-64172](https://intel.threadlinqs.com/cve/CVE-2026-64172) — HIGH 7.1 · EPSS 0.2% · 2026-07-19
- [CVE-2026-64521](https://intel.threadlinqs.com/cve/CVE-2026-64521) — EPSS 0.2% · 2026-07-25
- [CVE-2026-64522](https://intel.threadlinqs.com/cve/CVE-2026-64522) — EPSS 0.2% · 2026-07-25
- [CVE-2026-64178](https://intel.threadlinqs.com/cve/CVE-2026-64178) — HIGH 8.8 · EPSS 0.2% · 2026-07-19
- [CVE-2026-64170](https://intel.threadlinqs.com/cve/CVE-2026-64170) — EPSS 0.2% · 2026-07-19
- [CVE-2026-64173](https://intel.threadlinqs.com/cve/CVE-2026-64173) — EPSS 0.2% · 2026-07-19
- [CVE-2026-64181](https://intel.threadlinqs.com/cve/CVE-2026-64181) — HIGH 7.8 · EPSS 0.2% · 2026-07-19
- [CVE-2026-64179](https://intel.threadlinqs.com/cve/CVE-2026-64179) — EPSS 0.2% · 2026-07-19
- [CVE-2026-64507](https://intel.threadlinqs.com/cve/CVE-2026-64507) — EPSS 0.2% · 2026-07-25
- [CVE-2026-64527](https://intel.threadlinqs.com/cve/CVE-2026-64527) — EPSS 0.2% · 2026-07-25
- [CVE-2026-64180](https://intel.threadlinqs.com/cve/CVE-2026-64180) — EPSS 0.2% · 2026-07-19
- [CVE-2026-64182](https://intel.threadlinqs.com/cve/CVE-2026-64182) — EPSS 0.2% · 2026-07-19
- [CVE-2026-64184](https://intel.threadlinqs.com/cve/CVE-2026-64184) — EPSS 0.2% · 2026-07-19
- [CVE-2026-64169](https://intel.threadlinqs.com/cve/CVE-2026-64169) — EPSS 0.2% · 2026-07-19
- [CVE-2026-64525](https://intel.threadlinqs.com/cve/CVE-2026-64525) — EPSS 0.2% · 2026-07-25
- [CVE-2026-64186](https://intel.threadlinqs.com/cve/CVE-2026-64186) — EPSS 0.2% · 2026-07-19
- [CVE-2026-64520](https://intel.threadlinqs.com/cve/CVE-2026-64520) — EPSS 0.2% · 2026-07-25
- [CVE-2026-64523](https://intel.threadlinqs.com/cve/CVE-2026-64523) — EPSS 0.2% · 2026-07-25
- [CVE-2026-64171](https://intel.threadlinqs.com/cve/CVE-2026-64171) — EPSS 0.1% · 2026-07-19
- [CVE-2024-14040](https://intel.threadlinqs.com/cve/CVE-2024-14040) — HIGH 7.8 · EPSS 0.1% · 2026-07-26
- [CVE-2026-43503](https://intel.threadlinqs.com/cve/CVE-2026-43503) — HIGH 8.8 · EPSS 0.1% · 2026-05-23
- [CVE-2026-31694](https://intel.threadlinqs.com/cve/CVE-2026-31694) — HIGH 7.8 · EPSS 0.1% · 2026-05-01

## Products affected

Threadlinqs normalises CPE and CNA product records across all 70 CVEs; 2 distinct Linux products are affected. The most frequently affected:

- Linux — 48 CVEs
- Kernel — 22 CVEs

## Threat activity

71 tracked threat campaigns reference Linux products or exploit Linux CVEs; the 25 most recent are listed.

- [Spectre-v2 Branch Target Reuse (BTR) Attack Leaks Linux Kernel Memory Despite Existing Defenses (CVE-2026-64507, CVE-2026-64508)](https://intel.threadlinqs.com/threat/TL-2026-2796) — HIGH — 2026-09-29
- [Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE CVE-2026-20079, CVE-2026-76460; SonicWall SMA 1000 CVE-2026-83548/83549; Linux Kernel CopyFail CVE-2026-31431)](https://intel.threadlinqs.com/threat/TL-2026-2630) — CRITICAL — 2026-09-23
- [Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti UniFi OS Flaws to Steal Government Data](https://intel.threadlinqs.com/threat/TL-2026-2619) — CRITICAL — 2026-09-22
- [CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables SNAT Privilege Escalation, and AF_ALG Race Condition (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964)](https://intel.threadlinqs.com/threat/TL-2026-2582) — CRITICAL — 2026-09-19
- [CVE-2025-39682 — Linux Kernel net/tls rx_list Zero-Length Record Use-After-Free Added to CISA KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2570) — CRITICAL — 2026-09-18
- ["LPE Quartet": Public Exploits Released for Four Linux Kernel Local-Root Flaws (DirtyAH6, TUNderflow, PPPoEject, DiagSpill)](https://intel.threadlinqs.com/threat/TL-2026-2572) — HIGH — 2026-09-18
- [Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged)](https://intel.threadlinqs.com/threat/TL-2026-2514) — HIGH — 2026-09-15
- [Hyadina Rebrands Beast Ransomware as 'GodDamn' and Uses PoisonX Signed Kernel Driver to Disable Endpoint Defenses](https://intel.threadlinqs.com/threat/TL-2026-2409) — CRITICAL — 2026-09-08
- [Serbian Authorities Deploy Pegasus and NoviSpy Spyware Against Journalists, Opposition Politicians, and Student Protesters](https://intel.threadlinqs.com/threat/TL-2026-2316) — HIGH — 2026-09-03
- [EtherHiding: Blockchain-Based C2 on Polygon Fuels ClickFix Backdoor + Banking-Trojan Extension Campaign Adopted by Criminal, North Korean, and Iran-Linked Actors](https://intel.threadlinqs.com/threat/TL-2026-2273) — HIGH — 2026-09-01
- [Auto-Color Linux Backdoor Reverse-Engineered: Root-Level LD_PRELOAD Persistence and Encrypted C2](https://intel.threadlinqs.com/threat/TL-2026-2264) — HIGH — 2026-08-30
- [CVE-2026-53362 ("ipv6_frag_escape"): Linux Kernel IPv6 Fragmentation Flaw Enables Container-to-Host Privilege Escalation, Actively Exploited — Added to CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-2220) — HIGH — 2026-08-29
- [LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)](https://intel.threadlinqs.com/threat/TL-2026-2094) — HIGH — 2026-08-21
- [Chinese-speaking threat group UAT-10147 uses agentic AI to automate exploitation of internet-facing web servers](https://intel.threadlinqs.com/threat/TL-2026-2096) — HIGH — 2026-08-21
- [14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2](https://intel.threadlinqs.com/threat/TL-2026-2099) — CRITICAL — 2026-08-21
- [CVE-2026-64561 — Zapscape: KVM/x86 Shadow MMU Use-After-Free Allows L1 Guest Escape to Linux Host](https://intel.threadlinqs.com/threat/TL-2026-1919) — HIGH — 2026-08-06
- [OVSWrap (CVE-2026-64531): Linux kernel Open vSwitch datapath 16-bit nla_len wraparound local privilege escalation with public PoC targeting ~800 x86-64 kernel builds](https://intel.threadlinqs.com/threat/TL-2026-1887) — HIGH — 2026-08-05
- [CVE-2026-31431: Linux Local Privilege Escalation Actively Exploited by UMBRAL BISON Within 24 Hours of Disclosure](https://intel.threadlinqs.com/threat/TL-2026-1831) — HIGH — 2026-08-03
- [CVE-2026-53264: AI-Assisted Discovery of Linux Kernel net/sched Use-After-Free Enabling Local Root Privilege Escalation](https://intel.threadlinqs.com/threat/TL-2026-1744) — HIGH — 2026-07-28
- [UT Dallas Study: Multi-Patch CVE Fixes Leave Open Source Exposed to N-Day Exploitation Windows](https://intel.threadlinqs.com/threat/TL-2026-1704) — MEDIUM — 2026-07-26
- [Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge](https://intel.threadlinqs.com/threat/TL-2026-1663) — HIGH — 2026-07-23
- [RefluXFS: Linux Kernel XFS Copy-on-Write Race Condition Local Privilege Escalation (CVE-2026-64600)](https://intel.threadlinqs.com/threat/TL-2026-1629) — HIGH — 2026-07-22
- [Forbidden Hyena Adopts AI-Generated BlackReaperRAT and Milkyway (Blackout Locker) Ransomware in Telegram-C2 Campaign](https://intel.threadlinqs.com/threat/TL-2026-1496) — HIGH — 2026-07-18
- [F5OS / Traffix SDC Information Disclosure (CVE-2026-46333) — Linux Kernel ptrace/pidfd_getfd Race Condition, Public PoC (CHARON)](https://intel.threadlinqs.com/threat/TL-2026-1503) — HIGH — 2026-07-18
- [Krybit Ransomware — Babuk-Derived RaaS Operation Emerges with Double Extortion](https://intel.threadlinqs.com/threat/TL-2026-1263) — HIGH — 2026-07-13

## Threat actors targeting Linux

Named threat actors attributed to campaigns that involve Linux products or CVEs, with the number of linked campaigns:

- [APT32](https://intel.threadlinqs.com/actor/APT32) — 2 campaigns
- [Calypso](https://intel.threadlinqs.com/actor/Calypso) — 2 campaigns
- [Harvester](https://intel.threadlinqs.com/actor/Harvester) — 2 campaigns
- [VECT](https://intel.threadlinqs.com/actor/VECT) — 2 campaigns
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 1 campaign
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 1 campaign
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1 campaign
- [Chaos](https://intel.threadlinqs.com/actor/Chaos) — 1 campaign
- [Coinbase Cartel](https://intel.threadlinqs.com/actor/Coinbase%20Cartel) — 1 campaign
- [CoinbaseCartel](https://intel.threadlinqs.com/actor/CoinbaseCartel) — 1 campaign
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 1 campaign
- [Cytrox](https://intel.threadlinqs.com/actor/Cytrox) — 1 campaign

## How to prioritise Linux patching

This order follows the data Threadlinqs holds for Linux, not a generic severity checklist:

- 14 of 70 Linux CVEs (20%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with [CVE-2016-5195](https://intel.threadlinqs.com/cve/CVE-2016-5195), [CVE-2022-0847](https://intel.threadlinqs.com/cve/CVE-2022-0847), [CVE-2023-0386](https://intel.threadlinqs.com/cve/CVE-2023-0386).
- 1 CVE is known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are [CVE-2026-43500](https://intel.threadlinqs.com/cve/CVE-2026-43500) (27%), [CVE-2026-43284](https://intel.threadlinqs.com/cve/CVE-2026-43284) (25.6%), [CVE-2026-64530](https://intel.threadlinqs.com/cve/CVE-2026-64530) (0.5%).
- 1 CVE scores Critical and 28 High on CVSS v3 (maximum 9.8, average 7.7); sequence these after KEV and high-EPSS items.
- 11 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/linux
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
