How we count
Every figure on this page is a direct count of entries in CISA’s Known Exploited Vulnerabilities catalog attributed by CISA to Linux (KEV field vendorProject), refreshed daily. “Ransomware-linked” counts entries CISA marks as known to be used in ransomware campaigns; the remainder are “unknown” to CISA, not confirmed ransomware-free. A KEV listing means the vulnerability has been observed exploited in the wild. Snapshot as of 2026-08-31.
Exploited Linux vulnerabilities (CISA KEV)
| CVE | Product | Vulnerability | Added | |
|---|---|---|---|---|
| CVE-2026-53362 | Kernel | Linux Kernel Unspecified Vulnerability | 2026-08-27 | |
| CVE-2022-0995 | Kernel | Linux Kernel Out-of-Bounds Write Vulnerability | 2026-08-26 | |
| CVE-2022-0492 | Kernel | Linux Kernel Improper Authentication Vulnerability | 2026-06-02 | |
| CVE-2026-31431 | Kernel | Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability | 2026-05-01 | |
| CVE-2018-14634 | Kernel | Linux Kernel Integer Overflow Vulnerability | 2026-01-26 | |
| CVE-2021-22555 | Kernel | Linux Kernel Heap Out-of-Bounds Write Vulnerability | 2025-10-06 | |
| CVE-2025-38352 | Kernel | Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability | 2025-09-04 | |
| CVE-2023-0386 | Kernel | Linux Kernel Improper Ownership Management Vulnerability | 2025-06-17 | |
| CVE-2024-53150 | Kernel | Linux Kernel Out-of-Bounds Read Vulnerability | 2025-04-09 | |
| CVE-2024-53197 | Kernel | Linux Kernel Out-of-Bounds Access Vulnerability | 2025-04-09 | |
| CVE-2024-50302 | Kernel | Linux Kernel Use of Uninitialized Resource Vulnerability | 2025-03-04 | |
| CVE-2024-53104 | Kernel | Linux Kernel Out-of-Bounds Write Vulnerability | 2025-02-05 | |
| CVE-2017-1000253 | Kernel | Linux Kernel PIE Stack Buffer Corruption Vulnerability | 2024-09-09 | ransomware |
| CVE-2022-0185 | Kernel | Linux Kernel Heap-Based Buffer Overflow Vulnerability | 2024-08-21 | |
| CVE-2022-2586 | Kernel | Linux Kernel Use-After-Free Vulnerability | 2024-06-26 | |
| CVE-2024-1086 | Kernel | Linux Kernel Use-After-Free Vulnerability | 2024-05-30 | ransomware |
| CVE-2014-0196 | Kernel | Linux Kernel Race Condition Vulnerability | 2023-05-12 | |
| CVE-2010-3904 | Kernel | Linux Kernel Improper Input Validation Vulnerability | 2023-05-12 | |
| CVE-2023-0266 | Kernel | Linux Kernel Use-After-Free Vulnerability | 2023-03-30 | |
| CVE-2021-3493 | Kernel | Linux Kernel Privilege Escalation Vulnerability | 2022-10-20 | |
| CVE-2013-6282 | Kernel | Linux Kernel Improper Input Validation Vulnerability | 2022-09-15 | |
| CVE-2013-2596 | Kernel | Linux Kernel Integer Overflow Vulnerability | 2022-09-15 | |
| CVE-2013-2094 | Kernel | Linux Kernel Privilege Escalation Vulnerability | 2022-09-15 | |
| CVE-2014-3153 | Kernel | Linux Kernel Privilege Escalation Vulnerability | 2022-05-25 | |
| CVE-2022-0847 | Kernel | Linux Kernel Privilege Escalation Vulnerability | 2022-04-25 | |
| CVE-2021-22600 | Kernel | Linux Kernel Privilege Escalation Vulnerability | 2022-04-11 | |
| CVE-2016-5195 | Kernel | Linux Kernel Race Condition Vulnerability | 2022-03-03 | |
| CVE-2019-13272 | Kernel | Linux Kernel Improper Privilege Management Vulnerability | 2021-12-10 |
← All vendors by exploited-vulnerability count
🤖 Generated by defend.network from the CISA KEV catalog. Counts are deterministic aggregates of official CISA data; verify individual advisories at the linked sources.