Technology · Linux
Linux Kernel vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 6,418 vulnerabilities in Linux Kernel: 17 in the last 7 days and 3,112 in the last 90 days, 423 of them critical and 37 exploited in the wild. The most recent, CVE-2026-89276, was published on 22 September 2026.
- Last 7 days
- 17
- Last 90 days
- 3,112
- Critical, all time
- 423
- Exploited in the wild
- 37
About Linux Kernel
The Linux kernel is an open-source, monolithic, Unix-like operating system kernel.
Latest Linux Kernel vulnerabilities
- CVE-2026-89276: Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability…criticalCVSS 9.9EPSS 0.5%
- CVE-2026-89275: Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability…criticalCVSS 10EPSS 1.3%
- CVE-2026-84412: Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability…criticalCVSS 10EPSS 1.3%
- CVE-2026-83660: Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in…criticalCVSS 9.9EPSS 0.3%
- CVE-2026-82443: Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in…criticalCVSS 9.6EPSS 0.4%
- CVE-2026-82013: Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in…criticalCVSS 9.9EPSS 0.8%
- CVE-2026-82011: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL…criticalCVSS 9.1EPSS 0.5%
- CVE-2026-82010: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL…criticalCVSS 9.9EPSS 1.0%
- CVE-2026-82009: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL…criticalCVSS 9.1EPSS 1.0%
- CVE-2026-82008: Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code…criticalCVSS 9.9EPSS 0.5%
- CVE-2026-82003: Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code…highCVSS 8.5EPSS 0.9%
- CVE-2026-75728: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code…criticalCVSS 9.1EPSS 1.0%
- CVE-2026-75723: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code…criticalCVSS 10EPSS 1.2%
- CVE-2026-75721: Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability…criticalCVSS 10EPSS 1.3%
- CVE-2026-75703: Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability…criticalCVSS 10EPSS 1.3%
- CVE-2026-75699: Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability…criticalCVSS 10EPSS 1.3%
- CVE-2026-73369: Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability…criticalCVSS 10EPSS 1.3%
- CVE-2026-93204: Linux kernel batman-adv data race in MAC address updateinfoEPSS 0.2%
- CVE-2026-93203: Linux kernel batman-adv CRC corruption in claim handlinghighCVSS 7.1EPSS 0.4%
- CVE-2026-93202: Linux kernel i3c master recursive locking deadlockinfoEPSS 0.2%
- CVE-2026-93201: Linux kernel dm-pcache out-of-bounds access via unvalidated segment IDhighCVSS 7.8EPSS 0.2%
- CVE-2026-93200: Linux kernel i3c master use-after-free in sysfs callbacksinfoEPSS 0.2%
- CVE-2026-93199: Linux kernel i3c master duplicate device logic errorinfoEPSS 0.2%
- CVE-2026-93198: Linux kernel dm-pcache infinite loop in dirty tail chain validationinfoEPSS 0.2%
- CVE-2026-93197: Linux kernel memcg LRU size accounting information disclosureinfoCVSS 0EPSS 0.2%
Most severe Linux Kernel vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-10585: Google Chrome type confusion in V8 enginecriticalexploited in the wildCVSS 9.8EPSS 5.4%
- CVE-2025-39682: Linux Kernel memory corruption in TLS zero-length record handlingcriticalexploited in the wildCVSS 9.8EPSS 2.9%
- CVE-2026-5281: Google Chrome use after free in Dawncriticalexploited in the wildCVSS 8.8EPSS 5.0%
- CVE-2025-13223: Google Chrome type confusion in V8 enginecriticalexploited in the wildCVSS 8.8EPSS 4.8%
- CVE-2013-6282: Linux Kernel Improper Input Validation Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2022-0185: Linux Kernel Heap-Based Buffer Overflow Vulnerabilitycriticalexploited in the wildCVSS 8.4
- CVE-2013-2094: Linux Kernel Privilege Escalation Vulnerabilitycriticalexploited in the wildCVSS 8.4
- CVE-2023-0266: Linux Kernel Use-After-Free Vulnerabilitycriticalexploited in the wildCVSS 7.9
- CVE-2021-22555: Linux Kernel heap out-of-bounds write in Netfilter x_tablescriticalexploited in the wildCVSS 7.8EPSS 86.3%
- CVE-2023-0386: Linux Kernel privilege escalation in OverlayFScriticalexploited in the wildCVSS 7.8EPSS 54.2%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 28 | 1 | |
| 6 Jul 2026 | 1 | 0 | |
| 13 Jul 2026 | 321 | 0 | |
| 20 Jul 2026 | 255 | 0 | |
| 27 Jul 2026 | 27 | 0 | |
| 3 Aug 2026 | 19 | 2 | |
| 10 Aug 2026 | 546 | 82 | |
| 17 Aug 2026 | 158 | 22 | |
| 24 Aug 2026 | 249 | 41 | |
| 31 Aug 2026 | 204 | 1 | |
| 7 Sep 2026 | 420 | 66 | |
| 14 Sep 2026 | 867 | 32 | |
| 21 Sep 2026 | 17 | 16 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/kernel.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Linux Kernel vulnerabilities", https://junglewise.ai/threats/technologies/kernel, 26 September 2026.