Vendor
Gnome vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 89 vulnerabilities in Gnome: 9 in the last 7 days and 47 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-91841, was published on 25 September 2026. 7 technologies have a page of their own.
- Last 7 days
- 9
- Last 90 days
- 47
- Critical, all time
- 1
- Exploited in the wild
- 0
About Gnome
GNOME is a free and open-source desktop environment for Unix-like operating systems.
Gnome technologies
Latest Gnome vulnerabilities
- CVE-2026-91841: NetworkManager-vpnc CA-File path newline injection privilege escalationhighCVSS 7.8
- CVE-2026-91840: NetworkManager-vpnc privilege escalation via newline injection in VPN usernamehighCVSS 7.8
- CVE-2026-91838: NetworkManager-sstp shell injection in VPN profile fieldshighCVSS 7.8
- CVE-2026-91837: NetworkManager-iodine command injection in nameserver optionhighCVSS 7.8
- CVE-2026-97222: Gnumeric heap use-after-free in XML parsingmediumCVSS 5.5
- CVE-2026-97185: GIMP out-of-bounds write in GIMPressionist pluginhighCVSS 7.8EPSS 0.1%
- CVE-2026-96889: librsvg use-after-free in XML entity parsinghighCVSS 7.8EPSS 0.1%
- CVE-2026-96545: GIMP out-of-bounds heap read in TIM image loadermediumCVSS 4.4EPSS 0.2%
- CVE-2026-96541: GNOME Remote Desktop denial-of-service in RDP connection handlinghighCVSS 7.5EPSS 0.8%
- CVE-2026-91786: GNOME Shell out-of-bounds read in remote search icon renderingmediumCVSS 6.1EPSS 0.2%
- CVE-2026-88924: GNOME gvfs privilege escalation via symlink TOCTOU in admin daemonhighCVSS 7EPSS 0.1%
- CVE-2026-88859: Evolution arbitrary JavaScript execution via spoofed vCardmediumCVSS 6.3EPSS 0.5%
- CVE-2026-18090: gdk-pixbuf heap out-of-bounds read in ICNS decompressionmediumCVSS 6.1EPSS 0.2%
- CVE-2026-74859: GNOME Tweaks path traversal in shell theme installermediumCVSS 6.8EPSS 0.2%
- CVE-2026-85534: libsoup HTTP/2 denial of service via buffer overflow in data callbackmediumCVSS 5.9EPSS 0.5%
- CVE-2026-85197: GNOME libsoup heap use-after-free in HTTP/2 clienthighCVSS 7.6EPSS 0.4%
- CVE-2026-84270: GNOME gvfs buffer overflow in MTP backendmediumCVSS 4.3EPSS 0.2%
- CVE-2026-84269: GNOME gvfs AFP backend heap buffer overflowmediumCVSS 6.5EPSS 0.4%
- CVE-2026-84268: GNOME gvfs SFTP backend heap overflowhighCVSS 8.8EPSS 0.6%
- CVE-2026-84267: GNOME gvfs SFTP buffer read vulnerabilitymediumCVSS 4.3EPSS 0.4%
- CVE-2026-81893: gdk-pixbuf out-of-bounds write in JPEG ICC profile parsermediumCVSS 4.7EPSS 0.1%
- CVE-2026-77652: GNOME Dia WPG heap buffer overflow in colormap parserhighCVSS 7.8EPSS 0.2%
- CVE-2026-77658: Dia diagram editor stack buffer overflow in bus objectshighCVSS 7.8EPSS 0.2%
- CVE-2026-77680: libsoup HTTP Range header algorithmic complexity denial of servicemediumCVSS 5.3EPSS 0.6%
- CVE-2026-78322: GNOME file-roller stack buffer overflow in archive parsingmediumCVSS 6.5EPSS 0.5%
Most severe Gnome vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2019-11068: Nokogiri libxslt protection mechanism bypass via crafted URLcriticalCVSS 9.8EPSS 1.1%
- CVE-2026-84268: GNOME gvfs SFTP backend heap overflowhighCVSS 8.8EPSS 0.6%
- CVE-2026-1761: GNOME libsoup stack-based buffer overflow in multipart response parsinghighCVSS 8.6EPSS 0.9%
- CVE-2026-0719: GNOME libsoup stack buffer overflow in NTLM authenticationhighCVSS 8.6EPSS 0.6%
- CVE-2025-14523: GNOME libsoup HTTP request smuggling via duplicate Host headershighCVSS 8.2EPSS 0.5%
- CVE-2025-7425: GNOME libxslt heap use-after-free in attribute managementhighCVSS 7.8EPSS 0.3%
- CVE-2026-77652: GNOME Dia WPG heap buffer overflow in colormap parserhighCVSS 7.8EPSS 0.2%
- CVE-2026-77658: Dia diagram editor stack buffer overflow in bus objectshighCVSS 7.8EPSS 0.2%
- CVE-2026-97185: GIMP out-of-bounds write in GIMPressionist pluginhighCVSS 7.8EPSS 0.1%
- CVE-2026-96889: librsvg use-after-free in XML entity parsinghighCVSS 7.8EPSS 0.1%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 7 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 6 | 0 | |
| 20 Jul 2026 | 8 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 1 | 0 | |
| 24 Aug 2026 | 5 | 0 | |
| 31 Aug 2026 | 6 | 0 | |
| 7 Sep 2026 | 4 | 0 | |
| 14 Sep 2026 | 1 | 0 | |
| 21 Sep 2026 | 9 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/gnome.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Gnome vulnerabilities", https://junglewise.ai/threats/vendors/gnome, 26 September 2026.