Vendor
Gnu vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 142 vulnerabilities in Gnu: 6 in the last 7 days and 63 in the last 90 days, 7 of them critical and 5 exploited in the wild. The most recent, CVE-2026-100310, was published on 25 September 2026. 14 technologies have a page of their own.
- Last 7 days
- 6
- Last 90 days
- 63
- Critical, all time
- 7
- Exploited in the wild
- 5
About Gnu
The GNU Project is a collaborative effort to provide a free software operating system and a wide range of software tools.
Gnu technologies
Latest Gnu vulnerabilities
- CVE-2026-100310: GNU libextractor privilege escalation via plugin search pathhighCVSS 7
- CVE-2026-96442: Emacs Flymake code execution via untrusted fileshighCVSS 7.8EPSS 0.2%
- CVE-2026-96269: GNU Emacs arbitrary code execution in symbol handlinginfoEPSS 0.1%
- CVE-2026-94574: GNU wget local code execution via hardcoded config pathhighCVSS 7.8EPSS 0.1%
- CVE-2026-86805: GNU C Library dynamic loader privilege escalation via TOCTOU racemediumCVSS 6.3EPSS 0.1%
- CVE-2026-95619: libstdc++ integer overflow in aligned operator newhighCVSS 7.7EPSS 0.4%
- CVE-2026-8674: GNU C Library DNS resolver assertion failure in search list parsingmediumCVSS 5.3EPSS 0.3%
- CVE-2026-80489: GNU C Library EUC_JISX0213 converter denial of servicemediumCVSS 5.9EPSS 0.4%
- CVE-2026-77117: GNU C Library SHIFT_JISX0213 converter hang in iconvmediumCVSS 5.9EPSS 0.4%
- CVE-2026-91782: GNU Binutils null pointer dereference in dynamic relocation allocationlowCVSS 3.3EPSS 0.2%
- CVE-2026-91781: GNU Binutils null pointer dereference in ELF section handlerlowCVSS 3.3EPSS 0.2%
- CVE-2026-91780: GNU Binutils null pointer dereference in ELF linkerlowCVSS 3.3EPSS 0.2%
- CVE-2026-91779: GNU Binutils null pointer dereference in eh_frame section offsetlowCVSS 3.3EPSS 0.2%
- CVE-2026-91752: GNU libextractor stack-based buffer overflow in OLE2 extractorhighCVSS 7.5EPSS 0.7%
- CVE-2026-90831: GNU Binutils memory corruption in ELF string table handlingmediumCVSS 5.3EPSS 0.2%
- CVE-2026-90830: GNU Binutils null pointer dereference in section mergemediumCVSS 5.3EPSS 0.2%
- CVE-2026-90829: GNU Binutils null pointer dereference in SHT_GROUP handlermediumCVSS 5.3EPSS 0.2%
- CVE-2026-90828: GNU Binutils null pointer dereference in ELF orphan section handlermediumCVSS 5.3EPSS 0.2%
- CVE-2026-19542: GNU C Library tdelete stack-based buffer overflowmediumCVSS 5.6EPSS 0.2%
- CVE-2026-19499: GNU C Library buffer overflow in strfmon right-justificationhighCVSS 7.7EPSS 0.3%
- CVE-2026-90804: GNU Binutils heap buffer overflow in eh_frame handlermediumCVSS 4.8EPSS 0.2%
- CVE-2026-90803: GNU Binutils buffer overflow in elf_x86_64_relocate_sectionmediumCVSS 5.3EPSS 0.2%
- CVE-2026-90802: GNU Binutils ld null pointer dereference in bfd_putl64mediumCVSS 4.4EPSS 0.2%
- CVE-2026-90801: GNU Binutils ld heap buffer overflow in cache_bwritemediumCVSS 5.3EPSS 0.2%
- CVE-2026-90622: GNU libredwg null pointer dereference in LAYER encodinglowCVSS 3.3EPSS 0.2%
Most severe Gnu vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2014-6278: GNU Bash OS command injection via environment variablescriticalexploited in the wildCVSS 10EPSS 91.4%
- CVE-2026-24061: GNU InetUtils argument injection in telnetdcriticalexploited in the wildCVSS 9.8EPSS 91.1%
- CVE-2014-6271: GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2014-7169: GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2023-4911: GNU C Library Buffer Overflow Vulnerabilitycriticalexploited in the wildCVSS 7.8
- CVE-2026-5450: GNU glibc heap buffer overflow in scanf %mc specifiercriticalCVSS 9.8EPSS 0.4%
- CVE-2015-8972: GNU Chess stack buffer overflow in ValidateMove functioncriticalCVSS 9.8
- CVE-2023-6246: GNU glibc heap buffer overflow in __vsyslog_internalhighCVSS 8.4
- CVE-2016-7543: GNU Bash privilege escalation via SHELLOPTS and PS4 variableshighCVSS 8.4
- CVE-2023-6779: GNU glibc heap buffer overflow in __vsyslog_internalhighCVSS 8.2
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 2 | 0 | |
| 6 Jul 2026 | 9 | 0 | |
| 13 Jul 2026 | 5 | 0 | |
| 20 Jul 2026 | 4 | 0 | |
| 27 Jul 2026 | 4 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 8 | 0 | |
| 17 Aug 2026 | 1 | 0 | |
| 24 Aug 2026 | 3 | 0 | |
| 31 Aug 2026 | 1 | 0 | |
| 7 Sep 2026 | 1 | 0 | |
| 14 Sep 2026 | 19 | 0 | |
| 21 Sep 2026 | 6 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/gnu.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Gnu vulnerabilities", https://junglewise.ai/threats/vendors/gnu, 26 September 2026.