Vendor
Linux vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 6,993 vulnerabilities in Linux: 589 in the last 7 days and 3,684 in the last 90 days, 427 of them critical and 37 exploited in the wild. The most recent, CVE-2026-98163, was published on 26 September 2026. 1 technology has a page of its own.
- Last 7 days
- 589
- Last 90 days
- 3,684
- Critical, all time
- 427
- Exploited in the wild
- 37
About Linux
The developer of the open-source Linux kernel and associated software projects.
Linux technologies
- Linux Kernel6,418
Latest Linux vulnerabilities
- CVE-2026-98163: Linux kernel cgroup iterator use-after-free with dying tasksinfo
- CVE-2026-98162: Linux kernel SMB server tree connection resource leakinfo
- CVE-2026-98161: Linux kernel NVDIMM pmem ordering barrier bypass in flush handlinginfo
- CVE-2026-98160: Linux kernel rtl8723bs SDIO memory management errorinfo
- CVE-2026-100079: Linux kernel USB Type-C UCSI debugfs resource leakinfo
- CVE-2026-100078: Linux kernel iwlwifi MEI incorrect function argumentinfo
- CVE-2026-100077: Linux kernel DRM MSM GPU pagefault in recoveryinfo
- CVE-2026-100076: Linux kernel rtl8723bs xmit_frame/xmit_buf memory leakinfo
- CVE-2026-100075: Linux kernel RDMA/srpt integer underflow in send queue accountingcriticalCVSS 9.8
- CVE-2026-100074: Linux kernel BPF refcount field missing unique constraintinfo
- CVE-2026-100073: Linux kernel ext4 transaction overflow during writebackinfo
- CVE-2026-100072: Linux kernel ACPI platform unsafe pointer dereferenceinfo
- CVE-2026-100071: Linux kernel HSR memory leak in device setup failureinfo
- CVE-2026-100070: Linux kernel netfilter SIP NAT packet offset parsing buginfo
- CVE-2026-98159: Linux kernel mt76 mt7921 bounds check bypass in CLC firmware parsinginfo
- CVE-2026-98158: Linux kernel ppp_async headroom panic in PPP frame reassemblyinfo
- CVE-2026-98157: Linux kernel EDAC device sysfs integer truncationinfo
- CVE-2026-98156: Linux kernel drm/virtio memory disclosure on Xen PV domainshighCVSS 7.8
- CVE-2026-98155: Linux kernel QAIC out-of-bounds read in resp_workerinfo
- CVE-2026-98154: Linux kernel NVMe-RDMA double cleanup in error handlinghighCVSS 7
- CVE-2026-98153: Linux kernel NVMe race condition in FDP placement id initializationinfo
- CVE-2026-98152: Linux kernel nvmet-rdma queue resource leakinfo
- CVE-2026-98151: Linux kernel BPF verifier register invariants violation in speculative pointer arithmeticinfo
- CVE-2026-98150: Linux kernel BPF validation logic error in sparse CPU ID handlinghighCVSS 7
- CVE-2026-98149: Linux kernel BPF map update out-of-bounds read with sparse CPU IDsinfo
Most severe Linux vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-10585: Google Chrome type confusion in V8 enginecriticalexploited in the wildCVSS 9.8EPSS 5.4%
- CVE-2025-39682: Linux Kernel memory corruption in TLS zero-length record handlingcriticalexploited in the wildCVSS 9.8EPSS 2.9%
- CVE-2026-5281: Google Chrome use after free in Dawncriticalexploited in the wildCVSS 8.8EPSS 5.0%
- CVE-2025-13223: Google Chrome type confusion in V8 enginecriticalexploited in the wildCVSS 8.8EPSS 4.8%
- CVE-2013-6282: Linux Kernel Improper Input Validation Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2022-0185: Linux Kernel Heap-Based Buffer Overflow Vulnerabilitycriticalexploited in the wildCVSS 8.4
- CVE-2013-2094: Linux Kernel Privilege Escalation Vulnerabilitycriticalexploited in the wildCVSS 8.4
- CVE-2023-0266: Linux Kernel Use-After-Free Vulnerabilitycriticalexploited in the wildCVSS 7.9
- CVE-2021-22555: Linux Kernel heap out-of-bounds write in Netfilter x_tablescriticalexploited in the wildCVSS 7.8EPSS 86.3%
- CVE-2023-0386: Linux Kernel privilege escalation in OverlayFScriticalexploited in the wildCVSS 7.8EPSS 54.2%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 28 | 1 | |
| 6 Jul 2026 | 1 | 0 | |
| 13 Jul 2026 | 321 | 0 | |
| 20 Jul 2026 | 255 | 0 | |
| 27 Jul 2026 | 27 | 0 | |
| 3 Aug 2026 | 19 | 2 | |
| 10 Aug 2026 | 546 | 82 | |
| 17 Aug 2026 | 158 | 22 | |
| 24 Aug 2026 | 249 | 41 | |
| 31 Aug 2026 | 204 | 1 | |
| 7 Sep 2026 | 420 | 66 | |
| 14 Sep 2026 | 867 | 32 | |
| 21 Sep 2026 | 589 | 20 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/linux.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Linux vulnerabilities", https://junglewise.ai/threats/vendors/linux, 26 September 2026.