Vendor
Linuxfoundation vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 16 vulnerabilities in Linuxfoundation: 0 in the last 7 days and 0 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-37532, was published on 1 May 2026. 2 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 2
- Exploited in the wild
- 0
About Linuxfoundation
A non-profit organization that provides a neutral home for open source projects and collaboration.
Linuxfoundation technologies
Latest Linuxfoundation vulnerabilities
- CVE-2026-37532: Automotive Grade Linux agl-service-can-low-level heap over-read in isotp-chighCVSS 7.1
- CVE-2026-37531: Automotive Grade Linux app-framework-main Zip Slip in widget installercriticalCVSS 9.8EPSS 0.1%
- CVE-2026-37530: Automotive Grade Linux agl-service-can-low-level stack overflow in uds-chighCVSS 7.5EPSS 0.0%
- CVE-2026-37526: Automotive Grade Linux afb-daemon improper access control in supervision sockethighCVSS 7.8EPSS 0.0%
- CVE-2026-37525: Automotive Grade Linux afb-daemon privilege escalation in supervision Do commandhighCVSS 7.8EPSS 0.0%
- CVE-2026-40938: Tekton Pipelines argument injection in Git resolver revision parameterhighCVSS 7.5EPSS 0.9%
- CVE-2026-40924: Tekton Pipelines DoS via unbounded memory allocation in HTTP resolvermediumCVSS 6.5EPSS 0.5%
- CVE-2026-40923: Tekton Pipelines path traversal in VolumeMount validationmediumCVSS 5.4EPSS 0.1%
- CVE-2026-40161: Tekton Pipelines credential exfiltration in Git resolver API modehighCVSS 7.7EPSS 0.0%
- CVE-2026-25542: Tekton Pipelines regex bypass in trusted resources verificationmediumCVSS 6.5EPSS 0.0%
- CVE-2026-34045: Podman Desktop DoS and information disclosure in WebView serverhighCVSS 8.2EPSS 0.4%
- CVE-2026-33701: OpenTelemetry Java Instrumentation RCE via Unsafe Deserialization in RMIcriticalCVSS 9.8EPSS 1.1%
- CVE-2026-29773: Kubewarden incorrect authorization in deprecated host-callback APIsmediumCVSS 4.3EPSS 0.3%
- CVE-2026-29186: Backstage TechDocs arbitrary code execution via MkDocs configuration bypasshighCVSS 7.7EPSS 0.9%
- CVE-2026-27134: Strimzi Kafka Operator improper authentication in mTLS CA chain validationhighCVSS 8.1EPSS 0.3%
- CVE-2025-66623: Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations…highCVSS 7.4EPSS 0.2%
Most severe Linuxfoundation vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-33701: OpenTelemetry Java Instrumentation RCE via Unsafe Deserialization in RMIcriticalCVSS 9.8EPSS 1.1%
- CVE-2026-37531: Automotive Grade Linux app-framework-main Zip Slip in widget installercriticalCVSS 9.8EPSS 0.1%
- CVE-2026-34045: Podman Desktop DoS and information disclosure in WebView serverhighCVSS 8.2EPSS 0.4%
- CVE-2026-27134: Strimzi Kafka Operator improper authentication in mTLS CA chain validationhighCVSS 8.1EPSS 0.3%
- CVE-2026-37526: Automotive Grade Linux afb-daemon improper access control in supervision sockethighCVSS 7.8EPSS 0.0%
- CVE-2026-37525: Automotive Grade Linux afb-daemon privilege escalation in supervision Do commandhighCVSS 7.8EPSS 0.0%
- CVE-2026-29186: Backstage TechDocs arbitrary code execution via MkDocs configuration bypasshighCVSS 7.7EPSS 0.9%
- CVE-2026-40161: Tekton Pipelines credential exfiltration in Git resolver API modehighCVSS 7.7EPSS 0.0%
- CVE-2026-40938: Tekton Pipelines argument injection in Git resolver revision parameterhighCVSS 7.5EPSS 0.9%
- CVE-2026-37530: Automotive Grade Linux agl-service-can-low-level stack overflow in uds-chighCVSS 7.5EPSS 0.0%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/linuxfoundation.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Linuxfoundation vulnerabilities", https://junglewise.ai/threats/vendors/linuxfoundation, 26 September 2026.