GNU known exploited vulnerabilities
CISA lists 5 GNU CVEs as exploited in the wild. 2 were added in the last 12 months (latest 2026-01-26), and 0 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2014-6271 (Bourne-Again Shell (Bash)): EPSS 100.0%, added 2022-01-28
- CVE-2014-7169 (Bourne-Again Shell (Bash)): EPSS 99.9%, added 2022-01-28
- CVE-2014-6278 (GNU Bash): EPSS 99.6%, added 2025-10-02
- CVE-2026-24061 (InetUtils): EPSS 99.0%, added 2026-01-26
- CVE-2023-4911 (GNU C Library): EPSS 81.4%, added 2023-11-21
Most affected GNU products
Bourne-Again Shell (Bash) (2), InetUtils (1), GNU Bash (1), GNU C Library (1).
All GNU CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2026-24061 | InetUtils | InetUtils Argument Injection | 2026-01-26 | 2026-02-16 | 99.0% | – |
| CVE-2014-6278 | GNU Bash | Bash OS Command Injection | 2025-10-02 | 2025-10-23 | 99.6% | – |
| CVE-2023-4911 | GNU C Library | C Library Buffer Overflow | 2023-11-21 | 2023-12-12 | 81.4% | – |
| CVE-2014-7169 | Bourne-Again Shell (Bash) | Bourne-Again Shell (Bash) Arbitrary Code Execution | 2022-01-28 | 2022-07-28 | 99.9% | – |
| CVE-2014-6271 | Bourne-Again Shell (Bash) | Bourne-Again Shell (Bash) Arbitrary Code Execution | 2022-01-28 | 2022-07-28 | 100.0% | – |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors