CyberMax
Home › Exploited CVEs

GNU known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 5 GNU CVEs as exploited in the wild. 2 were added in the last 12 months (latest 2026-01-26), and 0 are known to be used in ransomware campaigns.

GNU CVEs added to CISA KEV per year
2022: 2202222023: 1202312025: 1202512026: 120261

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected GNU products

Bourne-Again Shell (Bash) (2), InetUtils (1), GNU Bash (1), GNU C Library (1).

All GNU CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2026-24061InetUtilsInetUtils Argument Injection2026-01-262026-02-1699.0%–
CVE-2014-6278GNU BashBash OS Command Injection2025-10-022025-10-2399.6%–
CVE-2023-4911GNU C LibraryC Library Buffer Overflow2023-11-212023-12-1281.4%–
CVE-2014-7169Bourne-Again Shell (Bash)Bourne-Again Shell (Bash) Arbitrary Code Execution2022-01-282022-07-2899.9%–
CVE-2014-6271Bourne-Again Shell (Bash)Bourne-Again Shell (Bash) Arbitrary Code Execution2022-01-282022-07-28100.0%–
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors