CyberMax
Home › Exploited CVEs

Linux known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 31 Linux CVEs as exploited in the wild. 9 were added in the last 12 months (latest 2026-09-18), and 2 are known to be used in ransomware campaigns.

Linux CVEs added to CISA KEV per year
2021: 1202112022: 8202282023: 3202332024: 4202442025: 7202572026: 820268

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected Linux products

Kernel (31).

All Linux CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2026-53266KernelKernel Out-of-Bounds Write2026-09-182026-09-210.6%–
CVE-2025-39964KernelKernel Race Condition2026-09-182026-09-211.0%–
CVE-2025-39682KernelKernel Improper Check for Unusual or Exceptional Conditions2026-09-182026-09-212.9%–
CVE-2026-53362KernelKernel Unspecified2026-08-272026-08-300.7%–
CVE-2022-0995KernelKernel Out-of-Bounds Write2026-08-262026-09-098.8%–
CVE-2022-0492KernelKernel Improper Authentication2026-06-022026-06-055.5%–
CVE-2026-31431KernelKernel Incorrect Resource Transfer Between Spheres2026-05-012026-05-153.4%–
CVE-2018-14634KernelKernel Integer Overflow2026-01-262026-02-1614.7%–
CVE-2021-22555KernelKernel Heap Out-of-Bounds Write2025-10-062025-10-2778.7%–
CVE-2025-38352KernelKernel Time-of-Check Time-of-Use (TOCTOU) Race Condition2025-09-042025-09-251.3%–
CVE-2023-0386KernelKernel Improper Ownership Management2025-06-172025-07-087.9%–
CVE-2024-53197KernelKernel Out-of-Bounds Access2025-04-092025-04-303.6%–
CVE-2024-53150KernelKernel Out-of-Bounds Read2025-04-092025-04-301.4%–
CVE-2024-50302KernelKernel Use of Uninitialized Resource2025-03-042025-03-250.8%–
CVE-2024-53104KernelKernel Out-of-Bounds Write2025-02-052025-02-263.4%–
CVE-2017-1000253KernelKernel PIE Stack Buffer Corruption2024-09-092024-09-3010.7%Yes
CVE-2022-0185KernelKernel Heap-Based Buffer Overflow2024-08-212024-09-1125.2%–
CVE-2022-2586KernelKernel Use-After-Free2024-06-262024-07-1710.2%–
CVE-2024-1086KernelKernel Use-After-Free2024-05-302024-06-2028.1%Yes
CVE-2014-0196KernelKernel Race Condition2023-05-122023-06-0222.5%–
CVE-2010-3904KernelKernel Improper Input Validation2023-05-122023-06-0214.5%–
CVE-2023-0266KernelKernel Use-After-Free2023-03-302023-04-203.7%–
CVE-2021-3493KernelKernel Privilege Escalation2022-10-202022-11-1049.2%–
CVE-2013-6282KernelKernel Improper Input Validation2022-09-152022-10-0639.7%–
CVE-2013-2596KernelKernel Integer Overflow2022-09-152022-10-063.2%–
CVE-2013-2094KernelKernel Privilege Escalation2022-09-152022-10-0647.7%–
CVE-2014-3153KernelKernel Privilege Escalation2022-05-252022-06-1537.2%–
CVE-2022-0847KernelKernel Privilege Escalation2022-04-252022-05-1692.8%–
CVE-2021-22600KernelKernel Privilege Escalation2022-04-112022-05-026.5%–
CVE-2016-5195KernelKernel Race Condition2022-03-032022-03-2483.5%–
CVE-2019-13272KernelKernel Improper Privilege Management2021-12-102022-06-1052.2%–
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors