Linux known exploited vulnerabilities
CISA lists 31 Linux CVEs as exploited in the wild. 9 were added in the last 12 months (latest 2026-09-18), and 2 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2022-0847 (Kernel): EPSS 92.8%, added 2022-04-25
- CVE-2016-5195 (Kernel): EPSS 83.5%, added 2022-03-03
- CVE-2021-22555 (Kernel): EPSS 78.7%, added 2025-10-06
- CVE-2019-13272 (Kernel): EPSS 52.2%, added 2021-12-10
- CVE-2021-3493 (Kernel): EPSS 49.2%, added 2022-10-20
Most affected Linux products
Kernel (31).
All Linux CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2026-53266 | Kernel | Kernel Out-of-Bounds Write | 2026-09-18 | 2026-09-21 | 0.6% | – |
| CVE-2025-39964 | Kernel | Kernel Race Condition | 2026-09-18 | 2026-09-21 | 1.0% | – |
| CVE-2025-39682 | Kernel | Kernel Improper Check for Unusual or Exceptional Conditions | 2026-09-18 | 2026-09-21 | 2.9% | – |
| CVE-2026-53362 | Kernel | Kernel Unspecified | 2026-08-27 | 2026-08-30 | 0.7% | – |
| CVE-2022-0995 | Kernel | Kernel Out-of-Bounds Write | 2026-08-26 | 2026-09-09 | 8.8% | – |
| CVE-2022-0492 | Kernel | Kernel Improper Authentication | 2026-06-02 | 2026-06-05 | 5.5% | – |
| CVE-2026-31431 | Kernel | Kernel Incorrect Resource Transfer Between Spheres | 2026-05-01 | 2026-05-15 | 3.4% | – |
| CVE-2018-14634 | Kernel | Kernel Integer Overflow | 2026-01-26 | 2026-02-16 | 14.7% | – |
| CVE-2021-22555 | Kernel | Kernel Heap Out-of-Bounds Write | 2025-10-06 | 2025-10-27 | 78.7% | – |
| CVE-2025-38352 | Kernel | Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition | 2025-09-04 | 2025-09-25 | 1.3% | – |
| CVE-2023-0386 | Kernel | Kernel Improper Ownership Management | 2025-06-17 | 2025-07-08 | 7.9% | – |
| CVE-2024-53197 | Kernel | Kernel Out-of-Bounds Access | 2025-04-09 | 2025-04-30 | 3.6% | – |
| CVE-2024-53150 | Kernel | Kernel Out-of-Bounds Read | 2025-04-09 | 2025-04-30 | 1.4% | – |
| CVE-2024-50302 | Kernel | Kernel Use of Uninitialized Resource | 2025-03-04 | 2025-03-25 | 0.8% | – |
| CVE-2024-53104 | Kernel | Kernel Out-of-Bounds Write | 2025-02-05 | 2025-02-26 | 3.4% | – |
| CVE-2017-1000253 | Kernel | Kernel PIE Stack Buffer Corruption | 2024-09-09 | 2024-09-30 | 10.7% | Yes |
| CVE-2022-0185 | Kernel | Kernel Heap-Based Buffer Overflow | 2024-08-21 | 2024-09-11 | 25.2% | – |
| CVE-2022-2586 | Kernel | Kernel Use-After-Free | 2024-06-26 | 2024-07-17 | 10.2% | – |
| CVE-2024-1086 | Kernel | Kernel Use-After-Free | 2024-05-30 | 2024-06-20 | 28.1% | Yes |
| CVE-2014-0196 | Kernel | Kernel Race Condition | 2023-05-12 | 2023-06-02 | 22.5% | – |
| CVE-2010-3904 | Kernel | Kernel Improper Input Validation | 2023-05-12 | 2023-06-02 | 14.5% | – |
| CVE-2023-0266 | Kernel | Kernel Use-After-Free | 2023-03-30 | 2023-04-20 | 3.7% | – |
| CVE-2021-3493 | Kernel | Kernel Privilege Escalation | 2022-10-20 | 2022-11-10 | 49.2% | – |
| CVE-2013-6282 | Kernel | Kernel Improper Input Validation | 2022-09-15 | 2022-10-06 | 39.7% | – |
| CVE-2013-2596 | Kernel | Kernel Integer Overflow | 2022-09-15 | 2022-10-06 | 3.2% | – |
| CVE-2013-2094 | Kernel | Kernel Privilege Escalation | 2022-09-15 | 2022-10-06 | 47.7% | – |
| CVE-2014-3153 | Kernel | Kernel Privilege Escalation | 2022-05-25 | 2022-06-15 | 37.2% | – |
| CVE-2022-0847 | Kernel | Kernel Privilege Escalation | 2022-04-25 | 2022-05-16 | 92.8% | – |
| CVE-2021-22600 | Kernel | Kernel Privilege Escalation | 2022-04-11 | 2022-05-02 | 6.5% | – |
| CVE-2016-5195 | Kernel | Kernel Race Condition | 2022-03-03 | 2022-03-24 | 83.5% | – |
| CVE-2019-13272 | Kernel | Kernel Improper Privilege Management | 2021-12-10 | 2022-06-10 | 52.2% | – |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors