boxscore/security
VENDOR · referenceVendors · latest edition

Reference page — cumulative record through Wednesday, October 7, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

Linux

Vendor reference — Linux · sector: Operating Systems & Platforms. Cumulative disclosure record across the archive.

Follow Linux — Atom feed

Career totals

Disclosures & known-exploited
All-timeYTD
CVEs100016413
KEV entries156
Rate & severity
KEV/100Med CVSSMed EPSSCHML
0.17.8.00215974557229013

KEV/100 = KEV entries ÷ CVEs × 100. Med CVSS / Med EPSS are medians over all disclosures. C/H/M/L = disclosures by CVSS severity band.

Monthly disclosures

Trend (by first-seen month, full archive): ▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▂▁▁▂▁▁▁▂▁▁▂▁▂▁▂▂▁▂▁▁▁▂▃▃▄▆█▂

Last 12 months (new CVEs by first-seen day)
MonthNew CVEs
2025-1145
2025-12345
2026-01115
2026-0254
2026-0365
2026-04209
2026-05655
2026-06513
2026-07836
2026-081643
2026-092115
2026-10208

Notable CVEs

Ranked by the published formula: KEV → EPSS → CVSS → CVE ID.

Notable (ranked)
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2024-10867.898.1HIGHYES2024-05-30
CVE-2018-146347.896.6HIGHYES2018-09-25
CVE-2021-226006.693.7MEDIUMYES2022-01-26
CVE-2024-531977.890.5HIGHYES2024-12-27
CVE-2023-02667.989.4HIGHYES2023-01-30
CVE-2026-314317.888.6HIGHYES2026-05-01
CVE-2024-531047.888.5HIGHYES2024-12-02
CVE-2025-396829.886.4CRITICALYES2025-09-05
CVE-2024-369717.885.5HIGHYES2024-08-07
CVE-2024-531507.170.7HIGHYES2024-12-24
CVE-2025-383527.869.3HIGHYES2025-09-04
CVE-2025-399645.569.0MEDIUMYES2025-10-13
CVE-2026-532668.856.1HIGHYES2026-06-25
CVE-2024-503025.555.5MEDIUMYES2024-11-19
CVE-2026-533627.852.0HIGHYES2026-07-04

Recent CVEs

Most recently seen
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2026-98372—4.7——2026-10-06
CVE-2026-98371—4.7——2026-10-06
CVE-2026-98370—5.9——2026-10-06
CVE-2026-98363—6.0——2026-10-06
CVE-2026-98362—6.0——2026-10-06
CVE-2026-98358—5.1——2026-10-06
CVE-2026-98356—4.7——2026-10-06
CVE-2026-98355—3.7——2026-10-06
CVE-2026-98354—5.9——2026-10-06
CVE-2026-98353—3.7——2026-10-06
CVE-2026-98352—5.5——2026-10-06
CVE-2026-98351—6.0——2026-10-06
CVE-2026-98350—8.5——2026-10-06
CVE-2026-98347—7.3——2026-10-06
CVE-2026-98346—6.4——2026-10-06

Products

This vendor's products with a reference page (≥2 disclosures), by CVE count. A monolithic vendor total dilutes signal; product pages sharpen it.

Products (by CVE count)
ProductCVEsKEV
Linux997411
Kernel203
Linux Kernel71

KEV entries

CISA Known Exploited Vulnerabilities (newest addition first)
CVEKEV addedCVSSEPSS %ileSeverity
CVE-2026-532662026-09-188.856.1HIGH
CVE-2025-399642026-09-185.569.0MEDIUM
CVE-2025-396822026-09-189.886.4CRITICAL
CVE-2026-533622026-08-277.852.0HIGH
CVE-2026-314312026-05-017.888.6HIGH
CVE-2018-146342026-01-267.896.6HIGH
CVE-2025-383522025-09-047.869.3HIGH
CVE-2024-531972025-04-097.890.5HIGH
CVE-2024-531502025-04-097.170.7HIGH
CVE-2024-503022025-03-045.555.5MEDIUM
CVE-2024-531042025-02-057.888.5HIGH
CVE-2024-369712024-08-077.885.5HIGH
CVE-2024-10862024-05-307.898.1HIGH
CVE-2023-02662023-03-307.989.4HIGH
CVE-2021-226002022-04-116.693.7MEDIUM

KEV timing

Longest unpatched (KEV due date passed)
CVEDueDays over
CVE-2021-226002022-05-021619
CVE-2023-02662023-04-201266
CVE-2024-10862024-06-20839
CVE-2024-369712024-08-28770
CVE-2024-531042025-02-26588
CVE-2024-503022025-03-25561
CVE-2024-531502025-04-30525
CVE-2024-531972025-04-30525
CVE-2025-383522025-09-25377
CVE-2018-146342026-02-16233

Methodology

Rate statistics are arithmetic over published figures: KEV/100 = KEV entries ÷ CVEs × 100; medians are taken over this vendor's disclosures. Vendor names are normalized (case, punctuation, common aliases) before aggregation; monthly counts are keyed to first-seen day, the day this archive first observed the record, not the upstream publication date.

Raw counts are not comparable across vendors: disclosure practices, product breadth, and CNA conventions differ widely, so a larger number here does not mean less secure software. This is a reference page assembled from the public record — not a record of its own, and not a ranking of vendors by our judgment.

Sources. CVE records from the CVE Program (cvelistV5); enrichment from NVD (NIST); known-exploited status from the CISA KEV catalog; exploit probability from FIRST EPSS.