Ubuntu
This hub aggregates every CVE we track for Ubuntu, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
9,574
CVEs tracked
780
Critical
3,205
High
69
In CISA KEV
Severity distribution
MEDIUM5,254HIGH3,205CRITICAL780LOW335
Monthly trend
146
128
227
165
205
128
322
82
96
255
152
113
73
279
210
35
146
96
16
43
43
32
4
7
2024-082026-07
Latest CVEs
The 15 most recently published vulnerabilities affecting Ubuntu.
- CVE-2026-8933snap-confine Local Privilege Escalation via Capabilities Misconfiguration or Flaw in Execution Environment Setup7.8
- CVE-2026-15226snapd snap-confine Sandbox Confinement Bypass via Omission of setuid Restriction in Seccomp Templates8.4
- CVE-2024-5300AppArmor Base Profile Misconfiguration in snapd Permits Confined Snaps Unauthorized Access to Hashed Passwords via systemd-userdbd5.6
- CVE-2026-12391ubuntu-pro-client Local Privilege Escalation and Information Disclosure via Symlink Arbitrary File Read in collect-logs5.0
- CVE-2026-11386ubuntu-pro-client Input Validation Vulnerability Leading to Arbitrary APT Directive Injection and Remote Code Execution9.0
- CVE-2026-9494ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process Command Line5.5
- CVE-2026-10037Sandbox Escape in Ubuntu OpenJDK Packages via xdg-desktop-portal8.8
- CVE-2026-12249Canonical ADSys Trust Store Poisoning via Plaintext HTTP Certificate Auto-Enrollment9.0
- CVE-2026-35058Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attackers to trigger a fatal assertion and ...7.7
- CVE-2026-3238Samba: denial of service against ad dc wins server7.5
- CVE-2026-46243smb: client: reject userspace cifs.spnego descriptions7.1
- CVE-2026-47337NULL pointer dereference in Ubuntu Linux AppArmor IPv4/IPv6 socket mediation3.3
- CVE-2026-47336Use of uninitialized value in Ubuntu Linux AppArmor IPv4/IPv6 socket mediation rules3.3
- CVE-2026-47335NULL pointer dereference in Ubuntu Linux AppArmor notification handling5.5
- CVE-2026-47334Deadlock or kernel panic in Ubuntu Linux AppArmor notification handling5.5
Product normalization is registry-driven with AI assist and human review. How it works