Vendor

GNU

As of , 5 GNU vulnerabilities are on CISA's list of exploited vulnerabilities; 1 was added in 2026. Patch first: CVE-2014-6278.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2014-6278OS Command InjectionGNU GNU BashPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
2CVE-2014-6271Arbitrary Code ExecutionGNU Bourne-Again Shell (Bash)Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
3CVE-2026-24061Argument InjectionGNU InetUtilsPatch this weekMetasploit module; EPSS 0.990.99
4CVE-2023-4911Buffer OverflowGNU GNU C LibraryPatch this weekMetasploit module; EPSS 0.640.64
5CVE-2014-7169Arbitrary Code ExecutionGNU Bourne-Again Shell (Bash)Patch this weekEPSS 0.99; verified Exploit-DB entry0.99

Products

  • Bourne-Again Shell (Bash)2 entries
  • GNU Bash1 entry
  • GNU C Library1 entry
  • InetUtils1 entry

Added each year

0.511.522022: 2220222023: 1120232024: nonenone20242025: 1120252026: 112026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20222
20231
2024none
20251
20261

Used in ransomware