DirtyDecrypt PoC Released for Linux Kernel CVE-2026The Hacker News·May 20, 04:10 UTC · May 20, 2026Exploit / PoCCVE-2026-31635CVE-2026-31431CVE-2026-43284+4 CVEs60
Linux maintainers were infected for 2 years by SSHArs Technica · Security·May 15, 00:00 UTC · May 15, 2024Exploit / PoC60
Alchimist: A new attack framework in Chinese for Mac, Linux and WindowsCisco Talos·Oct 13, 12:00 UTC · Oct 13, 2022Exploit / PoC in the wildCVE-2021-4034160
Dirty COW — Critical Linux Kernel Flaw Being Exploited in the WildThe Hacker News·Oct 25, 15:07 UTC · Oct 25, 2016Exploit / PoC in the wildCVE-2016-519560
Bad Epoll Flaw Gives Attackers Root Access on Linux and AndroidSecurity Affairs·Jul 6, 08:24 UTC · Jul 6, 2026Exploit / PoC in the wildCVE-2026-46242CVE-2026-4307460
Google Hacker Discloses New Linux Kernel Vulnerability and PoC ExploitThe Hacker News·Sep 28, 08:35 UTC · Sep 28, 2018Exploit / PoCCVE-2018-1718260
Linux Operation Windigo hit 500000 PC and 25000 dedicated serversSecurity Affairs·Aug 6, 20:36 UTC · Aug 6, 2017Exploit / PoC60
U.S. CISA adds a flaw in Linux Kernel to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 4, 10:26 UTC · May 4, 2026Exploit / PoC in the wildCVE-2026-3143160
Copy Fail: New Linux bug enables Root via page‑cache corruptionSecurity Affairs·Apr 30, 18:23 UTC · Apr 30, 2026Exploit / PoCCVE-2026-31431160
New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache CorruptionThe Hacker News·May 15, 00:00 UTC · May 15, 2026Exploit / PoC in the wildCVE-2026-4630060
New Bootkit “Bootkitty” Targets Linux Systems via UEFIInfosecurity Magazine·Nov 27, 16:30 UTC · Nov 27, 2024Exploit / PoC60
Critical Flaws Discovered in Azure App That Microsoft Secretly Installs on Linux VMsThe Hacker News·Sep 17, 19:17 UTC · Sep 17, 2021Exploit / PoCCVE-2021-38647CVE-2021-38648CVE-2021-38645+1 CVEs60
Grinch Bug Could be worse than Shellshock, Says ExpertsSecurity Affairs·Nov 5, 23:20 UTC · Nov 5, 2018Exploit / PoC in the wild60
Zerodium offers up to $500,000 for Linux ZeroSecurity Affairs·Jul 1, 12:29 UTC · Jul 1, 2018Exploit / PoC60
Zero-Day Flaw in Linux Kernel Found by AIInfosecurity Magazine·May 1, 10:45 UTC · May 1, 2026Exploit / PoCCVE-2026-3143160
U.S. CISA adds Microsoft Office, GNU InetUtils, SmarterTools SmarterMail, and Linux Kernel flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 27, 14:54 UTC · Jan 27, 2026Exploit / PoC in the wildCVE-2018-14634CVE-2025-52691CVE-2026-21509+2 CVEs60
Dirty COW Linux kernel zero-day exploited in the wild is now patchedHelp Net Security·Oct 24, 02:10 UTC · Oct 24, 2016Exploit / PoC in the wildCVE-2016-519560
AI-Assisted Bug Hunt Uncovers Linux Kernel 0Infosecurity Magazine·Jul 28, 14:45 UTC · Jul 28, 2026Exploit / PoCCVE-2026-53264CVE-2026-6430060
New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits AndroidThe Hacker News·Jul 3, 19:41 UTC · Jul 3, 2026Exploit / PoC in the wildCVE-2026-46242CVE-2026-43074CVE-2026-31431+2 CVEs160
'Copy Fail' is a real Linux security crisis wrapped in AI slopCyberScoop·May 4, 21:56 UTC · May 4, 2026Exploit / PoC in the wildCVE-2026-3143160
PoC rootkit Curing evades traditional Linux detection systemsSecurity Affairs·Apr 28, 09:38 UTC · Apr 28, 2025Exploit / PoC60
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux HostsThe Hacker News·Aug 6, 17:58 UTC · Aug 6, 2026Exploit / PoC in the wildCVE-2026-64561CVE-2026-53359CVE-2026-4631660
OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become RootSecurity Affairs·Aug 5, 14:24 UTC · Aug 5, 2026Exploit / PoCCVE-2026-6453160
Januscape: 16-Year-Old Linux KVM Bug Enables Cloud VM Escape AttacksSecurity Affairs·Jul 7, 07:07 UTC · Jul 7, 2026Exploit / PoCCVE-2026-53359CVE-2026-46316CVE-2026-43284+1 CVEs60
16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 SystemsThe Hacker News·Jul 7, 04:58 UTC · Jul 7, 2026Exploit / PoCCVE-2026-53359CVE-2026-43284CVE-2026-43500+2 CVEs60
Nine CrackArmor Flaws in Linux AppArmor Enable Root Escalation, Bypass Container IsolationThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2026Exploit / PoC60
A zero-day in Atlas VPN Linux Client leaks users' IP addressSecurity Affairs·Sep 6, 16:50 UTC · Sep 6, 2023Exploit / PoC60
Hackers running Linux Operation Windigo are changing tactictsSecurity Affairs·Aug 6, 20:31 UTC · Aug 6, 2017Exploit / PoC60
Serbian student activist’s phone hacked using Cellebrite zero-day exploitSecurity Affairs·Mar 3, 09:08 UTC · Mar 3, 2025Exploit / PoCCVE-2024-53104CVE-2024-53197CVE-2024-5030260
Critical flaw in Linux APT package manager could allow remote hackSecurity Affairs·Jan 22, 21:00 UTC · Jan 22, 2019Exploit / PoCCVE-2019-346260
Hacking Ubuntu Linux distro exploiting the CrashDB code injection issueSecurity Affairs·Dec 16, 14:34 UTC · Dec 16, 2016Exploit / PoCCVE-2016-9949CVE-2016-9950CVE-2016-9951160
Unprivileged users could exploit AppArmor bugs to gain root accessSecurity Affairs·Mar 16, 08:05 UTC · Mar 16, 2026Exploit / PoC60
Atlas VPN zero-day allows sites to discover users' IP addressHelp Net Security·Sep 18, 19:49 UTC · Sep 18, 2023Exploit / PoC60
U.S. CISA adds Linux kernel and VMware ESXi and Workstation flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 5, 06:09 UTC · Mar 5, 2025Exploit / PoC in the wildCVE-2024-50302CVE-2025-22225CVE-2025-22224+3 CVEs60
Printer bug sends researchers into uproar, affects major Linux distrosCyberScoop·Sep 27, 11:41 UTC · Sep 27, 2024Exploit / PoCCVE-2024-47176CVE-2024-47076CVE-2024-47175+1 CVEs60
Week in review: Atlassian Confluence RCE PoC, new Kali Linux, Patch Tuesday forecastHelp Net Security·Jun 9, 00:00 UTC · Jun 9, 2024Exploit / PoCCVE-2024-21683CVE-2024-28995CVE-2024-29972+4 CVEs60
Just about every Windows and Linux device vulnerable to new LogoFAIL firmware attackArs Technica · Security·Dec 6, 15:02 UTC · Dec 6, 2023Exploit / PoC60
8-year-old Linux Kernel flaw DirtyCred is nasty as Dirty PipeSecurity Affairs·Aug 22, 17:51 UTC · Aug 22, 2022Exploit / PoCCVE-2022-0847CVE-2022-2588CVE-2021-415460
Critical PPP Daemon Flaw Opens Most Linux Systems to Remote HackersThe Hacker News·Mar 6, 14:17 UTC · Mar 6, 2020Exploit / PoC in the wildCVE-2020-859760
Red Hat Linux DHCP Client Found Vulnerable to Command Injection AttacksThe Hacker News·May 15, 00:00 UTC · May 15, 2018Exploit / PoCCVE-2018-111160