Canonical
8,526 CVEs tracked since 2004. Since Jul 2021, 18 of them reached CISA KEV.
Canonical CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2021-07 | 22 | 0 |
| 2021-08 | 15 | 1 |
| 2021-09 | 4 | 2 |
| 2021-10 | 17 | 0 |
| 2021-11 | 11 | 0 |
| 2021-12 | 9 | 0 |
| 2022-01 | 19 | 2 |
| 2022-02 | 18 | 1 |
| 2022-03 | 45 | 2 |
| 2022-04 | 15 | 0 |
| 2022-05 | 17 | 0 |
| 2022-06 | 12 | 0 |
| 2022-07 | 15 | 0 |
| 2022-08 | 29 | 0 |
| 2022-09 | 26 | 0 |
| 2022-10 | 22 | 0 |
| 2022-11 | 28 | 0 |
| 2022-12 | 54 | 0 |
| 2023-01 | 7 | 0 |
| 2023-02 | 13 | 0 |
| 2023-03 | null or fewer | |
| 2023-04 | 12 | 0 |
| 2023-05 | 29 | 0 |
| 2023-06 | 40 | 0 |
| 2023-07 | 33 | 0 |
| 2023-08 | 25 | 1 |
| 2023-09 | 28 | 1 |
| 2023-10 | 29 | 2 |
| 2023-11 | 12 | 0 |
| 2023-12 | 9 | 0 |
| 2024-01 | 15 | 1 |
| 2024-02 | 76 | 0 |
| 2024-03 | 90 | 0 |
| 2024-04 | 113 | 0 |
| 2024-05 | 498 | 0 |
| 2024-06 | 94 | 1 |
| 2024-07 | 179 | 0 |
| 2024-08 | 146 | 0 |
| 2024-09 | 130 | 0 |
| 2024-10 | 234 | 0 |
| 2024-11 | 165 | 2 |
| 2024-12 | 206 | 0 |
| 2025-01 | 134 | 0 |
| 2025-02 | 323 | 0 |
| 2025-03 | 80 | 0 |
| 2025-04 | 95 | 0 |
| 2025-05 | 217 | 0 |
| 2025-06 | 145 | 1 |
| 2025-07 | 118 | 0 |
| 2025-08 | 72 | 0 |
| 2025-09 | 198 | 0 |
| 2025-10 | 201 | 0 |
| 2025-11 | 34 | 0 |
| 2025-12 | 142 | 0 |
| 2026-01 | 77 | 0 |
| 2026-02 | null or fewer | |
| 2026-03 | 16 | 0 |
| 2026-04 | 18 | 1 |
| 2026-05 | 34 | 0 |
| 2026-06 | 9 | 0 |
| 2026-07 | 7 | 0 |
| 2026-08 | 15 | 0 |
Products
The products that kept showing up in Canonical's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Canonical.
- CVE-2026-66897Instance template path traversal allows arbitrary host file write as root9.9
- CVE-2026-77113Path Traversal Vulnerability in apport-unpack—
- CVE-2026-61898accountsservice: shell injection via attacker-controlled ~/.pam_environment in Ubuntu language helper scripts7.8
- CVE-2026-61897accountsservice: incomplete privilege drop when running Ubuntu-specific language helper scripts7.8
- CVE-2026-16033Arbitrary file read+write on host via templates/ symlink in malicious image8.5
- CVE-2026-66898Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE9.9
- CVE-2026-63293Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root9.9
- CVE-2026-63294Root RCE via image backup.yaml symlink9.9
- CVE-2026-63295Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `security.idmap.isolated`4.3
- CVE-2026-63296Project restriction bypass via instance migration config override9.9
- CVE-2026-63297Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge9.9
- CVE-2026-63298LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration9.9
- CVE-2026-63299Storage volume cross-project move and snapshot restore bypass project disk limits9.9
- CVE-2026-62420Cross-project cluster migration bypasses project restrictions via cluster notification flag9.9
- CVE-2026-63300Cross-project instance move bypasses all project restrictions allowing host command execution9.9
The record
- Peak rank
- #1 in Sep 2010
- Busiest month shown
- May 2024, 498 CVEs
- Months with a KEV entry
- 13 since Jul 2021
- Monthly snapshots
- 231 since 2004