CVE Tools

Canonical

8,526 CVEs tracked since 2004. Since Jul 2021, 18 of them reached CISA KEV.

Canonical CVEs per month

Jul 2021 to Aug 2026. Point at a month, or focus the strip and use the arrow keys.
Canonical CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-07220
2021-08151
2021-0942
2021-10170
2021-11110
2021-1290
2022-01192
2022-02181
2022-03452
2022-04150
2022-05170
2022-06120
2022-07150
2022-08290
2022-09260
2022-10220
2022-11280
2022-12540
2023-0170
2023-02130
2023-03null or fewer
2023-04120
2023-05290
2023-06400
2023-07330
2023-08251
2023-09281
2023-10292
2023-11120
2023-1290
2024-01151
2024-02760
2024-03900
2024-041130
2024-054980
2024-06941
2024-071790
2024-081460
2024-091300
2024-102340
2024-111652
2024-122060
2025-011340
2025-023230
2025-03800
2025-04950
2025-052170
2025-061451
2025-071180
2025-08720
2025-091980
2025-102010
2025-11340
2025-121420
2026-01770
2026-02null or fewer
2026-03160
2026-04181
2026-05340
2026-0690
2026-0770
2026-08150

Products

The products that kept showing up in Canonical's monthly top three, with their CVEs summed over those months.

  1. Ubuntu4,33158 months
  2. Ubuntu Linux8626 months
  3. Lxd316 months
  4. Juju165 months
  5. Apport156 months
  6. Snapd94 months
  7. Ubuntu 22.04 Lts61 month
  8. Ubuntu 24.04 Lts61 month
  9. Ubuntu 26.04 Lts61 month
  10. Accountsservice54 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Canonical.

  1. CVE-2026-66897Instance template path traversal allows arbitrary host file write as root9.9
  2. CVE-2026-77113Path Traversal Vulnerability in apport-unpack—
  3. CVE-2026-61898accountsservice: shell injection via attacker-controlled ~/.pam_environment in Ubuntu language helper scripts7.8
  4. CVE-2026-61897accountsservice: incomplete privilege drop when running Ubuntu-specific language helper scripts7.8
  5. CVE-2026-16033Arbitrary file read+write on host via templates/ symlink in malicious image8.5
  6. CVE-2026-66898Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE9.9
  7. CVE-2026-63293Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root9.9
  8. CVE-2026-63294Root RCE via image backup.yaml symlink9.9
  9. CVE-2026-63295Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `security.idmap.isolated`4.3
  10. CVE-2026-63296Project restriction bypass via instance migration config override9.9
  11. CVE-2026-63297Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge9.9
  12. CVE-2026-63298LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration9.9
  13. CVE-2026-63299Storage volume cross-project move and snapshot restore bypass project disk limits9.9
  14. CVE-2026-62420Cross-project cluster migration bypasses project restrictions via cluster notification flag9.9
  15. CVE-2026-63300Cross-project instance move bypasses all project restrictions allowing host command execution9.9

The record

Peak rank
#1 in Sep 2010
Busiest month shown
May 2024, 498 CVEs
Months with a KEV entry
13 since Jul 2021
Monthly snapshots
231 since 2004
Canonical's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store