canonical security advisories
3 threat alerts tracking vulnerabilities and security advisories that affect canonical products.
Vulnios monitors canonical CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent canonical security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2026-28384 — canonical — lxd
An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the
criticalCVE-2026-28384Critical Vulnerability: CVE-2016-1580 — canonical — ubuntu_linux, ubuntu-core-launcher
The setup_snappy_os_mounts function in the ubuntu-core-launcher package before 1.0.27.1 improperly determines the mount point of bind mounts when using snaps, which might allow remote attackers to obt
criticalCVE-2016-1580Critical Vulnerability: CVE-2017-9232 — canonical — juju
Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege escalation by users on the system to root.
criticalCVE-2017-9232
Track canonical exposure across your environment
Vulnios automatically cross-references your asset inventory against new canonical CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan