Ubuntu security advisories
60 threat alerts tracking vulnerabilities and security advisories that affect Ubuntu products.
Vulnios monitors Ubuntu CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent Ubuntu security news in one place, or click into an individual alert for full detail.
USN-8779-2: Bubblewrap regression
USN-8779-1 fixed vulnerabilities in Bubblewrap. Unfortunately, the fix for CVE-2026-87766 introduced a regression in symlink resolution, preventing certain Flatpak applications from launching. This up
criticalCVE-2026-87766USN-8779-1: Bubblewrap vulnerabilities
It was discovered that Bubblewrap incorrectly handled certain temporary directories. A local attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue o
criticalCVE-2019-12439USN-8771-1: Valkey vulnerabilities
Madelyn Olson discovered that Valkey incorrectly handled TLS connections under certain conditions. A remote attacker could possibly use this issue to cause Valkey to crash, resulting in a denial of se
criticalCVE-2026-56684USN-8776-1: python-cryptography vulnerabilities
It was discovered that python-cryptography incorrectly accepted objects with immutable buffers when performing certain cipher operations. This would result in corrupted output, contrary to expectation
criticalCVE-2023-23931USN-8736-2: Perl vulnerabilities
USN-8736-1 fixed vulnerabilities in Perl. This update provides the corresponding fix for Perl on Ubuntu 24.04 LTS. Original advisory details: It was discovered that Perl incorrectly handled certain la
criticalCVE-2026-15534USN-8514-2: OpenSSH vulnerability
USN-8514-1 fixed a vulnerability in OpenSSH. This update provides the corresponding fix for Ubuntu 14.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory details: It was discovered that
criticalUSN-8770-1: SimpleSAMLphp vulnerabilities
It was discovered that SimpleSAMLphp incorrectly validated cryptographic signatures in XML messages. An authenticated attacker could possibly use this issue to impersonate users or gain elevated privi
criticalCVE-2019-3465USN-8763-1: kitty vulnerabilities
It was discovered that kitty incorrectly escaped error messages when handling specially crafted terminal escape sequences. A remote attacker could possibly use this issue to execute arbitrary commands
criticalCVE-2026-42850USN-8739-2: ImageMagick vulnerabilities
USN-8739-1 fixed vulnerabilities in ImageMagick. This update provides the corresponding fixes for Ubuntu 24.04 LTS. Original advisory details: It was discovered that ImageMagick incorrectly handled ce
criticalCVE-2026-56366USN-8749-1: CivetWeb vulnerabilities
It was discovered that CivetWeb did not correctly handle parsing certain URIs. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only a
criticalCVE-2025-55763USN-8744-1: Python vulnerabilities
It was discovered that Python's http.cookies module incorrectly handled control characters in certain cookie operations. An attacker could possibly use this issue to inject arbitrary content. This iss
criticalCVE-2026-3644USN-8737-2: GNU C Library vulnerabilities
USN-8737-1 fixed vulnerabilities in GNU C Library. This update provides the corresponding fixes for Ubuntu 24.04 LTS. Original advisory details: It was discovered that GNU C Library had a buffer overf
criticalCVE-2026-19499USN-8743-1: PHP vulnerabilities
It was discovered that PHP incorrectly handled backslash escaping in the PostgreSQL extension. An attacker could use this issue to perform SQL injection attacks. (CVE-2026-17543) It was discovered tha
criticalCVE-2026-17543USN-8741-1: Flatpak vulnerabilities
It was discovered that Flatpak did not properly validate paths in sandbox-expose options. A malicious or compromised Flatpak app could use app-controlled symlinks to access arbitrary host files and ga
criticalCVE-2026-34078USN-8675-2: Perl vulnerabilities
USN-8675-1 fixed vulnerabilities in Perl. This update provides the corresponding fix for Perl on Ubuntu 26.04 LTS. Original advisory details: It was discovered that Perl incorrectly handled short sour
criticalCVE-2026-12087USN-8716-2: FFmpeg vulnerabilities
USN-8716-1 fixed several vulnerabilities in FFmpeg. This update provides the corresponding fix for Ubuntu 26.04 LTS. Original advisory details: It was discovered that FFmpeg incorrectly handled certai
criticalCVE-2026-64830USN-8679-2: Vim vulnerability
USN-8679-1 fixed a vulnerability in Vim. This update provides the corresponding update for Ubuntu 26.04 LTS. Original advisory details: It was discovered that Vim incorrectly handled certain tags file
criticalUSN-8739-1: ImageMagick vulnerabilities
It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 L
criticalCVE-2026-56366USN-8670-3: curl vulnerability
USN-8670-1 fixed a vulnerability in curl. This update provides the corresponding update for Ubuntu 26.04 LTS. Original advisory details: Joshua Rogers discovered that curl incorrectly handled reusing
criticalUSN-8737-1: GNU C Library vulnerabilities
It was discovered that GNU C Library had a buffer overflow in the strfmon function when handling right-justification padding. An attacker could possibly use this issue to cause a denial of service or
criticalCVE-2026-19499USN-8724-1: rabbitmq-c vulnerabilities
It was discovered that the rabbitmq-c command-line tools only accepted credentials on the command line, making them visible to other local users through the process list. An attacker could possibly us
criticalCVE-2023-35789USN-8716-1: FFmpeg vulnerabilities
It was discovered that FFmpeg incorrectly handled certain crafted media files in the VobSub subtitle demuxer. An attacker could possibly use this issue to cause a denial of service or execute arbitrar
criticalCVE-2026-64830USN-8719-1: APR-util vulnerabilities
It was discovered that APR-util incorrectly performed password hash comparisons in a way that was not constant-time. An attacker could possibly use this issue to obtain sensitive information. (CVE-202
criticalCVE-2025-49506USN-8710-1: libevent vulnerabilities
Alexis Challande discovered that libevent incorrectly handled certain empty output buffers. An attacker could possibly use this issue to trigger a use-after-free, resulting in a denial of service or a
criticalCVE-2026-63381USN-8555-2: Ubuntu Advantage Tools (pro client) regression
USN-8555-1 fixed vulnerabilities in Ubuntu Advantage Tools. On Ubuntu 14.04 LTS only, it was discovered that some machines were unable to enable esm-infra-legacy due to a preemptive apt-helper check.
criticalCVE-2026-9494USN-8688-2: PAM vulnerability
USN-8688-1 fixed a vulnerability in PAM. This update provides the corresponding fix for PAM on Ubuntu 26.04 LTS. Original advisory details: Juthawong Naisanguansee discovered that PAM incorrectly clea
criticalUSN-8700-1: MySQL vulnerabilities
Multiple security issues were discovered in MySQL. MySQL has been updated to 8.4.11 in Ubuntu 26.04 LTS. Ubuntu 22.04 LTS and Ubuntu 24.04 LTS packages have been updated with backported patches. In ad
criticalUSN-8697-1: GNU Core Utilities vulnerabilities
It was discovered that GNU Core Utilities sort had a heap buffer under-read in its begfield() function. A local attacker could possibly use this issue to cause GNU Core Utilities to crash, resulting i
criticalCVE-2025-5278USN-8683-1: libheif vulnerabilities
Feng Ning discovered that libheif incorrectly handled certain image transforms. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS,
criticalCVE-2026-62289USN-8682-1: Bind vulnerabilities
Vitaly Simonovich discovered that Bind could exhaust memory during GSS-API TKEY negotiation. A remote attacker could possibly use this issue to cause Bind to use excessive resources, leading to a deni
criticalCVE-2026-3039USN-8680-1: FFmpeg vulnerabilities
Adrian Junge discovered that FFmpeg incorrectly handled certain subtitle data. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-70628) Adrian
criticalCVE-2026-70628USN-8670-2: curl vulnerability
USN-8670-1 fixed a vulnerability in curl. This update provides the corresponding update for Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. Original advisory details: Joshua Rogers discovere
criticalUSN-8654-1: Netty vulnerabilities
It was discovered that Netty did not properly handle malformed HTTP/2 control frames. An attacker could use this to cause a denial of service via resource exhaustion. This issue only affects Ubuntu 18
criticalCVE-2025-55163USN-8649-1: libheif vulnerabilities
It was discovered that libheif had an integer underflow in the Fraction constructor when a clap transform was applied twice. An attacker could possibly use this issue to cause libheif to crash, result
criticalCVE-2026-62289USN-8113-2: LibTIFF vulnerabilities
USN 8113-1 fixed vulnerabilities in tiff. This update provides the corresponding fixes for Ubuntu 26.04 LTS. Original advisory details: It was discovered that LibTIFF did not properly handle memory wh
criticalCVE-2025-61143USN-8648-1: Bind vulnerabilities
It was discovered that Bind incorrectly accepted NSEC3 records whose signer name did not match the owning zone. A remote attacker could possibly use this issue to perform NSEC3 impersonation attacks,
criticalCVE-2026-10723USN-8093-2: libssh vulnerability
USN-8093-1 fixed a vulnerability in libssh. This update provides the corresponsing fix for Ubuntu 26.04 LTS. Original advisory details: It was discovered that libssh incorrectly performed bounds check
criticalUSN-8639-1: libpng vulnerabilities
Patrick Keshishian discovered that libpng incorrectly handled certain text chunks. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 16.04 LTS. (C
criticalCVE-2016-10087USN-8638-1: Axios vulnerabilities
Ameer Assadi discovered that Axios did not properly handle certain hostnames when applying NO_PROXY rules. An attacker could possibly use this issue to bypass proxy restrictions and access internal se
criticalCVE-2025-62718USN-8628-1: libgit2 vulnerabilities
It was discovered that libgit2 incorrectly handled the Git Smart Protocol. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affec
criticalCVE-2016-10128USN-8592-1: ImageMagick vulnerabilities
Hao Ren discovered that ImageMagick incorrectly handled certain images when using the wavelet-denoise operation. An attacker could possibly use this issue to trigger an out-of-bounds heap write, resul
criticalCVE-2026-30936USN-8626-1: systemd vulnerabilities
It was discovered that systemd-homed did not properly verify the signature of home records. A local attacker could possibly use this issue to add arbitrary system groups to a logged-in user and gain e
criticalCVE-2026-16742USN-8611-1: GNU C Library vulnerabilities
It was discovered that the GNU C Library iconv function incorrectly handled certain IBM character sets. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-4046) It was d
criticalCVE-2026-4046USN-8588-1: Gawk vulnerabilities
It was discovered that Gawk incorrectly handled memory when processing input using the getline redirection. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-40467) It
criticalCVE-2026-40467USN-8584-1: GStreamer Good Plugins vulnerabilities
It was discovered that GStreamer Good Plugins incorrectly handled certain Matroska files. An attacker could possibly use this issue to cause GStreamer Good Plugins to crash, resulting in a denial of s
criticalCVE-2026-39043USN-8586-1: libgphoto2 vulnerabilities
It was discovered that libgphoto2 did not properly validate buffer boundaries when parsing EOS image format data. An attacker with physical access could possibly use this issue to obtain sensitive inf
criticalCVE-2026-40333USN-8580-2: AccountsService vulnerabilities
USN-8580-1 fixed vulnerabilities in AccountsService. This update provides the corresponding fixes for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory deta
criticalCVE-2026-61897USN-8582-1: jbig2dec vulnerabilities
Zeng Yunxiang and Song Jiaxuan discovered that jbig2dec had an out-of-bounds read vulnerability in its command-line tool. An attacker could possibly use this issue to cause jbig2dec to crash, resultin
criticalCVE-2023-46361USN-8580-1: AccountsService vulnerabilities
It was discovered that the Ubuntu-specific SetLanguage patch to AccountsService incorrectly handled dropping privileges. A local attacker could use this issue to execute arbitrary commands as an admin
criticalCVE-2026-61897USN-8579-1: snapd vulnerabilities
James Henstridge discovered that snapd's default apparmor template did not restrict access to systemd-userdbd varlink interface. A local attacker could possibly use this issue to obtain sensitive info
criticalCVE-2024-5300USN-8581-1: libarchive vulnerabilities
It was discovered that libarchive did not properly manage memory when unpacking certain RAR5 archives, leading to a double free. An attacker could possibly use this issue to cause a denial of service.
criticalCVE-2026-14164USN-8577-1: OpenSSH vulnerability
USN-8222-1 fixed a vulnerability in OpenSSH. This update provides the corresponding fix for Ubuntu 16.04 LTS. Original advisory details: Vladimir Tokarev discovered that OpenSSH incorrectly handled ce
criticalCVE-2026-35414USN-8558-1: ImageMagick vulnerabilities
It was discovered that ImageMagick did not limit mutual references between MVG files. An attacker could possibly use this issue to cause a stack overflow, resulting in a denial of service. This issue
criticalCVE-2025-68950USN-8573-1: libde265 vulnerabilities
It was discovered that libde265 did not properly manage memory under certain circumstances. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service. This
criticalCVE-2023-51792USN-8559-1: rlottie vulnerabilities
It was discovered that rlottie incorrectly handled certain shift operations. An attacker could possibly use this issue to cause rlottie to read out of bounds, resulting in a denial of service or expos
criticalCVE-2026-10305USN-8557-1: Authlib vulnerabilities
Jay Neiva and Mauro Carrillo discovered that Authlib did not properly validate cryptographic keys embedded in JWT headers. An attacker could possibly use this issue to forge trusted tokens, resulting
criticalCVE-2026-27962USN-8555-1: Ubuntu Advantage Tools (pro client) vulnerabilities
Bilal Teke discovered that Ubuntu Advantage Tools exposed the Pro bearer token in command-line arguments when validating APT credentials. A local attacker could possibly use this issue to obtain sensi
criticalCVE-2026-9494USN-8543-1: Wget vulnerabilities
It was discovered that Wget mishandled semicolons in the userinfo subcomponent of a URL. A remote attacker could possibly use this issue to trick a user into connecting to a different host than intend
criticalCVE-2024-38428USN-8541-1: Vim vulnerabilities
Hirohito Higashi discovered that Vim incorrectly escaped class or trait names when performing PHP omni-completion. An attacker could possibly use this issue to trick a user into opening a specially cr
criticalCVE-2026-59856USN-8526-2: libheif vulnerabilities
USN-8526-1 fixed vulnerabilities in libheif. This update provides the corresponding updates for CVE-2026-47709 and CVE-2026-47714 in Ubuntu 24.04 LTS. Original advisory details: Junyi Liu discovered t
criticalCVE-2026-47709
Showing the 60 most recent. Older alerts are archived but still reachable via search and the main feed.
Track Ubuntu exposure across your environment
Vulnios automatically cross-references your asset inventory against new Ubuntu CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan