CVE reports

The Common Vulnerabilities and Exposures (CVE) system is used to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. Canonical keeps track of all CVEs affecting Ubuntu, and releases a security notice when an issue is fixed. You can find additional guidance for high-profile vulnerabilities in the Ubuntu Vulnerability Knowledge Base section


Search CVEs


Recent CVEs

CVE-2026-84782

High priority

Some fixes available 3 of 18

DTLS Retransmits Handshake Messages From a Stale Buffer Offset

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe


CVE-2026-63030

High priority
Needs evaluation

(WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a R ...)

1 affected package

wordpress


CVE-2026-87902

High priority
Needs evaluation

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active...

1 affected package

wordpress


CVE-2026-87491

High priority
Not affected

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

1 affected package

chromium-browser


CVE-2026-85046

High priority
Not affected

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

1 affected package

chromium-browser