Ubuntu — Security Activity Report
Canonical Ubuntu (USN advisories)
Generated Oct 11, 2026Cohort: 9 vendors with ≥10 CVE advisoriesMethodology ↗
CVE Disclosure Volume
Total all-time: 30,286 CVEs with Ubuntu advisories. Source: NVD CVE records joined with vendor advisory publish dates.
Severity Composition
↓ -14.2 pp38.9% of Ubuntu's 30,286 CVEs are CRITICAL or HIGH severity. Industry median: 53.1%. Source: NVD CVSS v3.1.
CISA KEV Listings
↓ -0.4 pp39 of 13,087 Ubuntu CVEs in the last 3 years are on CISA's Known Exploited Vulnerabilities catalog (0.3%). Industry median: 0.7%.
Source: CISA Known Exploited Vulnerabilities catalog (current snapshot). KEV listing means CISA observed active in-the-wild exploitation.
Vendor Patch Velocity
Insufficient data to publish a reliable patch-velocity metric for Ubuntu(sample size: 0, minimum required: 10).
Top Recurring Weakness Classes
Most-frequently mapped CWEs across Ubuntu's last 3 years of CVE disclosures. Source: NVD — CWE mapping per MITRE taxonomy.
Recent Security Advisories
Latest advisories published by Ubuntu, straight from the vendor's own feed. Severity labels are the vendor's — scales differ across vendors.
- USN-8910-1
- USN-8909-1
- USN-8908-1
- USN-8906-1
- USN-8905-2
- USN-8905-1
- USN-8904-1
- USN-8903-2
Full advisory archive: /pulse/vendor-advisories →
Data sources & corrections
- NVD National Vulnerability Database (nvd.nist.gov) — CVE records + CVSS v3.1 severity
- MITRE cvelistV5 (github.com/CVEProject/cvelistV5) — CNA-published CVE timestamps
- CISA Known Exploited Vulnerabilities catalog (cisa.gov/known-exploited-vulnerabilities-catalog)
- Vendor security advisories (Red Hat RHSA, Ubuntu USN, Microsoft MSRC, Cisco PSIRT and other per-vendor feeds; the GitHub and OSV advisory databases are not used) — published_at timestamps
- MITRE CWE taxonomy (cwe.mitre.org) — weakness class mappings
Snapshot generated Oct 11, 2026: when these counts and industry medians were computed. Vendors in the index are recomputed every 6 hours.
Spot a factual error in this report?
Email [email protected] with the specific number you're disputing and a link to the authoritative source. We review every report and publish corrections on the methodology page.