Canonical has 31 CVEs on record between 2024 and 2026. Disclosure cadence is accelerating: 18 in the last 90 days against 7 in the 90 before. The busiest recent month was August 2026 with 11. The median CVSS is 9.1 (critical), with 16 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-22 (6) and CWE-863 (6). Most affected products: LXD (22), github.com/canonical/lxd (7), github.com/canonical/microceph/microceph (1).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 9.1
- Publish → KEV
- —
- Last 90 days
- 18 prev 7
Products
- LXD 22
- github.com/canonical/lxd 7
- github.com/canonical/microceph/microceph 1
- github.com/canonical/pebble 1
31
Total CVEs
16
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-63297Critical· 9.9An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies67CVE-2026-85526Critical· 9.9Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root via a …66CVE-2026-85185Critical· 9.6Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete arbitrary …65CVE-2026-66897Critical· 9.9A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root55CVE-2026-66898Critical· 9.9A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations55
Canonical vulnerabilities
CVEs affecting Canonical, newest first. Open any entry for full detail, references, and exploit status.
31 CVEsRSS