20 Total CVEs
20 AI Analyzed
0 CISA KEV
14 Critical

Profile

0% ended up actively exploited 0 of 20 added to CISA KEV
70% rated critical (CVSS 9.0+) 14 critical, 6 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

20 CVEs in the last 12 months

Products

  • Incus14
  • incus2

2 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-20 of 20 CVEs
CVE-2026-63343
Analyzed
9.9
lxc Incus

An authenticated Incus user can read or overwrite arbitrary files on the host as root by using a crafted image with a symlink in the `metadata.yaml` f...

2026-08-22
CVE-2026-63125
Analyzed
9.9
lxc Incus

An authenticated Incus user can achieve arbitrary code execution as root on the host by supplying a crafted image containing a symlink to a host file.

2026-08-22
CVE-2026-62941
Analyzed
9.9
lxc Incus

Incus versions prior to 7.3.0 contain an authorization flaw where instance configuration is merged before project restriction checks, allowing securit...

2026-08-22
CVE-2026-62940
Analyzed
9.9
lxc Incus

Incus versions prior to 7.3.0 fail to enforce project restrictions during instance migration, allowing restricted users to escalate privileges and esc...

2026-08-22
CVE-2026-62867
Analyzed
9.9
lxc Incus

Incus versions prior to 7.3.0 are vulnerable to argument injection in storage volume configuration, allowing project-scoped users to execute arbitrary...

2026-08-22
CVE-2026-55622
Analyzed
7.7
lxc Incus

Incus is a system container and virtual machine manager

2026-08-23
CVE-2026-55621
Analyzed
7.7
lxc Incus

Incus is a system container and virtual machine manager

2026-08-23
CVE-2026-48769
Analyzed
9.9
lxc incus

Incus client versions before 7.2.0 are vulnerable to an arbitrary file write flaw when processing a malicious Incus-Image-Hash header from an image se...

2026-08-22
CVE-2026-48755
Analyzed
9.9
lxc incus

Incus versions prior to 7.2.0 contain an argument injection vulnerability due to improper validation of backup compression algorithm inputs, enabling...

2026-08-22
CVE-2026-48753
Analyzed
9.9
lxc Incus

The S3 protocol endpoint in LXC Incus is vulnerable to path traversal, allowing authenticated users to create arbitrary files on the host system.

2026-08-22
CVE-2026-48752
Analyzed
9.9
lxc Incus

A file system vulnerability in LXC Incus allows authenticated users to read or write arbitrary files on the host system using crafted instance backups...

2026-08-22
CVE-2026-48751
Analyzed
9.9
lxc Incus

Incus instance snapshots improperly ignore security restrictions, allowing authenticated users to execute arbitrary commands on the host via lowlevel...

2026-08-22
CVE-2026-48750
Analyzed
9.9
lxc Incus

A symlink-based vulnerability in the Incus `/instances/$name/exec` endpoint allows authenticated users to write arbitrary content to host files, poten...

2026-08-22
CVE-2026-48749
Analyzed
9.9
lxc Incus

Incus versions prior to 7.2.0 are vulnerable to arbitrary file read, write, or creation via crafted images, potentially leading to arbitrary command e...

2026-08-22
CVE-2026-33945
Analyzed
9.9
lxc Incus

Incus versions prior to 6.23.0 are vulnerable to an arbitrary file write flaw where path traversal in systemd credential keys allows root-level writes...

2026-03-27
CVE-2026-33898
Analyzed
8.8
lxc Multiple Products

Incus is a system container and virtual machine manager

2026-03-27
CVE-2026-33897
Analyzed
9.9
lxc Incus

Incus versions prior to 6.23.0 contain a critical sandbox escape in the pongo2 template implementation that allows arbitrary file reads and writes as...

2026-03-27
CVE-2026-32606
Analyzed
7.6
lxc Multiple Products

IncusOS is an immutable OS image dedicated to running Incus

2026-03-18
CVE-2026-23954
Analyzed
8.7
lxc Multiple Products

Incus is a system container and virtual machine manager

2026-01-23
CVE-2026-23953
Analyzed
8.7
lxc Multiple Products

Incus is a system container and virtual machine manager

2026-01-23