Incus
Vendor:
First CVE: Nov 10, 2025 · Active for under a year
18
Total CVEs
More Total CVEs than 93% of tracked products
9.0
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Incus over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 10, 2025
8 months ago
Most Recent CVE
May 7, 2026
78 days ago
CVE Severity & Scoring
Incus18 CVEs
61%
28%
11%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (11.1%)
Network14 (77.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (11.1%)
Attack Complexity
Low16 (88.9%)
High2 (11.1%)
Unknown0 (0.0%)
User Interaction
None17 (94.4%)
Unknown0 (0.0%)
Required1 (5.6%)
Privileges Required
Low15 (83.3%)
High0 (0.0%)
None3 (16.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33945CRITICAL Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For containers, this is handled through a sh | Mar 26, 2026 | 9.6 | 37 | NO | NO |
CVE-2026-33897CRITICAL Incus is a system container and virtual machine manager. Prior to version 6.23.0, instance template files can be used to cause arbitrary read or writes as root on the host server. | Mar 26, 2026 | 9.9 | 35 | NO | NO |
CVE-2026-33898HIGH Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui` incorrectly validates the authentication token such that a | Mar 27, 2026 | 8.8 | 31 | NO | NO |
CVE-2026-23954HIGH Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom image (e.g a member of the ‘inc | Jan 22, 2026 | 8.7 | 31 | NO | NO |
CVE-2026-23953HIGH Incus is a system container and virtual machine manager. In versions 6.20.0 and below, a user with the ability to launch a container with a custom YAML configuration (e.g a member | Jan 22, 2026 | 8.7 | 30 | NO | NO |
CVE-2026-40197MEDIUM Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated user with acc | May 6, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-33711HIGH Incus is a system container and virtual machine manager. Incus provides an API to retrieve VM screenshots. That API relies on the use of a temporary file for QEMU to write the scre | Mar 26, 2026 | 7.8 | 27 | NO | NO |
CVE-2026-40251MEDIUM Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated user with acc | May 6, 2026 | 6.5 | 26 | NO | NO |
CVE-2026-40195MEDIUM Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage bucket import logic allows an authenticated user with acc | May 6, 2026 | 6.5 | 26 | NO | NO |
CVE-2025-64507HIGH Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incus user in an environment where an unprivileged user may have | Nov 10, 2025 | 7.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (18 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (18 CVEs).
Media Mentions
Signals from CVEs in this product scope (18 CVEs).
Top CNAs Publishing CVEs For Incus
Top CWEs
Versions
No cataloged versions.