Vulnerability intelligence
CVE-2014-6278
GNU Bash OS Command Injection Vulnerability
GNU GNU Bash
GNU Bash contains an OS command injection vulnerability which allows remote attackers to execute arbitrary commands via a crafted environment.
CVSS Score
8.8
High
EPSS — Exploit Probability
—
Awaiting FIRST.org data
Exploitation
Confirmed in the wild
KEV since 2025-10-02
Remediation
Patch available
Federal deadline 2025-10-23
CISA required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Deadline for federal agencies: 2025-10-23.
1 article across 1 outlet · first covered Oct 8, 2026 · latest Oct 8, 2026
Associated threat actors
Coverage timeline
-
China-Based Hackers Accused of Stealing Emails Across 7 Countriesthehackernews.com · Oct 8, 2026