Vulnerabilities & Exploits

Debian Patches LXD Flaws Allowing Command Execution

Debian released security updates for LXD. Two vulnerabilities (CVE-2026-23953, CVE-2026-23954) can execute arbitrary commands via malformed images.

1 source · Mar 1

CVE-2026-23954

NVD KEV

CVSS 8.7 HIGH: incus is a system container and virtual machine manager. EPSS 0.7% (52nd percentile).

CVE-2026-23953

NVD KEV

CVSS 8.7 HIGH: incus is a system container and virtual machine manager. EPSS 0.5% (39th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-03-01

Every edition of this story: Debian Patches LXD Flaws Allowing Command Execution

More from today