CVE-2014-6278(gnu / bash)

LOWCVSS 8.8 · HIGHCISA KEV

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271, CVE-2014-7169, and CVE-2014-6277.

0.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-10-23. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bash

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • 3 total mentions across 1 day

Affected systems

Vendors
Products
bash

25 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-10-08: 310-08
Referenced assets1 URL
By indicator
Full discourse3 posts
  • ♫NØX♥H♪@_Why_Noot

    - GNU — GNU Bash | Ivanti — Pulse Connect Secure | GitLab — Community and Enterprise Editions → CVE-2014-6278 → Evidence → Operational Risk Current State: DISCLOSED, ACTIVE_EXPLOITATION, KEV_ADDED, RANSOMWARE_USE Watch: - New infrastructure - Exploit reuse

    1000039
    8 followersView on X
  • ♫NØX♥H♪@_Why_Noot

    NØX Echo Lineage Signal: CVE-2014-6278 Entity: GNU — GNU Bash | Ivanti — Pulse Connect Secure | GitLab — Community and Enterprise Editions Lineage: Public vulnerability → Observed exploitation → CISA KEV confirmation → Ransomware campaign use Relationship:

    1000054
    8 followersView on X
  • ♫Why♥Not♪@Python_s_

    NØØT Ransomware Watch Classification: Critical CVE: CVE-2014-6278 Product: GNU — GNU Bash | Ivanti — Pulse Connect Secure | GitLab — Community and Enterprise Editions Summary: CISA confirms active exploitation of CVE-2014-6278, CVE-2019-11510, CVE-2021-22205 through its KEV catalog. Affected products include: GNU — GNU Bash, Ivanti — Pulse Connect Secure. CISA also records known ransomware campaign use. Evidence: Active exploitation confirmed by CISA KEV; Ransomware activity; state-sponsored activity; active exploitation; compromise; intrusion; IoCs Impact: CISA confirms active exploitation of CVE-2014-6278, CVE-2019-11510, CVE-2021-22205 through its KEV catalog. Affected products include: GNU — GNU Bash, Ivanti — Pulse Connect Secure. CISA also records known ransomware campaign use. Action: Apply CISA and vendor remediation guidance to affected systems immediately and identify exposed assets. Date: 08 October 2026 Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a #NØØT #CyberSecurity #InfoSec #ThreatIntelligence #CyberThreats #CVE #CyberDefense #GNU_GNU_Bash_Ivanti_Pulse_Connect_Secure_GitLab_Co #CVE_2014_6278 #ActiveExploitation #Exploit #Ransomware #CISAKEV

    0000079
    227 followersView on X
CPE platform detail28 entries

28 of 28 entries

PartVendorProductVersionTarget SWTarget HW
Appgnubash1.14.0--
Appgnubash1.14.1--
Appgnubash1.14.2--
Appgnubash1.14.3--
Appgnubash1.14.4--
Appgnubash1.14.5--
Appgnubash1.14.6--
Appgnubash1.14.7--
Appgnubash2.0--
Appgnubash2.01--
Appgnubash2.01.1--
Appgnubash2.02--
Appgnubash2.02.1--
Appgnubash2.03--
Appgnubash2.04--
Appgnubash2.05--
Appgnubash2.05--
Appgnubash2.05--
Appgnubash3.0--
Appgnubash3.0.16--
Appgnubash3.1--
Appgnubash3.2--
Appgnubash3.2.48--
Appgnubash4.0--
Appgnubash4.0--
Appgnubash4.1--
Appgnubash4.2--
Appgnubash4.3--

Explore more