High 7.0
KEV-listed
CVE-2016-5195
Kimwolf v7 Botnet Exploits Android TV Boxes and Linux Kernel
Vendor / product: Linux kernel, Android TV boxes, set-top boxes
Event date: 2025-09-02
Public PoC: Yes
First tracked by RiskWire: 2026-07-28
CISA KEV catalog
Added to KEV
Federal remediation due
2022-03-24 (1641 days overdue)
Ransomware campaign use
Unknown
CISA description
Race condition in mm/gup.c in the Linux kernel allows local users to escalate privileges.
Required action
Apply updates per vendor instructions.
Named threat actors
KimwolfAISURU
Sources & citations (1)
- Kimwolf v7: An Evolution of the Kimwolf Botnet unit42.paloaltonetworks.com · 2026-08-11
References
See CVE-2016-5195 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →