Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Kali Linux

Kali Linux Vendor Cyber Rating & Cyber Score

kali.org

Creating, developing and maintaining the Kali Linux penetration testing distribution while keeping it open-source and free for all.


Kali Linux A.I CyberSecurity Scoring

Kali Linux
Company Information
Website:http://www.kali.org
Employees number:341
Number of followers:0
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:kali.org
Kali Linux Risk Score (AI oriented)
Between 800 and 849
logo
Kali LinuxIT Services and IT Consulting
Updated:
14/04/2026
825/1000
Good
A
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Kali Linux Global Score (TPRM)
xxxx
logo
Kali LinuxIT Services and IT Consulting
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Kali Linux
Kali LinuxGood
Current Score
825A (GOOD)
01000
2 incidents
-2 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
826Before Incident
MAY 2026
825Before Incident
APRIL 2026
825Before Incident
MARCH 2026
827Before Incident
Vulnerability
02 Mar 2026Kali Linux
Kali Forms: Hackers Exploit Kali Forms Vulnerability to Take Over WordPress Sites

Critical Kali Forms WordPress Plugin Vulnerability Exploited in the Wild

825After Incident
CRITICAL-2
KAL1776155151
Critical Kali Forms WordPress Plugin Vulnerability Exploited in the Wild A severe Remote Code Execution (RCE) vulnerability in Kali Forms, a popular WordPress plugin with over 10,000 active installations, has been actively exploited following its public disclosure. The flaw, tracked in versions up to and including 2.4.9, allows unauthenticated attackers to execute arbitrary code on vulnerable websites, leading to potential full site takeovers. ### Timeline of the Vulnerability - March 2, 2026: The RCE flaw was reported via a bug bounty program. - March 5, 2026: Wordfence Premium, Care, and Response users received firewall protection. - March 20, 2026: The vendor released Kali Forms 2.4.10, patching the issue. Exploitation began the same day. - April 4, 2026: Free Wordfence users gained firewall protection. - April 4–10, 2026: Peak exploitation activity was observed. ### Technical Root Cause The vulnerability stems from improper input validation in the plugin’s `prepare_post_data()` function, which processes user-supplied form data. Attackers can manipulate placeholders (e.g., `{entryCounter}`) to inject malicious PHP function names, which are then executed via `call_user_func()`. A common attack vector involves forcing `wp_set_auth_cookie()` to bypass authentication and gain admin access. ### Active Exploitation & Attack Patterns Security monitoring detected over 312,200 exploit attempts targeting the flaw, with attacks peaking between April 4–10, 2026. Attackers sent automated requests to `admin-ajax.php`, leveraging manipulated form submissions to trigger RCE. Key attacking IPs included: - 209.146.60.26 (152,000+ blocked requests) - 49.156.40.126 (50,000+) - 124.248.183.139 (26,000+) ### Impact & Mitigation The vulnerability enables unauthenticated RCE, allowing attackers to compromise websites, steal data, or deploy malware. Users were urged to update to Kali Forms 2.4.10 immediately to mitigate risk. Exploitation remains ongoing, with threat actors continuing to scan for unpatched instances.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Data Compromised: Potential data theftSystems Affected: WordPress websites using Kali Forms (versions ≤ 2.4.9)Operational Impact: Full site takeovers, malware deploymentBrand Reputation Impact: Potential reputational damage for affected websites
DATA BREACH
Data Exfiltration: Potential data exfiltration
FEBRUARY 2026
827Before Incident
JANUARY 2026
826Before Incident
Vulnerability
26 Jan 2026Kali Linux
GNU: Over 800K GNU InetUtils telnetd Instances Exposed to RCE Attacks as PoC Released

Critical RCE Vulnerability in GNU InetUtils telnetd Exposes 800,000 Systems

827After Incident
CRITICAL-1
GNU1769439621
Critical RCE Vulnerability in GNU InetUtils telnetd Exposes 800,000 Systems A severe remote code execution (RCE) vulnerability, CVE-2026-24061, has been identified in the GNU InetUtils telnetd component, affecting approximately 800,000 exposed instances worldwide. The flaw, rated Critical (CVSS 9.8), allows unauthenticated attackers to execute arbitrary commands with root privileges on vulnerable systems. The vulnerability stems from inadequate input validation in the telnetd service, enabling threat actors to craft malicious payloads that compromise systems. Proof-of-concept exploits have already been demonstrated, increasing the risk of widespread attacks. Since telnetd often runs with elevated privileges on legacy systems, successful exploitation grants full control over affected infrastructure. Data from the Shadowserver Foundation’s Accessible Telnet Report reveals that exposed instances span multiple geographies and networks, with many systems running unpatched versions for extended periods. While safe vulnerability-specific scanning remains unavailable, organizations can use Shadowserver’s report to identify at-risk systems by cross-referencing their infrastructure against publicly accessible telnet services. Immediate remediation steps include disabling telnetd on public-facing systems, implementing network segmentation, and upgrading to patched versions of GNU InetUtils. For systems where telnetd cannot be removed, restricting access via firewall rules and monitoring for exploitation attempts is recommended. The combination of widespread exposure, exploit availability, and delayed patching makes this a high-priority threat for affected organizations.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Systems Affected: 800,000 exposed instancesOperational Impact: Full control over affected infrastructure
DECEMBER 2025
826Before Incident
NOVEMBER 2025
826Before Incident
OCTOBER 2025
826Before Incident
SEPTEMBER 2025
826Before Incident
AUGUST 2025
826Before Incident
JULY 2025
826Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Kali Linux ?
?
What was Kali Linux's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Kali Linux's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Kali Linux's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Kali Linux's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Kali Linux's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Kali Linux's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Kali Linux's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Kali Linux's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Kali Linux's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Kali Linux's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Kali Linux's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Kali Linux's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Kali Linux ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Kali Linux's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?