Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Kali Linux

Kali Linux Vendor Cyber Rating & Cyber Score

kali.org

Creating, developing and maintaining the Kali Linux penetration testing distribution while keeping it open-source and free for all.


Kali Linux A.I CyberSecurity Scoring

Kali Linux
Company Information
Website:http://www.kali.org
Employees number:341
Number of followers:0
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:kali.org
Kali Linux Risk Score (AI oriented)
Between 800 and 849
logo
Kali LinuxIT Services and IT Consulting
Updated:
05/08/2026
825/1000
Good
A
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Kali Linux Global Score (TPRM)
xxxx
logo
Kali LinuxIT Services and IT Consulting
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Kali Linux
Kali LinuxGood
Current Score
825A (GOOD)
01000
3 incidents
-2 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
825Before Incident
AUGUST 2026
825Before Incident
JULY 2026
824Before Incident
JUNE 2026
826Before Incident
MAY 2026
825Before Incident
APRIL 2026
825Before Incident
MARCH 2026
827Before Incident
Vulnerability
02 Mar 2026Kali Linux
Kali Forms: Hackers Exploit Kali Forms Vulnerability to Take Over WordPress Sites

Critical Kali Forms WordPress Plugin Vulnerability Exploited in the Wild

825After Incident
CRITICAL-2
KAL1776155151
Critical Kali Forms WordPress Plugin Vulnerability Exploited in the Wild A severe Remote Code Execution (RCE) vulnerability in Kali Forms, a popular WordPress plugin with over 10,000 active installations, has been actively exploited following its public disclosure. The flaw, tracked in versions up to and including 2.4.9, allows unauthenticated attackers to execute arbitrary code on vulnerable websites, leading to potential full site takeovers. ### Timeline of the Vulnerability - March 2, 2026: The RCE flaw was reported via a bug bounty program. - March 5, 2026: Wordfence Premium, Care, and Response users received firewall protection. - March 20, 2026: The vendor released Kali Forms 2.4.10, patching the issue. Exploitation began the same day. - April 4, 2026: Free Wordfence users gained firewall protection. - April 4–10, 2026: Peak exploitation activity was observed. ### Technical Root Cause The vulnerability stems from improper input validation in the plugin’s `prepare_post_data()` function, which processes user-supplied form data. Attackers can manipulate placeholders (e.g., `{entryCounter}`) to inject malicious PHP function names, which are then executed via `call_user_func()`. A common attack vector involves forcing `wp_set_auth_cookie()` to bypass authentication and gain admin access. ### Active Exploitation & Attack Patterns Security monitoring detected over 312,200 exploit attempts targeting the flaw, with attacks peaking between April 4–10, 2026. Attackers sent automated requests to `admin-ajax.php`, leveraging manipulated form submissions to trigger RCE. Key attacking IPs included: - 209.146.60.26 (152,000+ blocked requests) - 49.156.40.126 (50,000+) - 124.248.183.139 (26,000+) ### Impact & Mitigation The vulnerability enables unauthenticated RCE, allowing attackers to compromise websites, steal data, or deploy malware. Users were urged to update to Kali Forms 2.4.10 immediately to mitigate risk. Exploitation remains ongoing, with threat actors continuing to scan for unpatched instances.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Data Compromised: Potential data theftSystems Affected: WordPress websites using Kali Forms (versions ≤ 2.4.9)Operational Impact: Full site takeovers, malware deploymentBrand Reputation Impact: Potential reputational damage for affected websites
DATA BREACH
Data Exfiltration: Potential data exfiltration
FEBRUARY 2026
827Before Incident
JANUARY 2026
826Before Incident
Vulnerability
26 Jan 2026Kali Linux
GNU: Over 800K GNU InetUtils telnetd Instances Exposed to RCE Attacks as PoC Released

Critical RCE Vulnerability in GNU InetUtils telnetd Exposes 800,000 Systems

827After Incident
CRITICAL-1
GNU1769439621
Critical RCE Vulnerability in GNU InetUtils telnetd Exposes 800,000 Systems A severe remote code execution (RCE) vulnerability, CVE-2026-24061, has been identified in the GNU InetUtils telnetd component, affecting approximately 800,000 exposed instances worldwide. The flaw, rated Critical (CVSS 9.8), allows unauthenticated attackers to execute arbitrary commands with root privileges on vulnerable systems. The vulnerability stems from inadequate input validation in the telnetd service, enabling threat actors to craft malicious payloads that compromise systems. Proof-of-concept exploits have already been demonstrated, increasing the risk of widespread attacks. Since telnetd often runs with elevated privileges on legacy systems, successful exploitation grants full control over affected infrastructure. Data from the Shadowserver Foundation’s Accessible Telnet Report reveals that exposed instances span multiple geographies and networks, with many systems running unpatched versions for extended periods. While safe vulnerability-specific scanning remains unavailable, organizations can use Shadowserver’s report to identify at-risk systems by cross-referencing their infrastructure against publicly accessible telnet services. Immediate remediation steps include disabling telnetd on public-facing systems, implementing network segmentation, and upgrading to patched versions of GNU InetUtils. For systems where telnetd cannot be removed, restricting access via firewall rules and monitoring for exploitation attempts is recommended. The combination of widespread exposure, exploit availability, and delayed patching makes this a high-priority threat for affected organizations.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Systems Affected: 800,000 exposed instancesOperational Impact: Full control over affected infrastructure
DECEMBER 2025
826Before Incident
NOVEMBER 2025
826Before Incident
OCTOBER 2025
826Before Incident
JANUARY 2025
826Before Incident
Vulnerability
01 Jan 2025Kali Linux
AlmaLinux, Fedora, Linux Kernel, Debian, Ubuntu, Rocky Linux, Amazon Linux, Linux Mint and Kali Linux: New OVSwrap Linux Vulnerability Lets Attackers Gain Root Access

New Linux Kernel Vulnerability (CVE-2026-64531) Enables Local Privilege Escalation via OVSwrap Flaw

827After Incident
CRITICAL-1
TUXUBUROCDEBTHEAMAKALFED1785940491
New Linux Kernel Vulnerability (CVE-2026-64531) Enables Local Privilege Escalation via OVSwrap Flaw A critical Linux kernel vulnerability, tracked as CVE-2026-64531 and dubbed OVSwrap, has been disclosed, allowing unprivileged local users to escalate privileges to root on a wide range of Linux distributions. The flaw resides in the Open vSwitch (OVS) kernel datapath, a networking component commonly used in cloud, container, and virtualization environments. The vulnerability was discovered by researcher Asim Viladi Oglu Manizada using an experimental approach combining large language models with structured memory-geometry visualizations to analyze complex kernel memory bugs. The issue stems from a 16-bit length field limitation in Netlink attributes, which OVS uses to store network actions. While the kernel permits action streams exceeding 64 KiB, it failed to validate whether individual nested actions such as a CLONE wrapping multiple small conntrack actions remained under the 16-bit ceiling. When an attacker crafts an action large enough to exceed 65,535 bytes, the stored length value wraps around to a small number. The kernel then misinterprets attacker-controlled data as legitimate actions, enabling exploitation without memory grooming. The attack is highly reliable, resembling a logic bug rather than a traditional memory-corruption flaw. Exploitation requires no pre-existing OVS bridge, daemon, or administrative rights an unprivileged local user can trigger the vulnerability by creating a user and network namespace (e.g., via `unshare -Urn`), gaining CAP_NET_ADMIN, and initializing a private OVS datapath. Since most distributions ship OVS as a loadable kernel module that auto-loads on demand, the attack surface exists even on systems where OVS was never explicitly installed. The flaw affects default configurations across major Linux distributions, including AlmaLinux, Debian, Fedora, Ubuntu, Rocky Linux, Arch Linux, openSUSE Tumbleweed, Amazon Linux, Kali Linux, NixOS, and Linux Mint. Some systems require minor configuration adjustments, while older kernel branches (pre-2025) remain unaffected. The vulnerable code existed for 13 years but only became exploitable after a size limit was removed in 2025. Patches have been released in stable kernel versions 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, and 7.1.5. Temporary mitigations include blacklisting the openvswitch module, disabling unprivileged user namespaces, or deploying an emergency BPF-based mitigation released alongside the proof-of-concept.
INCIDENT DETAILS -
TYPE
Local Privilege Escalation
IMPACT
Systems Affected: Linux distributions with vulnerable Open vSwitch kernel moduleOperational Impact: Potential full system compromise via root access

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Kali Linux ?
?
What was Kali Linux's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Kali Linux's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Kali Linux's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Kali Linux's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Kali Linux's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Kali Linux's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Kali Linux's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Kali Linux's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Kali Linux's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Kali Linux's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Kali Linux's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on Kali Linux's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Kali Linux ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Kali Linux's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?