Synced 12 Sept 2026 01:32 UTC Account
← All products

Debian

Debian · Operating System
↻ RSS feed
Monitors Debian and tailors your dashboard to that exact version.
13.6 · latest cycle5/100 Critical · exploited

Summary iPlain-English security verdict for Debian, generated from its current health score, actively-exploited vulnerabilities, and latest supported version.

Debian currently scores 5/100 — critical, with active exploitation. 13 of its known vulnerabilities are being actively exploited in the wild (CISA KEV), including CVE-2021-40438. The latest supported release is 13.6. Upgrade immediately and review your exposure to the actively-exploited CVEs below. Note: this product is assessed at the product level on recent (365-day) activity rather than an exact per-version match, so it is never marked a confident "healthy".

Disclosure trend iNew CVEs published for Debian each year (NVD). A higher bar means more disclosures that year — more scrutiny, not necessarily less safe.

'19
'20
'21
'22
'23
'24
'25
'26

7 of its known vulnerabilities are linked to ransomware campaigns (CISA KEV).

Get alerted about Debian

Be emailed the moment Debian gets a newly exploited vulnerability (CISA KEV) or a release reaches end of life. Free · double opt-in · unsubscribe anytime.

We email only on real events for Debian — no marketing, no sharing, and we never know what you run. Track your whole stack →

Monitor up to 200 products — freeHit ☆ Monitor on anything you run, then sign in (no password) to sync your stack across devices and unlock smart insights, risk history & CSV/JSON exports. Sign in free →

Versions & lifecycle iWhen each release line stops receiving security patches (end-of-life). After EOL there are no more fixes — plan upgrades before these dates.

How long each Debian release line is supported — and when it sunsets. Select a line for its full report.

Jun30'30 Debian 13EOL 2030-06-30
Jun30'28 Debian 12EOL 2028-06-30
Aug31'26 Debian 11ended 2026-08-31
Jun30'24 Debian 10ended 2024-06-30
Jul1'22 Debian 9ended 2022-07-01
Jun30'20 Debian 8ended 2020-06-30
May31'18 Debian 7ended 2018-05-31
Feb29'16 Debian 6ended 2016-02-29
Feb6'12 Debian 5ended 2012-02-06
Feb15'10 Debian 4ended 2010-02-15
Mar31'08 Debian 3.1ended 2008-03-31
Jun30'06 Debian 3.0ended 2006-06-30

Full Debian end-of-life dates & support timeline →

13 latest 13.6 Supported until 2030-06-30security notices → 12 latest 12.15 Supported until 2028-06-30security notices →
11 latest 11.11 End of life ended 2026-08-31
10 latest 10.13 End of life ended 2024-06-30
9 latest 9.13 End of life ended 2022-07-01
8 latest 8.11 End of life ended 2020-06-30
7 latest 7.11 End of life ended 2018-05-31
6 latest 6.0.10 End of life ended 2016-02-29
5 latest 5.0.10 End of life ended 2012-02-06
4 latest 4.0r9 End of life ended 2010-02-15
See all upcoming end-of-life dates →

Frequently asked

Is Debian safe and patched?

Debian currently scores 5/100 — critical, with active exploitation. 13 of its known vulnerabilities are being actively exploited in the wild (CISA KEV), including CVE-2021-40438. The latest supported release is 13.6. Upgrade immediately and review your exposure to the actively-exploited CVEs below. Note: this product is assessed at the product level on recent (365-day) activity rather than an exact per-version match, so it is never marked a confident "healthy".

What should I do about Debian now?

Upgrade Debian to the latest supported release (13.6) or later, which clears the actively-exploited issues affecting older versions, then confirm against Debian's official advisory.

When does Debian reach end-of-life?

The latest supported Debian release is 13.6. After end-of-life a release no longer receives security patches.

Which versions of Debian are still receiving security updates?

Supported Debian release lines (latest 13.6): 13, 12. End-of-life releases no longer receive security patches.

product-level posture (last 365d); exact per-version verdict pending precise version mapping

Informational only, from public data (NVD · CISA KEV · EPSS · endoflife.date), and can lag or miss vendor-specific fixes. Always confirm against Debian's official advisory before you patch or upgrade — Debian official site ↗