Search
Find merged stories by title or summary.
U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog
U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added [ 1 , 2 ] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog : • CVE-2025-39682 – Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability • CVE-2025-39964 Linux Kernel Race Condition Vulnerability • CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability Below are detailed descriptions of the flaws: • CVE-2025-39682 (CVSS score: 9.8) – A flaw in the TLS receive path that fails to properly handle unexpected conditions, potentially allowing authenticated local users to expose sensitive memory contents or cause a denial-of-service (DoS).
CISA Warns of Linux Kernel Vulnerabilities Actively Exploited in Attacks
The U. S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that attackers are actively exploiting three Linux kernel vulnerabilities, creating an urgent patching and investigation deadline. CISA added CVE-2025-39682 , CVE-2026-53266 , and CVE-2025-39964 to its Known Exploited Vulnerabilities catalog on September 18, 2026, with remediation required by September 21 under Binding Operational Directive 26-04. The KEV catalog tracks vulnerabilities exploited in real-world attacks, while BOD 26-04 requires covered federal civilian agencies to accelerate remediation based on operational risk. CISA also marked all three vulnerabilities as requiring forensic triage, meaning affected agencies must investigate potentially exposed assets for evidence of compromise rather than treating patch installation as the only response activity.
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
The U. S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2025-39682 (CVSS score: 9.8) - An improper check for unusual or exceptional conditions vulnerability in the TLS receive path
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2025-39682 Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.
[CISA] CVE-2025-39682 - Confirmed Exploitation
CVE-2025-39682 Catalog: CISA Status: Confirmed Exploited: Yes Status Updated: 2026-09-18 00:00 UTC Evidence Sources: 1 First Seen: 2026-09-18 Asserted: 2026-09-18
You've reached the end of current stories for this search.
