Search
Find merged stories by title or summary.
U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog
U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added [ 1 , 2 ] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog : • CVE-2025-39682 – Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability • CVE-2025-39964 Linux Kernel Race Condition Vulnerability • CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability Below are detailed descriptions of the flaws: • CVE-2025-39682 (CVSS score: 9.8) – A flaw in the TLS receive path that fails to properly handle unexpected conditions, potentially allowing authenticated local users to expose sensitive memory contents or cause a denial-of-service (DoS).
CISA Warns of Linux Kernel Vulnerabilities Actively Exploited in Attacks
The U. S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that attackers are actively exploiting three Linux kernel vulnerabilities, creating an urgent patching and investigation deadline. CISA added CVE-2025-39682 , CVE-2026-53266 , and CVE-2025-39964 to its Known Exploited Vulnerabilities catalog on September 18, 2026, with remediation required by September 21 under Binding Operational Directive 26-04. The KEV catalog tracks vulnerabilities exploited in real-world attacks, while BOD 26-04 requires covered federal civilian agencies to accelerate remediation based on operational risk. CISA also marked all three vulnerabilities as requiring forensic triage, meaning affected agencies must investigate potentially exposed assets for evidence of compromise rather than treating patch installation as the only response activity.
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2025-39964 Linux Kernel Race Condition Vulnerability • CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.
[CISA] CVE-2026-53266 - Confirmed Exploitation
CVE-2026-53266 Catalog: CISA Status: Confirmed Exploited: Yes Status Updated: 2026-09-18 00:00 UTC Evidence Sources: 1 First Seen: 2026-09-18 Asserted: 2026-09-18
You've reached the end of current stories for this search.
