← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 20, 2026 · 16:12via Security Affairs

U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog

Brief

U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog.

The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added [ 1 , 2 ] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog :

  • CVE-2025-39682 – Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
  • CVE-2025-39964 Linux Kernel Race Condition Vulnerability
  • CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability

Below are detailed descriptions of the flaws:

  • CVE-2025-39682 (CVSS score: 9.8) – A flaw in the TLS receive path that fails to properly handle unexpected conditions, potentially allowing authenticated local users to expose sensitive memory contents or cause a denial-of-service (DoS).
Read more on Security Affairs