CISA KEV Alert 18 Sept 2026, 15:31 UTC

CISA Warns of Actively Exploited Linux Kernel Memory Flaw

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Status Unknown

CISA has added CVE-2026-53266 to its Known Exploited Vulnerabilities (KEV) catalogue. The vulnerability affects Linux Kernel and is an out-of-bounds write in the ebtables SNAT target, which can rewrite an ARP sender hardware address directly into a nonlinear socket-buffer fragment backed by a splice-imported file page.

The flaw can allow memory to be written outside its intended bounds. The available data identifies the ebtables SNAT target and splice-imported file pages as the relevant components, but does not provide further details on authentication requirements or attack complexity. NVD rates the vulnerability 8.8 HIGH. Patch availability is currently unknown. CISA also warns that affected product versions could be end-of-life or end-of-service.

KEV inclusion confirms that attackers are actively exploiting the vulnerability. The available data does not confirm use in ransomware campaigns. CISA set 21 September 2026 as the remediation deadline for affected federal agencies.

CISA requires organisations to apply mitigations in accordance with vendor instructions, comply with BOD 26-04 guidance on prioritising security updates based on risk, and follow its Forensics Triage Requirements. Agencies must assess each asset’s internet exposure and follow the applicable patching guidance for cloud services, or discontinue use if mitigations are unavailable.

The requirement directly applies to federal civilian executive branch (FCEB) agencies, but all organisations should review their Linux Kernel exposure, supported-version status and available fixes.

See the NVD entry and CISA KEV catalogue for full details.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline