www.cisa.gov 18 Sept 2026, 12:00 UTC

CISA Flags Two Linux Kernel Flaws Under Active Exploitation

CyberSIXT Evidence Panel

CISA added two Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog on 18 September 2026, citing evidence of active exploitation. The entries are CVE-2025-39964, a race condition vulnerability, and CVE-2026-53266, an out-of-bounds write vulnerability. CISA said vulnerabilities of these types are frequently used by malicious cyber actors and pose significant risks to the federal enterprise.

Binding Operational Directive (BOD) 26-04 requires US Federal Civilian Executive Branch agencies to prioritise rapid remediation of KEV-listed vulnerabilities affecting publicly exposed assets that could give an attacker total control after exploitation. It also sets expectations for checking whether systems were compromised before patches were installed.

The directive applies only to those federal agencies, but CISA encouraged all organisations to use risk-based vulnerability management and prioritise remediation of KEV entries. The notice does not provide affected kernel versions, technical exploitation details or specific mitigations beyond prioritising the relevant security updates.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline