CISA KEV Alert 8/26/2026, 10:54:10 PM

CISA Adds CVE-2015-3246 to Known Exploited Vulnerabilities Catalogue

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

CISA has added CVE-2015-3246 to the Known Exploited Vulnerabilities catalogue. The flaw affects Red Hat’s Libuser library and is known as the Red Hat Libuser Race Condition Vulnerability. It allows authenticated local users to corrupt the /etc/passwd file, leading to denial of service or privilege escalation.

The vulnerability is a race condition in libuser that can be exploited by an authenticated local user to overwrite or corrupt critical system files, specifically /etc/passwd. Successful exploitation can cause a denial of service or enable privilege escalation. The CVSS v3.1 base score is 5.1, rated MEDIUM. A patch is available from Red Hat via the advisory at https://access.redhat.com/articles/1537873.

CISA added this entry because active exploitation in the wild has been confirmed. There is no publicly known use of this vulnerability in ransomware campaigns. Federal Civilian Executive Branch (FCEB) agencies must apply the required mitigations by the remediation due date of 9 September 2026.

CISA requires agencies to apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26‑04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements”. Follow applicable BOD 26‑04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26‑04 patching guidelines. While the directive binds FCEB agencies, all organisations should review their exposure to libuser and apply any available updates in a timely manner.

For full details, see the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2015-3246 and the CISA KEV catalogue.

View CISA KEV Entry

Article by CyberSIXT