CISA KEV Alert 8/27/2026, 8:52:18 PM

CISA adds Linux kernel CVE‑2026-53362 to KEV as exploited

Developing story vulnerability 4 articles tracked
Linux kernel Bad Epoll flaw (CVE-2026-46242) allows local root escalation
CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

CISA has added CVE‑2026-53362 to its Known Exploited Vulnerabilities (KEV) catalogue. The entry concerns the Linux Kernel, affecting the open‑source component used by distributions such as SUSE, Red Hat and others. The flaw, labelled Linux Kernel Unspecified Vulnerability, permits privilege escalation through the IPv6 networking subsystem.

The vulnerability is a local privilege‑escalation bug in the IPv6 stack that can be exploited by an attacker with existing low‑privilege access to a system. Successful exploitation allows the attacker to gain root or equivalent privileges, compromising the confidentiality, integrity and availability of the affected host. The Common Vulnerability Scoring System assigns it a score of 7.8 (High). A patch is available; the fix has been backported to the stable kernel trees and is referenced by the commit 14200d435af9a9eeb444f529fc2f689a236b7962.

Because the flaw appears in the KEV catalogue, CISA has confirmed that it is being actively exploited in the wild. No public reports link this CVE to ransomware campaigns at this time. Federal Civilian Executive Branch (FCEB) agencies must apply the required mitigations by the remediation due date of 30 August 2026. Continuing to run unpatched kernels after that date violates CISA’s Binding Operational Directive (BOD) 26‑04.

CISA directs FCEB agencies to apply mitigations in accordance with vendor instructions, ensuring compliance with BOD 26‑04 – Prioritising Security Updates Based on Risk – and with the Forensics Triage Requirements that accompany the directive. Agencies must also follow the applicable BOD 26‑04 guidance for cloud services or discontinue use of the product if mitigations cannot be applied.

Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to the BOD 26‑04 patching guidelines. While the directive binds FCEB organisations, all other organisations are advised to review their Linux‑based systems for exposure and to apply the vendor‑supplied patches as soon as practicable.

Full details are available in the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2026-53362 and in the CISA KEV catalogue.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline