CISA KEV Alert 18 Sept 2026, 19:31 UTC

CISA Warns of Actively Exploited Critical Linux Kernel Flaw

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Status Unknown

CISA has added CVE-2025-39682 to its Known Exploited Vulnerabilities (KEV) catalogue. The vulnerability affects Linux Kernel and is described as an improper check for unusual or exceptional conditions in the TLS receive path. It can allow a zero-length record to bypass intended record-type handling.

The flaw occurs when the kernel retrieves a zero-length TLS record from the receive list. Subsequent records may then be processed using incorrect zero-copy and queuing assumptions. The available data does not specify the precise attack vector or resulting impact beyond this processing issue. NVD rates the vulnerability 9.8 (Critical) under CVSS. Patch status is unknown, and no patch or advisory URL is listed. CISA also warns that affected products may be end-of-life or end-of-service.

KEV inclusion confirms that attackers are actively exploiting the vulnerability. The data does not confirm use in ransomware campaigns. Federal Civilian Executive Branch (FCEB) agencies must remediate the issue by 21 September 2026.

CISA requires organisations to apply mitigations in accordance with vendor instructions and ensure compliance with BOD 26-04, “Prioritizing Security Updates Based on Risk”, and CISA’s “Forensics Triage Requirements”. Agencies must follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders should assess each asset’s internet exposure and follow BOD 26-04 patching guidance. Although the requirement directly affects FCEB agencies, all organisations should review their Linux Kernel exposure and supported-version status.

See the linked NVD entry and CISA KEV catalogue for full details.

View CISA KEV Entry

Article by CyberSIXT