securityaffairs.com 20 Sept 2026, 16:12 UTC

CISA Flags Three Exploited Linux Kernel Flaws for Urgent Patching

CISA Flags Three Exploited Linux Kernel Flaws for Urgent Patching

THE US Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalogue: CVE-2025-39682, CVE-2025-39964 and CVE-2026-53266. CISA’s additions were reported on 18 September 2026. The flaws affect different kernel components and have CVSS scores ranging from 7.8 to 9.8.

CVE-2025-39682 is a TLS receive-path flaw that could allow authenticated local users to expose sensitive memory contents or cause a denial-of-service. CVE-2026-53266 is an out-of-bounds write in the ebtables SNAT ARP rewrite path, potentially enabling a local attacker to crash a system, cause unexpected behaviour or gain elevated privileges.

CVE-2025-39964 is a race condition affecting AF_ALG sockets; simultaneous writes could interfere with one another, potentially crashing systems or affecting the integrity of cryptographic operations. The article says there are no available details about how the vulnerabilities are being exploited, or whether they are being used together in a single attack chain.

Under Binding Operational Directive 22-01, US federal civilian executive branch agencies must address the listed vulnerabilities by CISA’s deadline of 21 September 2026. The article also recommends that private organisations review the KEV catalogue and remediate affected systems.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline