Skip to main content
Emerging Threats

CISA Flags Linux Kernel Flaws Exploited in Wild

Linux server setup in a data center with muted colors and standard lighting.

"This CVE is high risk and there are known public exploits leveraging this vulnerability," Red Hat said.

CISA adds three Linux kernel CVEs to the Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three vulnerabilities affecting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. CISA’s action places the three flaws on a list the agency uses to alert organizations that exploitation is occurring in the wild and to accelerate remediation priorities.

The agency noted that there are currently no public details about exactly how the three vulnerabilities are being exploited, nor whether they are being combined into a single attack chain.

Technical summaries of the three newly cataloged CVEs

  • CVE-2025-39682 (CVSS 9.8) — Described as an "improper check for unusual or exceptional conditions" in the TLS receive path. According to the advisory language, the flaw could allow local authenticated users to trigger memory disclosure or a denial-of-service (DoS) condition.
  • CVE-2026-53266 (CVSS 8.8) — An out-of-bounds write in the ebtables Source Network Address Translation (SNAT) ARP rewrite path. The vulnerability could allow a local attacker to trigger unintended system behavior, cause DoS, or achieve local privilege escalation.
  • CVE-2025-39964 (CVSS 7.8) — A race condition that can permit concurrent writes to the same AF_ALG socket. A local attacker exploiting this condition could crash the system or corrupt cryptographic operation results, producing DoS or data integrity failures.

Red Hat advisories acknowledge active exploitation

Red Hat updated its advisories for all three flaws on September 19, 2026 at 02:00 UTC to acknowledge active exploitation. The company explicitly warned that at least one of the flaws has known public exploits, urging customers to prioritize remediation. The advisory language cited above states: "This CVE is high risk and there are known public exploits leveraging this vulnerability. Address this vulnerability with high priority."

BOD 26-04: remediation deadline for Federal Civilian Executive Branch agencies

Pursuant to Binding Operational Directive 26-04, titled "Prioritizing Security Updates Based on Risk," Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the necessary fixes by September 21, 2026. The inclusion of these CVEs on CISA’s KEV catalog, combined with the BOD guidance, establishes a near-term remediation window for U.S. federal civilian systems.

What this means for technologists, FCEB agencies, and adversaries

  • Technologists and security teams: Teams running Linux kernels will need to identify whether systems are vulnerable to CVE-2025-39682, CVE-2026-53266, or CVE-2025-39964 and prioritize patching and mitigations consistent with Red Hat’s updated advisories. The advisories’ acknowledgement of active exploitation and the presence of public exploits for at least one CVE increase urgency.
  • Federal Civilian Executive Branch agencies: FCEB agencies are operating under BOD 26-04, which recommends applying fixes by September 21, 2026. That deadline places immediate operational pressure on agency patching schedules and inventory efforts to identify affected endpoints.
  • Adversaries and threat actors: The cataloging by CISA and Red Hat’s statement that public exploits exist are signals adversaries may already be leveraging or testing these vulnerabilities. The lack of published exploitation details, however, leaves open whether attackers are chaining the three bugs or exploiting them in isolation.

The public record in this notice also records a separate disclosure by security researcher Asim Manizada, who disclosed four local privilege escalation flaws in the Linux kernel: CVE-2026-80844 (DirtyAH6), CVE-2026-81000 (TUNderflow), CVE-2026-68121 (PPPoEject), and CVE-2026-74469 (DiagSpill). The new KEV entries and these additional disclosures together paint a rapid sequence of kernel-level findings that defenders must map against their inventories.

Red Hat’s advisory, CISA’s KEV action, and the BOD 26-04 remediation timeline are fixed facts. What remains open in the record is whether the three newly cataloged CVEs are being combined in practice into a single exploit chain, and which environments have actually been compromised. Those are the specific questions organizations and oversight bodies will need to answer while they prioritize patches and follow the deadlines CISA and Red Hat have established.

https://thehackernews.com/2026/09/cisa-flags-three-linux-kernel.html