CISA Adds Three Linux Kernel Vulnerabilities to Known Exploited Vulnerabilities Catalog
CISA has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog, citing active exploitation and setting a tight federal patching deadline.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux kernel vulnerabilities to its catalog of Known Exploited Vulnerabilities (KEV), citing evidence of active exploitation in the wild. The vulnerabilities include CVE-2025-39682, a critical flaw with a CVSS score of 9.8, CVE-2026-53266, rated high with a CVSS score of 8.8, and CVE-2025-39964, also rated high with a CVSS score of 7.8 per The Hacker News.
These identified flaws are actively being exploited by malicious actors. Red Hat has confirmed this active exploitation and has marked the vulnerabilities as high risk. Public exploits for these issues are also available, increasing the immediate threat to systems as reported by TechRadar Pro.
The specific vulnerabilities include a race condition in the AF_ALG socket interface that is reportedly 14 years old (CVE-2025-39964), an out-of-bounds write in the ebtables SNAT functionality (CVE-2026-53266), and a flaw in the TLS receive path (CVE-2025-39682) according to Bleeping Computer.
CISA issued this alert on September 18, 2026, and imposed a strict three-day deadline for federal agencies to apply patches. This directive, under Binding Operational Directive (BOD) 26-04, required all affected federal civilian executive branch agencies to remediate these vulnerabilities by September 21, 2026 as detailed by The Hacker News.
This accelerated timeline reflects the urgency CISA places on addressing actively exploited threats. While the vulnerabilities require forensic triage, patches are readily available from the respective vendors, allowing for swift mitigation as noted by Bleeping Computer.
The Linux kernel is the core component of the Linux kernel operating system, managing hardware resources and providing essential services for applications. Exploitation of kernel-level vulnerabilities can grant attackers deep access to a system.
The inclusion of these three vulnerabilities in the KEV catalog underscores the ongoing threat landscape for Linux-based systems. Organizations using Linux are strongly advised to review their systems and ensure that patches addressing CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 are applied promptly, especially if they fall under CISA’s BOD 26-04 requirements as highlighted by TechRadar Pro.