CISA Adds Three Actively Exploited Linux Kernel Flaws to KEV Catalog
At a glance
- CISA listed three Linux kernel vulnerabilities on September 18, 2026.
- Federal agencies were told to patch or mitigate by September 21, 2026.
- Red Hat classified the flaws as high-risk with public exploits available.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on September 18, 2026, following evidence of active exploitation.
The vulnerabilities, identified as CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266, were flagged by CISA after reports indicated they had been exploited in the wild. The agency instructed Federal Civilian Executive Branch agencies to apply available patches or mitigations by September 21, 2026.
CVE-2025-39682 affects the Linux kernel’s TLS receive-path logic, where improper handling of zero-length records can result in memory disclosure or denial-of-service. CVE-2025-39964 is a race condition in the AF_ALG cryptographic socket interface that allows concurrent writes, which may cause system crashes or corrupt cryptographic results.
CVE-2026-53266 involves an out-of-bounds write in the ebtables SNAT ARP rewrite path, which can lead to memory corruption, denial-of-service, or local privilege escalation. CISA marked all three vulnerabilities as requiring forensic triage, directing agencies to examine affected assets for any indications of prior exploitation.
What the numbers show
- Three Linux kernel vulnerabilities were added to the KEV catalog on September 18, 2026.
- Federal agencies were given a three-day deadline to apply patches or mitigations, ending September 21, 2026.
- Red Hat updated advisories for all three vulnerabilities on September 19, 2026.
CISA’s advisory stated that active exploitation had been observed for each of the three vulnerabilities. The agency’s instructions included both patching and conducting forensic analysis to identify any signs of compromise on government systems.
Red Hat responded by updating its advisories on September 19, 2026, and classified all three vulnerabilities as high-risk. The company also noted that public exploits for these flaws were already available, increasing the urgency for remediation.
Each vulnerability targets different components of the Linux kernel, but all have the potential to disrupt system operations or compromise sensitive information if left unaddressed. The instructions from CISA required agencies to act quickly to reduce exposure and check for evidence of exploitation.
Industry reaction
Red Hat stated in its updated advisories that the three vulnerabilities were high-risk and confirmed the existence of public exploits targeting them. The company’s advisories were revised the day after CISA’s announcement to reflect the heightened threat level.
CISA’s actions included not only the addition of the vulnerabilities to the KEV catalog but also a directive for agencies to perform forensic triage, emphasizing the need for immediate investigation into possible prior system compromise.
* This article is based on publicly available information at the time of writing.