CISA Adds Linux CVE-2026-53266 to Actively Exploited Vulnerabilities List

CISA added an ebtables SNAT vulnerability in the Linux kernel to its KEV catalog. Organizations should review affected configurations and deploy fixes from vendors.

On September 18, the U.S. agency CISA added CVE-2026-53266 in Linux to the Known Exploited Vulnerabilities (KEV) catalog. The inclusion means CISA has evidence that the flaw is being actively exploited. The vulnerability affects the Linux kernel, specifically ebtables SNAT processing when rewriting the sender hardware address in ARP packets.

CISA set the remediation deadline for September 21, 2026. It recommends that organizations follow the instructions from the vendor of the product they use. If a fix or mitigation is unavailable, the agency recommends discontinuing use of the affected product.

CVE-2026-53266 in Linux and affected configurations

The flaw is related to ebtables SNAT rules that modify the ARP sender hardware address (SHA). According to the Linux kernel CVE record, under certain circumstances, the faulty write may target a shared memory page. This could result in memory or file corruption, denial of service, and potential privilege escalation.

However, this is not a problem that automatically means remote unauthenticated takeover of every Linux system. Relevance varies depending on the distribution, the kernel version in use, and especially the network configuration. Administrators of systems using bridge netfilter or ebtables SNAT rules for ARP on bridge interfaces should pay particular attention.

The upstream fix adjusts processing so that the ARP SHA range is writable before being written through the skb_store_bits() function. The specific fixed packages and supported kernel branches will depend on security advisories from individual distributions and cloud image providers.

What administrators should do

KEV is a prioritization signal for security teams because this is not merely a theoretical known flaw. Administrators should identify machines with vulnerable kernel packages and verify whether ARP ebtables SNAT rules operate on bridge interfaces.

  • Check advisories from the distribution or cloud image vendor and deploy the available kernel fix.
  • Review the configuration of ebtables and bridge interfaces, especially rules that rewrite the ARP hardware address.
  • If an update is not yet available, consider a temporary configuration mitigation.

As a temporary measure, Red Hat lists disabling ARP hardware address rewriting in ebtables SNAT rules, or removing such rules from bridge interfaces. Before changing the configuration, it is advisable to verify what function those rules serve in the specific network.

Few details about real-world exploitation

When adding the vulnerability, CISA did not disclose attacker attribution, the campaign’s scope, or technical details of the observed exploitation. The provided information also does not publicly list indicators of compromise or proof-of-concept code.

In the near term, it will be important to monitor security advisories from distributions and cloud providers for specific versions of fixed kernel packages. Additional information from CISA or researchers about the exploitation method and affected kernel branches may also be expected.

Sources

Verified and updated: 09/19/2026 06:21

Sharing