CISA Adds Three Linux Kernel Flaws to Actively Exploited Vulnerabilities

CISA has recorded active exploitation of three Linux kernel flaws. U.S. federal civilian agencies have until September 21, 2026, to remediate and conduct forensic triage of affected assets.

Linux kernel vulnerabilities have been added to the Known Exploited Vulnerabilities (KEV) catalog. CISA added CVE-2025-39964, CVE-2026-53266, and CVE-2025-39682, for which it has recorded confirmed active exploitation.

Being added to the KEV catalog means that CISA has evidence of exploitation in practice, not just a theoretical vulnerability. Along with installing patches, organizations should therefore also check for possible signs of compromise on affected systems.

Linux kernel vulnerabilities affect three subsystems

The flaws affect the following Linux kernel interfaces and subsystems:

  • CVE-2025-39964 is related to the AF_ALG interface.
  • CVE-2026-53266 affects ebtables SNAT.
  • CVE-2025-39682 affects kTLS.

Fixes or mitigations are available. Administrators should update the kernel according to their distribution’s security guidance and restart the system after updating. Practical exploitability depends on the version in use and the enabled subsystems.

Deadline for federal agencies and forensic triage

The catalog entries set September 21, 2026, as the remediation deadline for U.S. federal civilian agencies. The requirement also includes forensic triage of affected assets, not just deploying the update.

For other administrators, this deadline does not represent a direct obligation, but it is a signal of urgency. Servers and devices with outdated kernels should be prioritized. Reviews should be based on the advisories of the specific distribution.

Attack details are still unavailable

CISA has not published technical details of the incidents, the scope of the attacks, or the identity of the attackers. It has not been confirmed which distributions, kernel versions, or configurations were affected in real-world attacks.

Nor has a connection between these exploits and ransomware groups been confirmed.

What to watch next

Administrators should monitor distribution security advisories for exact kernel fix versions. Any indicators of compromise, technical information, or attribution of the attackers will also be important if CISA or vendors publish them later. They should also watch for confirmation of publicly available exploits and the specific conditions under which they are used.

Sources

  • CISA KEV data mirror – CISA’s official mirror for Known Exploited Vulnerabilities catalog data.
  • BleepingComputer – Identifies the three CVEs, their Linux kernel components, the remediation deadline, and the fact that CISA did not publish attack details.

Verified and updated: 09/22/2026 06:24

Sharing