Skip to main content

CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities, Federal Deadline Today (CVE-2025-39682 / CVE-2026-53266 / CVE-2025-39964)

Scope: Linux Kernel (All Distributions Running Affected Kernel Versions, Including Servers, Container Hosts, and CI/CD Runners)

Severity: Red

CISA added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog on September 18, 2026, after Red Hat confirmed active exploitation with known public exploits available for all three. CVE-2025-39682 (CVSS 9.8) is a flaw in the kernel's TLS receive path where a zero-length record can bypass normal message handling, leading to memory disclosure or denial of service. CVE-2026-53266 (CVSS 8.8) is an out-of-bounds write in the ebtables SNAT ARP rewrite path that can trigger memory corruption, denial of service, or local privilege escalation on systems using specific bridge netfilter rules. CVE-2025-39964 (CVSS 7.8) is a race condition in the kernel's AF_ALG cryptographic interface that can crash the system or corrupt cryptographic operation results. The same day these three were added to KEV, a separate researcher published working exploit code for four additional local privilege escalation flaws, meaning the Linux kernel attack surface saw significant new activity within a single 24 hour window. Organizations must apply their distribution's kernel update immediately, reboot into the patched kernel, verify the running version afterward, and treat affected systems as requiring forensic review rather than assuming a patch alone addresses prior exposure.

The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.