CISA confirms active exploitation of three Linux kernel flaws

The U.S. Cybersecurity and Infrastructure Security Agency added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog after finding evidence of active exploitation.

The three flaws are CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964. CISA published the additions on September 18, 2026, through two separate alerts: one covering CVE-2025-39682 and another covering CVE-2025-39964 and CVE-2026-53266.

What CISA added to the KEV catalog

All three vulnerabilities affect the Linux kernel, but they involve different kernel components and different exposure conditions.

CVEAffected areaReported impactKey exposure detail
CVE-2025-39682Kernel TLS receive pathImproper handling of zero-length records can affect TLS record processing and is associated with memory disclosure or denial-of-service risk in public vulnerability summaries.Red Hat states the issue can only be triggered when kernel TLS ULP is in use.
CVE-2026-53266Netfilter bridge ebtables SNATAn ARP hardware address rewrite can improperly modify memory pages, which Red Hat says may lead to unintended system behavior, denial of service, or local privilege escalation.Red Hat says exploitation requires specific bridge netfilter rules.
CVE-2025-39964AF_ALG cryptographic user APIA race condition involving concurrent writes to the same AF_ALG socket may crash the system or corrupt cryptographic operation results.Red Hat describes this as requiring local access.

Severity scoring differs by source. CVE-2025-39682 is rated 9.8 in the CVE.org record cited by security reporting, while Red Hat scores it lower for its products. CVE-2025-39964 is another example: Red Hat and NVD list it at 5.5, while CVE.org lists it at 7.8. The practical takeaway for administrators is that confirmed exploitation, affected configuration, and asset exposure matter more than a single headline score.

Federal agencies faced a short remediation window

CISA’s September 18 alerts point to Binding Operational Directive 26-04, which sets vulnerability management requirements for U.S. Federal Civilian Executive Branch agencies. CISA says the directive reinforces use of the KEV catalog and requires agencies to prioritize rapid remediation for high-risk vulnerabilities.

BleepingComputer reported that CISA marked the three Linux flaws with a September 21, 2026 remediation deadline for federal agencies and also reported that the entries required forensic triage. For organizations outside the U.S. federal government, the deadline itself may not apply, but the signal still matters: these are no longer theoretical Linux bugs sitting in a scanner report.

Why this matters for Linux administrators

Linux kernel vulnerabilities can be awkward to prioritize because exploitability often depends on configuration, workload, module availability, local access, and whether a distribution has backported a fix into an older package version.

That makes simple version checks risky. Red Hat’s own CVE pages warn that product-specific impact and scoring can differ from NVD and other sources. In enterprise Linux environments, a package may carry an older upstream version number while still including a backported security fix from the vendor.

Administrators should confirm status through the distribution’s security advisory, not only through generic kernel version matching.

Linux teams should treat the three KEV additions as patch-priority events, especially for internet-facing servers, multi-user systems, container hosts, virtualization infrastructure, and appliances where kernel updates depend on a vendor image.

  • Identify affected systems. Review Linux servers, virtual machine images, container hosts, network appliances, and managed service environments that depend on Linux kernels.
  • Check vendor advisories. Confirm whether the relevant distribution, cloud image, or appliance vendor has issued fixed kernel packages or mitigation guidance.
  • Prioritize exposed and multi-tenant assets. Systems with untrusted local users, container workloads, bridge networking, kernel TLS, or ebtables SNAT rules deserve early attention.
  • Apply kernel updates and complete required restarts. Kernel fixes normally require a reboot or controlled node rotation before the patched kernel is actually running.
  • Use mitigations only with validation. Red Hat lists mitigations such as preventing the tls or af_alg modules from loading and adjusting ebtables SNAT rules for ARP traffic. Those changes can affect workloads and should be tested before broad deployment.
  • Look for signs of compromise. Because exploitation is confirmed, response should include more than patching. Kernel crashes, suspicious local privilege escalation activity, unexpected module behavior, and unusual changes around affected systems should be reviewed.

Small businesses should check with providers

Many small businesses do not patch Linux kernels directly. Managed hosting providers, cloud platforms, appliance vendors, MSPs, and IT support teams may control the affected systems.

For hosted or managed environments, the useful question is not simply whether “systems are patched.” The better request is confirmation that the provider has reviewed CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 against the environment, applied available vendor fixes or mitigations where needed, and checked affected assets for signs of exploitation.

There is no public evidence from CISA’s alerts showing which organizations have been targeted or whether ransomware groups are involved. Until more details are available, the safest reading is straightforward: affected Linux systems should be inventoried, patched or mitigated, restarted where required, and reviewed for suspicious activity.

Get new small business insights by email

Practical ideas and useful articles to help you make better business decisions.

HelperX Bot

Not sure what to read next?

I can suggest related Tech Help Canada articles based on the topic you’re reading now.

Tech Help Canada Staff researches, writes, and reviews practical content for business owners and professionals. Our coverage spans business, marketing, SEO, technology, and the tools and systems people use to grow and operate online. We focus on clear, useful information backed by research, hands-on experience, and editorial review. Learn more about our team and editorial standards. Need help with something? Contact Us

Leave a Comment

Tweet
Share
Share
Pin
WhatsApp
Reddit
Email