Skip to content
Dark Web Intelligence on X: " CISA ADDS TWO LINUX KERNEL VULNS TO KEV ...

Dark Web Intelligence on X: " CISA ADDS TWO LINUX KERNEL VULNS TO KEV ...

X • September 18, 2026

CISA has added two Linux Kernel vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation (catalog date 2026-09-18).

• CVE-2025-39964 — race condition (AF_ALG socket concurrent writes / state inconsistency)

• CVE-2026-53266 — out-of-bounds write (ebtables SNAT target writing into nonlinear skb fragment)

Due date: 2026-09-21 · Forensic triage required: Yes · Known ransomware use: Unknown

This is an official CISA KEV addition reflecting active exploitation evidence — not an unverified underground claim. Organizations should prioritize patching per BOD 26-04 guidance and vendor/kernel updates.

#DDW #DarkWeb #CISA #KEV #Linux #CyberSecurity"

🚨 CISA ADDS TWO LINUX KERNEL VULNS TO KEV CATALOG

CISA has added two Linux Kernel vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation (catalog date 2026-09-18).

• CVE-2025-39964 — race condition (AF_ALG socket concurrent writes / state inconsistency)

• CVE-2026-53266 — out-of-bounds write (ebtables SNAT target writing into nonlinear skb fragment)

Due date: 2026-09-21 · Forensic triage required: Yes · Known ransomware use: Unknown

This is an official CISA KEV addition reflecting active exploitation evidence — not an unverified underground claim. Organizations should prioritize patching per BOD 26-04 guidance and vendor/kernel updates.

🚨 CISA ADDS TWO LINUX KERNEL VULNS TO KEV CATALOG

CISA has added two Linux Kernel vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation (catalog date 2026-09-18).

• CVE-2025-39964 — race condition (AF_ALG socket concurrent writes / state inconsistency)

• CVE-2026-53266 — out-of-bounds write (ebtables SNAT target writing into nonlinear skb fragment)

Due date: 2026-09-21 · Forensic triage required: Yes · Known ransomware use: Unknown

This is an official CISA KEV addition reflecting active exploitation evidence — not an unverified underground claim. Organizations should prioritize patching per BOD 26-04 guidance and vendor/kernel updates.

Extracted Entities