Skip to content
CISA Flags Active Exploitation of Linux Kernel Vulnerabilities

CISA Flags Active Exploitation of Linux Kernel Vulnerabilities

First seen 19 Sep 2026, 07:55 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 20, 2026 at 07:51 UTC
  • CISA has flagged three Linux kernel vulnerabilities for active exploitation.
  • CVE-2025-39964 allows local attackers to exploit a race condition in AF_ALG sockets.
  • Federal agencies must apply patches by September 21, 2026, according to CISA.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including CVE-2025-39964, which allows local attackers to exploit a race condition in AF_ALG sockets. This vulnerability, along with CVE-2025-39682 and CVE-2026-53266, has been confirmed to be actively exploited in the wild. The vulnerabilities can lead to system crashes, denial-of-service (DoS), and privilege escalation. Red Hat has issued advisories urging immediate action to address these vulnerabilities. Federal agencies are advised to apply necessary fixes by September 21, 2026. The vulnerabilities primarily affect multi-tenant Linux servers, container hosts, and systems running untrusted local code. The risk is heightened in environments where operational technology is involved. The situation is evolving as researchers continue to monitor the exploitation methods.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2025-09-05
CVE-2025-39682 published
An improper check vulnerability in the TLS receive path was disclosed, affecting local authenticated users.
The Hacker News
2025-10-13
CVE-2025-39964 published
A race condition vulnerability in AF_ALG sockets was disclosed, allowing potential system crashes.
Redpacketsecurity
2026-06-25
CVE-2026-53266 published
An out-of-bounds write vulnerability in the ebtables SNAT ARP rewrite path was disclosed.
The Hacker News
2026-08-10
CVE-2026-68121 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-15
CVE-2026-74469 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-04
CVE-2026-80844 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-11
CVE-2026-81000 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-18
CVE vulnerabilities added to CISA KEV
CISA added CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 to its KEV catalog due to active exploitation.
The Hacker News
2026-09-19
Red Hat updates advisories
Red Hat acknowledged active exploitation of the vulnerabilities and urged high-priority fixes.
The Hacker News

More articles in this cluster (4)

Following this threat?

Track CVE-2025-39682 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed