Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation
Article Content
- •CVE-2025-39682 in the Linux kernel allows remote code execution via zero-length TLS records.
- •CISA added the vulnerability to its KEV list on September 18, 2026, with a patch deadline of September 21.
- •Gravity Forms has a separate critical vulnerability (CVE-2026-84434) allowing unauthenticated file uploads.
A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited Vulnerabilities (KEV) list on September 18, 2026, with a remediation deadline of September 21, 2026. The vulnerability can fully compromise the confidentiality, integrity, and availability of affected systems. Public exploits are available, and administrators are urged to patch immediately. The flaw impacts Linux kernel versions from commit 84c61fe1a75b to the stable fix commits. Gravity Forms also has a separate critical vulnerability (CVE-2026-84434) that allows unauthenticated file uploads leading to remote code execution. Organizations using affected software must prioritize updates to mitigate these risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Debian and CVE-2025-39682 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CISA Flags Active Exploitation of Linux Kernel Vulnerabilities The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including CVE-2025-39964, which allows local attackers to exploit a race condition in AF_ALG sockets. This vulnerability, along with CVE-2025-39682 and…
CISA Urges Urgent Patching for Actively Exploited Linux Kernel Vulnerabilities The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged three Linux kernel vulnerabilities as actively exploited, requiring federal agencies to patch them by September 21, 2026. The vulnerabilities, CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964, were added to CISA's Known Exploited…