Skip to content
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation

Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation

First seen 20 Sep 2026, 02:22 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 21, 2026 at 01:32 UTC

A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited Vulnerabilities (KEV) list on September 18, 2026, with a remediation deadline of September 21, 2026. The vulnerability can fully compromise the confidentiality, integrity, and availability of affected systems. Public exploits are available, and administrators are urged to patch immediately. The flaw impacts Linux kernel versions from commit 84c61fe1a75b to the stable fix commits. Gravity Forms also has a separate critical vulnerability (CVE-2026-84434) that allows unauthenticated file uploads leading to remote code execution. Organizations using affected software must prioritize updates to mitigate these risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2025-09-05
CVE-2025-39682 published
A critical vulnerability in the Linux kernel related to TLS record handling was disclosed.
Redpacketsecurity
2026-05-22
First public PoC for CVE-2025-39682
Proof-of-concept code for the Linux kernel vulnerability was made publicly available.
Redpacketsecurity
2026-06-30
CVE-2026-58138 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-18
CISA adds CVE-2025-39682 to KEV
CISA confirmed active exploitation of the Linux kernel vulnerability and added it to the KEV list.
Buttondown
2026-09-19
Gravity Forms vulnerability CVE-2026-84434 published
A critical flaw in Gravity Forms allows unauthenticated file uploads leading to remote code execution.
Buttondown
2026-09-20
Current status of CVE-2025-39682
The Linux kernel vulnerability remains actively exploited, and patches are urgently needed.
exploitbulletin.com

More articles in this cluster (3)

Following this threat?

Track Debian and CVE-2025-39682 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed