CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
- ID
- 26266
- Status
- summarized
- Published
- 19 Sep 2026, 2:24 PM
- Fetched
- 19 Sep 2026, 3:23 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/cisa-flags-three-linux-kernel.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 5.5
- Created
- 19 Sep 2026, 3:23 PM
- Tags
- Audience
- developersdatabase_learners
What happened
CISA added three actively exploited Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog on September 19, 2026: CVE-2025-39682 (CVSS 9.8, TLS receive path memory disclosure/DoS), CVE-2026-53266 (CVSS 8.8, ebtables SNAT ARP out-of-bounds write enabling local privilege escalation), and CVE-2025-39964 (CVSS 7.8, AF_ALG socket race condition corrupting crypto operations). Red Hat confirmed public exploits exist and flagged them as high priority; FCEB agencies face a September 21, 2026 patching deadline. All three require local authenticated access.
Why it matters
If you operate Linux servers or containers with multi-tenant or untrusted local users, patch these now—Red Hat says public exploits exist and CVE-2025-39682's 9.8 CVSS reflects trivial memory disclosure via the TLS receive path. For single-tenant dev boxes or sealed containers with no local untrusted access, the practical risk is lower since all three require local authentication. Check whether your distro has backported fixes yet rather than waiting for the next routine update cycle.
Discussion angle
How many of us actually know which kernel version our production servers and CI runners are on right now, and whether our distro has shipped patched kernels—versus just assuming cloud providers handle it?