HomeSecurityLinux Kernel: CISA warns of 3 exploitable vulnerabilities

Linux Kernel: CISA warns of 3 exploitable vulnerabilities

Three serious Linux kernel vulnerabilities have been added to CISA ’s Known Exploited Vulnerabilities (KEV) list , with the US cybersecurity agency confirming that they are actively being exploited online. The announcement is a serious warning to system administrators worldwide, as these vulnerabilities could lead to privilege escalation , denial-of-service and disclosure of sensitive data . CISA is urging public sector organizations to implement the necessary fixes as soon as possible.

Linux Kernel vulnerabilities CISA KEV catalog exploit

The Linux kernel is the core of millions of systems worldwide — from enterprise servers and government infrastructure to IoT devices and Android phones . The discovery of actively exploited vulnerabilities in this kernel is critical, as the attack surface is vast. Of particular concern is the fact that two of the three vulnerabilities allow local privilege escalation , meaning an attacker who has already gained access to the system can escalate their privileges to root level .

According to The Hacker News, CISA announced the addition of the three vulnerabilities to the KEV list on Friday, without revealing details about how they were exploited or whether they were used as part of a single attack chain. Red Hat updated the related announcements on September 19, 2026, confirming active exploitation and marking the vulnerabilities as high priority.

See also: CVE-2026-53266: Critical vulnerability in Linux Kernel's ebtables SNAT

Analysis of the three Linux Kernel vulnerabilities

The first vulnerability, CVE-2025-39682, has a CVSS score of 9.8 — the highest of the three — and concerns improper checking for unusual or exceptional conditions in the TLS receive path. This means that a locally authenticated user could cause a memory disclosure or denial-of-service (DoS). The severity of this vulnerability is extremely high, as TLS is widely used to encrypt communications, and memory disclosure could expose encryption keys or other sensitive data.

The second vulnerability, CVE-2026-53266 , with a CVSS score of 8.8 , is located in the ebtables Source Network Address Translation (SNAT) Address Resolution Protocol (ARP) rewrite path . This is an out-of-bounds write vulnerability that could allow a local attacker to cause unexpected system behavior, DoS , or local privilege escalation . ebtables is a packet filtering tool for Ethernet bridges in the Linux kernel , and exploitation of this vulnerability could severely impact virtualization environments and network infrastructures.

The third vulnerability, CVE-2025-39964, with a CVSS score of 7.8, concerns a race condition that allows concurrent writes to the same AF_ALG socket. A local attacker could exploit this condition to crash the system or corrupt the results of cryptographic operations, causing DoS or data integrity issues.

Linux Kernel - SecNews.gr

Linux Kernel Deadline and Obligations — What CISA Says

Under Binding Operational Directive (BOD) 26-04 , “Prioritizing Security Updates Based on Risk,” Federal Civilian Executive Branch (FCEB) were required to implement the necessary fixes by September 21, 2026.This extremely short deadline — just two days from the announcement — indicates the urgent nature of the threat and CISA’s concern about the active exploitation of the vulnerabilities.

It is worth noting that, although the CISA guidelines are officially addressed to US, in practice they are an important guide for organizations worldwide. Businesses, government agencies and private Linux across Europe, including Greece, should address these vulnerabilities with the same urgency. Active exploitation on a global scale means that no system running vulnerable versions of the Linux kernel is safe.

See also: CISA: Linux Kernel vulnerability used for ransomware attacks

Additionally, the discovery of these vulnerabilities comes at a time of increased threat actor activity targeting Linux infrastructure. Ransomware groups and government agencies have increasingly turned their attention to Linux systems , recognizing that they form the backbone of critical infrastructure — from data centers and cloud services to industrial control systems.

Practical security tips for Linux Kernel systems

For system administrators running Linux, immediate action is imperative. First, check the version of the Linux kernel running on your systems and apply any available security updates from your distribution vendor — Red Hat, Ubuntu, Debian, SUSE , or other. Second, implement principles least privilege to limit the impact of a potential exploit: an attacker who cannot gain local access cannot exploit local privilege escalation vulnerabilities. Third, monitor system logs for suspicious activity, particularly attempts to elevate privileges or unusual use of cryptographic interfaces.

See also: ZcopyReaper: Critical vulnerability in Linux Kernel leads to root access

Additionally, it is worth considering implementing kernel hardening measures, such as enabling SELinux or AppArmor , using seccomp to limit system calls, and implementing kernel address space layout randomization (KASLR ) . These measures are not a substitute for applying patches, but they can significantly reduce the likelihood of successful exploitation. Finally, consider adopting vulnerability management tools that automatically monitor the CISA KEV list and alert you to vulnerabilities affecting your systems.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Linux Kernel: CISA warns of 3 exploitable vulnerabilities

In summary, the addition of three Linux kernel vulnerabilities to CISA ’s KEV list is a clear wake-up call for the cybersecurity community. The active exploitation of CVE-2025-39682 , CVE-2026-53266 , and CVE-2025-39964 means that attackers are already using these vulnerabilities in real-world attacks. Prompt application of available patches and adoption of a comprehensive Linux security strategy is the only effective response to this threat.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS