INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
CISA Adds Linux Kernel Flaws to Known Exploited Vulnerabilities List
| 2026-09-21 09:31 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
Hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers have been actively exploiting these flaws since at least September 21st, with the most recent vulnerability existing in the Linux kernel for 14 years. CISA marked all three flaws as requiring "forensic triage," meaning federal agencies need to examine affected assets for signs of exploitation. Currently, none of the three vulnerabilities is flagged as exploited by ransomware groups. The attacks work by taking advantage of a race condition, an out-of-bounds write vulnerability, and a Linux kernel TLS receive-path logic flaw, allowing hackers to potentially crash systems or alter cryptographic results. As of now, no details about the incidents or nature of the threat actors have been revealed.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-81000, CVE-2026-53266 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-81000CVE-2026-81000
CVE-2026-53266CVE-2026-53266
CVE-2026-80844CVE-2026-80844
CVE-2026-74469CVE-2026-74469
CVE-2025-39682CVE-2025-39682
CVE-2026-68121CVE-2026-68121
CVE-2025-39964CVE-2025-39964
Target & Sectors
Global Scope
governmentgovernment
Incident Timeline
2026/09/14
Threat actors exploited three separately added Linux kernel vulnerabilities with severity ratings ranging from medium to critical.
September 19, 2026
Threat actors used the three exploited Linux kernel vulnerabilities to target organizations before Red Hat updated its advisories on September 19, 2026.
Click on any entity below to view its context and source!
general_metric
2 following vulnerabilities
However, Red Hat has
updated
the
advisories
for
all the flaws
as of September 19, 2026, at 2 a.m. UTC to acknowledge active exploitation.
organisation
UTC
However, Red Hat has
updated
the
advisories
for
all the flaws
as of September 19, 2026, at 2 a.m. UTC to acknowledge active exploitation.
Sep 19, 2026
Threat actors used three exploited Linux kernel vulnerabilities to launch attacks on organizations worldwide.
September 20, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Linux Kernel vulnerabilities to its Known Exploited Vulnerabilities catalog on September 20, 2026.
Click on any entity below to view its context and source!
infrastructure
Linux
U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog
Pierluigi Paganini
September 20, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog.
tactic
T1588.006 - Vulnerabilities
U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog
Pierluigi Paganini
September 20, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog.
attribution
Known Exploited
U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog
Pierluigi Paganini
September 20, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog.
2026/09/21
CISA marked three exploited Linux kernel vulnerabilities with the highest priority for federal agencies, ordering them to apply available security updates and mitigations by September 21, 2026.
September 21, 2026
Federal Civilian Executive Branch agencies are ordered by CISA to apply necessary fixes for three exploited Linux kernel vulnerabilities by September 21, 2026.
Click on any entity below to view its context and source!
attribution
FCEB
"Address this vulnerability with high priority."
Pursuant to Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the necessary fixes by September 21, 2026.
attribution
Pursuant to Binding Operational Directive (
"Address this vulnerability with high priority."
Pursuant to Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the necessary fixes by September 21, 2026.
attribution
Federal Civilian Executive Branch
"Address this vulnerability with high priority."
Pursuant to Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the necessary fixes by September 21, 2026.
general_metric
26 Binding Operational Directive
"Address this vulnerability with high priority."
Pursuant to Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the necessary fixes by September 21, 2026.
2026/09/21
Threat actors are exploiting three Linux kernel vulnerabilities, including CVE-2025-39682 and CVE-2026-53266, which have been added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog.
Click on any entity below to view its context and source!
infrastructure
Linux
Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities.
The Cybersecurity and Infrastructure Security Agency has expanded its Known Exploited Vulnerabilities (KEV) catalog with three Linux kernel flaws, urging federal agencies to immediately patch them.
The third Linux kernel flaw newly added to
CISA’s KEV
list is
CVE-2026-53266
(CVSS score of 8.8), an out-of-bounds write issue in the bridge Netfilter ebtables Source Network Address Translation (SNAT) target.
CISA alerts of active exploitation of three Linux kernel flaws.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical.
One of them, tracked as CVE-2025-39964, existed in the Linux kernel for 14 years.
CVE-2026-53266: an out-of-bounds write vulnerability in the Linux kernel’s ebtables SNAT implementation that can cause an ARP address rewrite to modify shared file-backed memory without first making the affected packet range writable.
CVE-2025-39682: a Linux kernel TLS receive-path logic flaw
U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [
1
,
2
] the following vulnerabilities to its
Known Exploited Vulnerabilities (KEV) catalog
:
CVE-2025-39682
– Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
CVE-2025-39964
Linux Kernel Race Condition Vulnerability
CVE-2026-53266
Linux Kernel Out-of-Bounds Write Vulnerability…
The development comes as a security researcher named Asim Manizada
disclosed
four local privilege escalation flaws impacting the Linux kernel: CVE-2026-80844 (aka DirtyAH6), CVE-2026-81000 (aka TUNderflow), CVE-2026-68121 (aka PPPoEject), and CVE-2026-74469 (aka DiagSpill).
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild.
Ravie Lakshmanan
Sep 19, 2026
Vulnerability / Linux
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added
three security flaws
impacting the
Linux kernel
to its Known Exploited Vulnerabilities (
KEV
) catalog, citing evidence of active exploitation.
organisation
Known Exploited
The Cybersecurity and Infrastructure Security Agency has expanded its Known Exploited Vulnerabilities (KEV) catalog with three Linux kernel flaws, urging federal agencies to immediately patch them.
organisation
KEV
The Cybersecurity and Infrastructure Security Agency has expanded its Known Exploited Vulnerabilities (KEV) catalog with three Linux kernel flaws, urging federal agencies to immediately patch them.
organisation
CVE-2025-39964
One of them, tracked as CVE-2025-39964, existed in the Linux kernel for 14 years.
The second vulnerability,
CVE-2025-39964
(CVSS score of 7.8), is described as a race condition: issuing two writes to the same AF_ALG socket leads to data being interleaved in an unpredictable fashion.
CVE-2025-39964
(CVSS score: 7.8) – A synchronization flaw affecting AF_ALG sockets that could allow simultaneous writes to interfere with each other, potentially crashing the system or affecting the integrity of cryptographic operations.
CVE-2025-39964
(CVSS score: 7.8) -
organisation
CVE-2025-39682
CVE-2025-39682: a Linux kernel TLS receive-path logic flaw
The vulnerabilities are listed below -
CVE-2025-39682
(CVSS score: 9.8) -
organisation
CVE-2026-74469
The development comes as a security researcher named Asim Manizada
disclosed
four local privilege escalation flaws impacting the Linux kernel: CVE-2026-80844 (aka DirtyAH6), CVE-2026-81000 (aka TUNderflow), CVE-2026-68121 (aka PPPoEject), and CVE-2026-74469 (aka DiagSpill).
organisation
TUNderflow
The development comes as a security researcher named Asim Manizada
disclosed
four local privilege escalation flaws impacting the Linux kernel: CVE-2026-80844 (aka DirtyAH6), CVE-2026-81000 (aka TUNderflow), CVE-2026-68121 (aka PPPoEject), and CVE-2026-74469 (aka DiagSpill).
organisation
DiagSpill
The development comes as a security researcher named Asim Manizada
disclosed
four local privilege escalation flaws impacting the Linux kernel: CVE-2026-80844 (aka DirtyAH6), CVE-2026-81000 (aka TUNderflow), CVE-2026-68121 (aka PPPoEject), and CVE-2026-74469 (aka DiagSpill).
organisation
Microsoft Patches
Related:
Microsoft Patches 18 Vulnerabilities in AI, Cloud Products
Related:
Critical Orkes Conductor Vulnerability Exploited in Attacks
Related:
Check Point, Kaspersky, Tanium Patch Product Vulnerabilities
Related:
ISC Patches 14 Vulnerabilities in BIND 9 Security Update
organisation
Kaspersky
Related:
Microsoft Patches 18 Vulnerabilities in AI, Cloud Products
Related:
Critical Orkes Conductor Vulnerability Exploited in Attacks
Related:
Check Point, Kaspersky, Tanium Patch Product Vulnerabilities
Related:
ISC Patches 14 Vulnerabilities in BIND 9 Security Update
organisation
BIND
Related:
Microsoft Patches 18 Vulnerabilities in AI, Cloud Products
Related:
Critical Orkes Conductor Vulnerability Exploited in Attacks
Related:
Check Point, Kaspersky, Tanium Patch Product Vulnerabilities
Related:
ISC Patches 14 Vulnerabilities in BIND 9 Security Update
organisation
TLS
Tracked as
CVE-2025-39682
(CVSS score of 9.8), the first of the bugs is a critical-severity issue impacting the kernel’s handling of zero-length records on the rx_list in the TLS receive path.
A flaw in the TLS receive path that fails to properly handle unexpected conditions, potentially allowing authenticated local users to expose sensitive memory contents or cause a denial-of-service (DoS).
An improper check for unusual or exceptional conditions vulnerability in the TLS receive path that could allow local authenticated users to trigger memory disclosure or denial-of-service (DoS).
organisation
Red Hat
For CVE-2025-39682, there are public exploits available, as also confirmed by Red Hat in its
security bulletin
.
organisation
DoS
A flaw in the TLS receive path that fails to properly handle unexpected conditions, potentially allowing authenticated local users to expose sensitive memory contents or cause a denial-of-service (DoS).
An improper check for unusual or exceptional conditions vulnerability in the TLS receive path that could allow local authenticated users to trigger memory disclosure or denial-of-service (DoS).
A local attacker could exploit this improper check for unusual or exceptional conditions to cause a denial-of-service (DoS) condition or trigger memory disclosure.
organisation
STAR Labs
Offensive security company STAR Labs found CVE-2025-39964,
saying
that its researchers found the issue with no help from an AI system.
organisation
DATA
This is a corner case where the recvmsg() logic – each recvmsg() call processes either DATA or non-DATA records – breaks out of the processing loop when an initial zero-length record is pulled from rx_list.
organisation
rx_list
This is a corner case where the recvmsg() logic – each recvmsg() call processes either DATA or non-DATA records – breaks out of the processing loop when an initial zero-length record is pulled from rx_list.
organisation
Google
They demonstrated the vulnerability by achieving privilege escalation and container escape in Google’s kernelCTF.
organisation
Dirty Pipe
However,
the researcher notes
that the proposed exploitation chain is inferred by analogy with Dirty Pipe and has not been demonstrated with public exploit code.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
Source Network Address Translation
An out-of-bounds write vulnerability in the ebtables Source Network Address Translation (SNAT)
Tactical Metrics
Metrics
infrastructure
Linux
Affected Product
Click for context!
Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities.
The Cybersecurity and Infrastructure Security Agency has expanded its Known Exploited Vulnerabilities (KEV) catalog with three Linux kernel flaws, urging federal agencies to immediately patch them.
The third Linux kernel flaw newly added to
CISA’s KEV
list is
CVE-2026-53266
(CVSS score of 8.8), an out-of-bounds write issue in the bridge Netfilter ebtables Source Network Address Translation (SNAT) target.
CISA alerts of active exploitation of three Linux kernel flaws.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical.
One of them, tracked as CVE-2025-39964, existed in the Linux kernel for 14 years.
CVE-2026-53266: an out-of-bounds write vulnerability in the Linux kernel’s ebtables SNAT implementation that can cause an ARP address rewrite to modify shared file-backed memory without first making the affected packet range writable.
CVE-2025-39682: a Linux kernel TLS receive-path logic flaw
U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog.
U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog
Pierluigi Paganini
September 20, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [
1
,
2
] the following vulnerabilities to its
Known Exploited Vulnerabilities (KEV) catalog
:
CVE-2025-39682
– Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
CVE-2025-39964
Linux Kernel Race Condition Vulnerability
CVE-2026-53266
Linux Kernel Out-of-Bounds Write Vulnerability…
The development comes as a security researcher named Asim Manizada
disclosed
four local privilege escalation flaws impacting the Linux kernel: CVE-2026-80844 (aka DirtyAH6), CVE-2026-81000 (aka TUNderflow), CVE-2026-68121 (aka PPPoEject), and CVE-2026-74469 (aka DiagSpill).
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild.
Ravie Lakshmanan
Sep 19, 2026
Vulnerability / Linux
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added
three security flaws
impacting the
Linux kernel
to its Known Exploited Vulnerabilities (
KEV
) catalog, citing evidence of active exploitation.
Intelligence Sources
The Hacker News
2026-09-19
Security Affairs
2026-09-20
BleepingComputer
2026-09-21
CISA alerts of active exploitation of three Linux kernel flaws
BleepingComputer
SecurityWeek
2026-09-21
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T11:23
Comprehensive Tactical Telemetry
Highly Correlated Entities
22x
organisation
Identified Entity
Known Exploited
entity
12x
attribution
Attributing Entity
The U.S. Cybersecurity and Infrastructure Security Agency
authority
9x
timeline
Temporal Reference
2026/09/14
date
7x
vulnerability
Exploited CVE
CVE-2025-39682
cve
3x
vulnerability
CVSS Score
10
score
2x
tactic
Cyber Operation Type
Privilege Escalation
tactic
Contextual Telemetry
Context Block
12 METRICS
infrastructure
Affected Product
Linux
software
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
general metric
Kernel Vulnerabilities
3
kernel vulnerabilities
general metric
Vulnerabilities
18
vulnerabilities
general metric
Related Vulnerabilities
14
related vulnerabilities
general metric
Bind
9
bind
general metric
Cisa
1
cisa
general metric
Following Vulnerabilities
2
following vulnerabilities
general metric
Score
10
score
general metric
Cvss Score
9
cvss score
general metric
Sep
19
sep
general metric
Binding Operational Directive
26
binding operational directive
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.