Find notable cyber news and cases, enriched with sources, timelines, and signals.

CISA orders federal agencies to patch Linux kernel flaws

Public Sector Action
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

CISA ordered federal agencies to apply security updates and mitigations for three Linux kernel flaws by end of today, putting the response on an urgent federal timeline. The directive also requires forensic triage on affected assets to check whether exploitation has already occurred. CISA says the vulnerabilities have been exploited in attacks, increasing the operational urgency for agencies.

Related Happenings

Linux kernel race condition, out-of-bounds write, and TLS flaw (multiple vulnerabilities)

Vulnerability
H score36 First: 21.09.2026 23:12 Last: 21.09.2026 23:12 Sources 1

How related: The three vulnerabilities are: CVE-2025-39964: a race condition in the kernel’s AF_ALG cryptographic socket interface that allows concurrent writes to corrupt per-socket state and potentially crash systems or alter cryptographic results. CVE-2026-53266: an out-of-bounds write vulnerability in the Linux kernel’s ebtables SNAT implementation that can cause an ARP address rewrite to modify shared file-backed memory without first making the affected packet range writable. CVE-2025-39682: a Linux kernel TLS receive-path logic flaw that mishandles zero-length records queued for later processing, potentially allowing different TLS record types to be processed together when kTLS is in use.

About this happening: Attackers are actively exploiting three Linux kernel vulnerabilities in AF_ALG, ebtables SNAT, and kTLS, and CISA has ordered urgent mitigation for federal sys...

Linux kernel active exploitation wave (CVE-2025-39964, CVE-2026-53266, CVE-2025-39682)

Exploitation Wave
H score35 First: 21.09.2026 23:12 Last: 21.09.2026 23:12 Sources 1

How related: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical.

About this happening: CISA has warned that three Linux kernel vulnerabilities are being exploited in attacks, including one critical flaw, creating immediate risk for exposed systems. The w...

CISA KEV order for FCEB agencies on LiteSpeed cPanel flaw

Public Sector Action
H score36 First: 16.06.2026 13:47 Last: 16.06.2026 13:47 Sources 1

About this happening: CISA added the LiteSpeed cPanel user-end plugin flaw to KEV and ordered Federal Civilian Executive Branch agencies to secure systems within three days under ...

CISA BOD 26-04 prioritizes vulnerability remediation for federal civilian agencies

Public Sector Action
H score27 First: 10.06.2026 15:00 Last: 10.06.2026 15:00 Sources 1

About this happening: CISA issued Binding Operational Directive 26-04 for federal civilian agencies, directing them to prioritize vulnerability remediation using Asset Exposure, KEV S...

CISA KEV remediation for Android and Linux vulnerabilities

Advisory/Mitigation
H score57 First: 03.06.2026 18:36 Last: 03.06.2026 18:36 Sources 1

About this happening: CISA’s KEV update forced federal agencies to remediate CVE-2025-48595 and CVE-2022-0492 in Android and the Linux kernel before the June 5 deadline, or...

Timeline

  1. 21.09.2026 23:12 2 articles · 1h ago

    CISA orders federal agencies to patch three Linux kernel vulnerabilities

    Legal Policy Action Update

    CISA warned that hackers are actively exploiting CVE-2025-39964, CVE-2026-53266, and CVE-2025-39682 in the Linux kernel and ordered federal agencies to apply available security updates and mitigations by the end of today. CISA also required forensic triage on affected assets to look for signs that exploitation already occurred, while saying it had not disclosed details about the incidents or the threat actors.

    Show sources