CISA orders federal agencies to patch Linux kernel flaws
Public Sector Action
Summary
Hide ▲
Show ▼
CISA ordered federal agencies to apply security updates and mitigations for three Linux kernel flaws by end of today, putting the response on an urgent federal timeline. The directive also requires forensic triage on affected assets to check whether exploitation has already occurred. CISA says the vulnerabilities have been exploited in attacks, increasing the operational urgency for agencies.
Related Happenings
Linux kernel race condition, out-of-bounds write, and TLS flaw (multiple vulnerabilities)
Vulnerability
H score36
First: 21.09.2026 23:12
Last: 21.09.2026 23:12
Sources 1
How related:
The three vulnerabilities are:
CVE-2025-39964: a race condition in the kernel’s AF_ALG cryptographic socket interface that allows concurrent writes to corrupt per-socket state and potentially crash systems or alter cryptographic results.
CVE-2026-53266: an out-of-bounds write vulnerability in the Linux kernel’s ebtables SNAT implementation that can cause an ARP address rewrite to modify shared file-backed memory without first making the affected packet range writable.
CVE-2025-39682: a Linux kernel TLS receive-path logic flaw that mishandles zero-length records queued for later processing, potentially allowing different TLS record types to be processed together when kTLS is in use.
About this happening:
Attackers are actively exploiting three Linux kernel vulnerabilities in AF_ALG, ebtables SNAT, and kTLS, and CISA has ordered urgent mitigation for federal sys...
Linux kernel race condition, out-of-bounds write, and TLS flaw (multiple vulnerabilities)
VulnerabilityHow related: The three vulnerabilities are: CVE-2025-39964: a race condition in the kernel’s AF_ALG cryptographic socket interface that allows concurrent writes to corrupt per-socket state and potentially crash systems or alter cryptographic results. CVE-2026-53266: an out-of-bounds write vulnerability in the Linux kernel’s ebtables SNAT implementation that can cause an ARP address rewrite to modify shared file-backed memory without first making the affected packet range writable. CVE-2025-39682: a Linux kernel TLS receive-path logic flaw that mishandles zero-length records queued for later processing, potentially allowing different TLS record types to be processed together when kTLS is in use.
About this happening: Attackers are actively exploiting three Linux kernel vulnerabilities in AF_ALG, ebtables SNAT, and kTLS, and CISA has ordered urgent mitigation for federal sys...
Linux kernel active exploitation wave (CVE-2025-39964, CVE-2026-53266, CVE-2025-39682)
Exploitation Wave
H score35
First: 21.09.2026 23:12
Last: 21.09.2026 23:12
Sources 1
How related:
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical.
About this happening:
CISA has warned that three Linux kernel vulnerabilities are being exploited in attacks, including one critical flaw, creating immediate risk for exposed systems. The w...
Linux kernel active exploitation wave (CVE-2025-39964, CVE-2026-53266, CVE-2025-39682)
Exploitation WaveHow related: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical.
About this happening: CISA has warned that three Linux kernel vulnerabilities are being exploited in attacks, including one critical flaw, creating immediate risk for exposed systems. The w...
CISA KEV order for FCEB agencies on LiteSpeed cPanel flaw
Public Sector Action
H score36
First: 16.06.2026 13:47
Last: 16.06.2026 13:47
Sources 1
About this happening:
CISA added the LiteSpeed cPanel user-end plugin flaw to KEV and ordered Federal Civilian Executive Branch agencies to secure systems within three days under ...
CISA KEV order for FCEB agencies on LiteSpeed cPanel flaw
Public Sector ActionAbout this happening: CISA added the LiteSpeed cPanel user-end plugin flaw to KEV and ordered Federal Civilian Executive Branch agencies to secure systems within three days under ...
CISA BOD 26-04 prioritizes vulnerability remediation for federal civilian agencies
Public Sector Action
H score27
First: 10.06.2026 15:00
Last: 10.06.2026 15:00
Sources 1
About this happening:
CISA issued Binding Operational Directive 26-04 for federal civilian agencies, directing them to prioritize vulnerability remediation using Asset Exposure, KEV S...
CISA BOD 26-04 prioritizes vulnerability remediation for federal civilian agencies
Public Sector ActionAbout this happening: CISA issued Binding Operational Directive 26-04 for federal civilian agencies, directing them to prioritize vulnerability remediation using Asset Exposure, KEV S...
CISA KEV remediation for Android and Linux vulnerabilities
Advisory/Mitigation
H score57
First: 03.06.2026 18:36
Last: 03.06.2026 18:36
Sources 1
About this happening:
CISA’s KEV update forced federal agencies to remediate CVE-2025-48595 and CVE-2022-0492 in Android and the Linux kernel before the June 5 deadline, or...
CISA KEV remediation for Android and Linux vulnerabilities
Advisory/MitigationAbout this happening: CISA’s KEV update forced federal agencies to remediate CVE-2025-48595 and CVE-2022-0492 in Android and the Linux kernel before the June 5 deadline, or...
Timeline
-
21.09.2026 23:12 2 articles · 1h ago
CISA orders federal agencies to patch three Linux kernel vulnerabilities
Legal Policy Action UpdateCISA warned that hackers are actively exploiting CVE-2025-39964, CVE-2026-53266, and CVE-2025-39682 in the Linux kernel and ordered federal agencies to apply available security updates and mitigations by the end of today. CISA also required forensic triage on affected assets to look for signs that exploitation already occurred, while saying it had not disclosed details about the incidents or the threat actors.
Show sources
- CISA alerts of active exploitation of three Linux kernel flaws — www.bleepingcomputer.com — 21.09.2026 23:12
- CISA alerts of active exploitation of three Linux kernel flaws — www.bleepingcomputer.com — 21.09.2026 23:12