Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Two Actively Exploited Linux Kernel Vulnerabilities (CVE‑2025‑39964, CVE‑2026‑53266) Added to CISA KEV Catalog

CISA announced that two Linux kernel flaws—CVE‑2025‑39964 (race condition) and CVE‑2026‑53266 (out‑of‑bounds write)—are now in its Known Exploited Vulnerabilities catalog, indicating active exploitation. Organizations must prioritize patching to maintain audit‑ready vulnerability management.

LiveThreat™ Intelligence · 📅 September 18, 2026· 📰 cisa.gov
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
cisa.gov

Two Actively Exploited Linux Kernel Vulnerabilities (CVE‑2025‑39964, CVE‑2026‑53266) Added to CISA KEV Catalog

What It Is – CISA’s Known Exploited Vulnerabilities (KEV) catalog now includes two Linux kernel flaws: CVE‑2025‑39964, a race‑condition that can lead to privilege escalation, and CVE‑2026‑53266, an out‑of‑bounds write that can allow arbitrary code execution. Both have confirmed active exploitation in the wild.

Exploitability – Evidence of real‑world attacks; no public proof‑of‑concept needed. CVSS scores have not been published yet, but the impact is “total control of the affected asset” once exploited.

Affected Products – Linux kernel versions impacted by the two CVEs (specific version ranges disclosed in vendor advisories).

Why It Matters for Trust & Control Assurance

  • Continuous vulnerability management is a core control area; rapid identification and remediation of KEV items demonstrates a defensible audit trail.
  • Documented patching and verification provide evidence that an organization is meeting risk‑based remediation mandates (e.g., CISA BOD 26‑04).
  • Mapping these high‑risk flaws to the Verisq Common Framework shows how a single control—Vulnerability Management & Patch Assurance—covers requirements across NIST CSF, ISO 27001, and other standards, reinforcing trust with regulators and partners.

Recommended Actions

  • Inventory all Linux‑based assets and cross‑reference against CVE‑2025‑39964 and CVE‑2026‑53266.
  • Prioritize patch deployment per CISA BOD 26‑04, capturing remediation tickets as evidence.
  • Validate that patches are applied and verify post‑patch system integrity.
  • Update your risk register and control evidence repository to reflect the remediation status.
  • Monitor threat feeds for any new exploitation indicators.

Source: CISA Advisory – 2026‑09‑18

📰 Original Source
https://www.cisa.gov/news-events/alerts/2026/09/18/cisa-adds-two-known-exploited-vulnerabilities-catalog ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →