Two Actively Exploited Linux Kernel Vulnerabilities (CVE‑2025‑39964, CVE‑2026‑53266) Added to CISA KEV Catalog
What It Is – CISA’s Known Exploited Vulnerabilities (KEV) catalog now includes two Linux kernel flaws: CVE‑2025‑39964, a race‑condition that can lead to privilege escalation, and CVE‑2026‑53266, an out‑of‑bounds write that can allow arbitrary code execution. Both have confirmed active exploitation in the wild.
Exploitability – Evidence of real‑world attacks; no public proof‑of‑concept needed. CVSS scores have not been published yet, but the impact is “total control of the affected asset” once exploited.
Affected Products – Linux kernel versions impacted by the two CVEs (specific version ranges disclosed in vendor advisories).
Why It Matters for Trust & Control Assurance
- Continuous vulnerability management is a core control area; rapid identification and remediation of KEV items demonstrates a defensible audit trail.
- Documented patching and verification provide evidence that an organization is meeting risk‑based remediation mandates (e.g., CISA BOD 26‑04).
- Mapping these high‑risk flaws to the Verisq Common Framework shows how a single control—Vulnerability Management & Patch Assurance—covers requirements across NIST CSF, ISO 27001, and other standards, reinforcing trust with regulators and partners.
Recommended Actions
- Inventory all Linux‑based assets and cross‑reference against CVE‑2025‑39964 and CVE‑2026‑53266.
- Prioritize patch deployment per CISA BOD 26‑04, capturing remediation tickets as evidence.
- Validate that patches are applied and verify post‑patch system integrity.
- Update your risk register and control evidence repository to reflect the remediation status.
- Monitor threat feeds for any new exploitation indicators.
Source: CISA Advisory – 2026‑09‑18