Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

CISA Adds Three Critical Linux Kernel Flaws to Known Exploited Vulnerabilities Catalog

CISA listed three high‑severity Linux kernel CVEs (2025‑39682, 2025‑39964, 2026‑53266) in its KEV catalog, urging immediate patching. This underscores the need for continuous vulnerability management and audit‑ready evidence of remediation.

LiveThreat™ Intelligence · 📅 September 20, 2026· 📰 securityaffairs.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
2 recommended
📰
Source
securityaffairs.com

CISA Adds Three Critical Linux Kernel Flaws to Known Exploited Vulnerabilities Catalog

What Happened – The U.S. Cybersecurity and Infrastructure Security Agency (CISA) listed three high‑severity Linux kernel vulnerabilities (CVE‑2025‑39682, CVE‑2025‑39964, CVE‑2026‑53266) in its Known Exploited Vulnerabilities (KEV) catalog. The flaws involve improper condition checks, a race condition, and an out‑of‑bounds write, each with CVSS scores ranging from 7.8 to 9.8.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous vulnerability monitoring and rapid patching to satisfy the “Vulnerability Management” control objective across frameworks.
  • Provides a concrete trigger for evidence collection (e.g., patch‑status reports) that can be presented in audits or third‑party assessments.
  • Highlights the importance of a control‑mapping capability that aligns remediation actions with the Verisq Common Framework (VCF) and NIST CSF 2.0.

Who Is Affected – Cloud‑infrastructure providers, SaaS platforms, and any organization that runs Linux‑based servers or containers, spanning sectors such as technology, finance, healthcare, and government.

Recommended Actions

  • Verify whether any of the listed CVEs affect your Linux kernel version.
  • Prioritize patching or applying mitigations before the CISA deadline (Sept 21 2026).
  • Record remediation steps in a continuous control‑assurance system to generate defensible audit evidence.

Technical Notes –

  • CVE‑2025‑39682: TLS receive path mishandles unexpected conditions, allowing local users to read memory or cause DoS (CVSS 9.8).
  • CVE‑2025‑39964: Race condition in AF_ALG sockets may corrupt cryptographic operations (CVSS 7.8).
  • CVE‑2026‑53266: Out‑of‑bounds write in ebtables SNAT ARP rewrite path can lead to privilege escalation (CVSS 8.8).

Source: SecurityAffairs article

📰 Original Source
https://securityaffairs.com/199430/security/u-s-cisa-adds-linux-kernel-flaws-to-its-known-exploited-vulnerabilities-catalog-2.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →