CISA Adds Two Exploited Linux Kernel Vulnerabilities to KEV Catalog
CISA has added CVE-2025-39964 and CVE-2026-53266, two actively exploited Linux kernel vulnerabilities, to its Known Exploited Vulnerabilities catalog.
CVE search metadata
CVE search record: CVE-2025-39964. Severity: high. CVSS: 7.8. EPSS: 0.32%. KEV: no. Product: Linux Kernel, Kernel. Brief: CISA Adds Two Exploited Linux Kernel Vulnerabilities to KEV Catalog. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cisa-kev-update/
CVE search record: CVE-2026-53266. Severity: high. CVSS: 8.8. EPSS: 0.12%. KEV: no. Product: Linux Kernel, Kernel. Brief: CISA Adds Two Exploited Linux Kernel Vulnerabilities to KEV Catalog. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cisa-kev-update/
What's new
- 1. new product Sep 18, 19:03 via cisa-kev
On September 18, 2026, CISA updated its Known Exploited Vulnerabilities (KEV) Catalog to include two Linux kernel vulnerabilities that are currently being leveraged in active exploitation campaigns. The vulnerabilities include CVE-2025-39964, a race condition vulnerability, and CVE-2026-53266, an out-of-bounds write vulnerability. Both flaws reside within the core Linux kernel, making them high-risk entry points or escalation vectors for attackers seeking to gain unauthorized control over affected systems. Per Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies are required to prioritize the remediation of these vulnerabilities on internet-facing assets. CISA strongly recommends that all organizations, regardless of sector, apply the latest security updates provided by their Linux distribution maintainers to mitigate these risks.
Impact
Successful exploitation of these Linux kernel vulnerabilities can grant attackers total control over the compromised asset. These flaws are high-risk because they enable low-privileged users or unauthenticated attackers to potentially elevate privileges or execute arbitrary code. The inclusion in the KEV Catalog confirms that these vulnerabilities are currently used in the wild, posing a significant risk to any organization running vulnerable Linux kernel versions.
Recommendation
Prioritize patching for all Linux assets in the environment to the latest kernel versions provided by your vendor. Ensure that your vulnerability management program includes automated monitoring for the presence of CVE-2025-39964 and CVE-2026-53266. Agencies under BOD 26-04 must prioritize remediation on internet-facing assets immediately and perform historical log analysis to determine if compromise occurred prior to patch application.
Immediate actions
Patch all Linux systems to the latest kernel version available from the distribution provider to remediate CVE-2025-39964 and CVE-2026-53266.
Mitigations
Apply kernel security updates provided by the distribution vendor.
CVE-2025-39964 and CVE-2026-53266