{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3olinuxlinux_kernel6.17rc4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","cpe:2.3:o:linux:linux_kernel:6.17:rc1:*:*:*:*:*:*","cpe:2.3:o:linux:linux_kernel:6.17:rc2:*:*:*:*:*:*","cpe:2.3:o:linux:linux_kernel:6.17:rc3:*:*:*:*:*:*","cpe:2.3:o:linux:linux_kernel:6.17:rc4:*:*:*:*:*:*","cpe:2.3:o:linux:linux_kernel:6.17:rc5:*:*:*:*:*:*","cpe:2.3:o:linux:linux_kernel:6.17:rc6:*:*:*:*:*:*","cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*","cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*","cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*","cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*","cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*","cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2025-39964"},{"cvss":8.8,"id":"CVE-2026-53266"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Linux Kernel","Kernel"],"_cs_severities":["high"],"_cs_tags":["vulnerability-management","linux","kernel","cisa-kev"],"_cs_type":"threat","_cs_vendors":["Linux"],"content_html":"\u003cp\u003eOn September 18, 2026, CISA updated its Known Exploited Vulnerabilities (KEV) Catalog to include two Linux kernel vulnerabilities that are currently being leveraged in active exploitation campaigns. The vulnerabilities include CVE-2025-39964, a race condition vulnerability, and CVE-2026-53266, an out-of-bounds write vulnerability. Both flaws reside within the core Linux kernel, making them high-risk entry points or escalation vectors for attackers seeking to gain unauthorized control over affected systems. Per Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies are required to prioritize the remediation of these vulnerabilities on internet-facing assets. CISA strongly recommends that all organizations, regardless of sector, apply the latest security updates provided by their Linux distribution maintainers to mitigate these risks.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these Linux kernel vulnerabilities can grant attackers total control over the compromised asset. These flaws are high-risk because they enable low-privileged users or unauthenticated attackers to potentially elevate privileges or execute arbitrary code. The inclusion in the KEV Catalog confirms that these vulnerabilities are currently used in the wild, posing a significant risk to any organization running vulnerable Linux kernel versions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching for all Linux assets in the environment to the latest kernel versions provided by your vendor. Ensure that your vulnerability management program includes automated monitoring for the presence of CVE-2025-39964 and CVE-2026-53266. Agencies under BOD 26-04 must prioritize remediation on internet-facing assets immediately and perform historical log analysis to determine if compromise occurred prior to patch application.\u003c/p\u003e\n","date_modified":"2026-09-18T19:03:43Z","date_published":"2026-09-18T18:33:02Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cisa-kev-update/","summary":"CISA has added CVE-2025-39964 and CVE-2026-53266, two actively exploited Linux kernel vulnerabilities, to its Known Exploited Vulnerabilities catalog.","title":"CISA Adds Two Exploited Linux Kernel Vulnerabilities to KEV Catalog","url":"https://feed.craftedsignal.io/briefs/2026-09-cisa-kev-update/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:o:linux:linux_kernel:6.17:rc4:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}