Overview
- The Cybersecurity and Infrastructure Security Agency added CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266 to its Known Exploited Vulnerabilities catalog and told federal agencies to apply fixes by September 21, 2026.
- CVE-2025-39682 is a critical TLS receive-path logic error that can let a local authenticated user cause memory disclosure or crash the system when kernel TLS processing mishandles zero-length records.
- CVE-2025-39964 is a long-standing race condition in AF_ALG crypto sockets that can let concurrent writes corrupt cryptographic results or crash systems, and researchers have demonstrated privilege escalation and container escape scenarios.
- CVE-2026-53266 is an out-of-bounds write in the ebtables SNAT ARP rewrite path that can corrupt shared memory, trigger denial-of-service, or lead to local privilege escalation under certain conditions.
- Vendors such as Red Hat have published high-priority advisories and fixes, and operators are urged to patch immediately, inventory exposed or multi-tenant Linux hosts, and perform forensic hunts for signs of exploitation while triaging additional kernel LPE disclosures from researcher Asim Manizada.