Overview
- CISA added three Linux kernel flaws — CVE-2025-39682, CVE-2025-39964 and CVE-2026-53266 — to its Known Exploited Vulnerabilities catalog after telemetry showed active exploitation.
- The three bugs range from memory disclosure and denial-of-service to race conditions and out-of-bounds writes that can lead to local privilege escalation or corrupted cryptographic results.
- Red Hat updated advisories to acknowledge active exploitation and warned that at least one of the flaws has public exploits and must be addressed with high priority.
- CISA ordered federal civilian agencies to remediate the listed vulnerabilities by September 21, 2026, triggering an accelerated patch and inventory effort under its Binding Operational Directive framework.
- Security researchers disclosed four additional local privilege‑escalation kernel bugs during the same period, increasing the patching and forensic workload for administrators responsible for internet‑facing and multi‑tenant Linux systems.