hacker-news · Crawled Sep 19, 2026
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
3 CVEs
Read original article ↗
AI Summary
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog due to evidence of active exploitation in the wild. The vulnerabilities—CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964—allow local attackers to achieve memory disclosure, denial-of-service, or local privilege escalation. Red Hat has acknowledged active exploitation and labeled the flaws as high risk, urging immediate remediation. Federal agencies are required to patch these vulnerabilities by September 21, 2026, per Binding Operational Directive 26-04.
AI-extracted · verify before operational use