Cookie Consent by Free Privacy Policy Generator

CISA Adds Three Actively Exploited Linux Kernel Vulnerabilities to Known Exploited List

CISA has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. The vulnerabilities are CVE-2025-39964, a race condition flaw; CVE-2026-53266, an out-of-bounds write vulnerability; and CVE-2025-39682, an improper check for unusual or exceptional conditions vulnerability. CISA's inclusion of these flaws signals that they are being actively exploited in the wild and pose significant risk to organisations running affected Linux systems. Federal agencies in the US are required to patch these vulnerabilities by specified deadlines under Binding Operational Directive 26-04. While this directive applies to US federal agencies, the inclusion of vulnerabilities in CISA's Known Exploited Vulnerabilities Catalog is widely recognised as a signal that these flaws are being actively targeted by attackers and should be prioritised by organisations globally.

Why this matters for UK organisations

For UK businesses, the operational relevance is that Linux underpins a significant proportion of enterprise infrastructure, including servers, cloud workloads, containers, networking equipment, embedded systems and IoT devices. Actively exploited kernel vulnerabilities can provide attackers with privileged access, persistence and the ability to move laterally across environments. The fact that CISA has flagged these vulnerabilities as actively exploited means that threat actors are already using them in attacks, and that exploitation techniques may be publicly available or widely shared among attacker communities. For organisations running Linux in production, this is a clear signal to prioritise patching, review vulnerability management processes and ensure that Linux systems are included in regular patch cycles alongside Windows and application updates. Many organisations have strong patch management processes for Windows endpoints and servers, but Linux systems, particularly those running in cloud environments, containers or as part of infrastructure services, are sometimes overlooked or managed separately. This can create gaps in vulnerability coverage that attackers can exploit.

What to review

For UK businesses, this is a prompt to review whether Linux systems across your estate are being patched in a timely manner, whether vulnerability scanning covers Linux workloads and whether your patch management process includes kernel updates. Consider whether you have visibility of all Linux instances, including cloud, containerised and embedded systems, and whether patching responsibilities are clearly assigned. Review whether your vulnerability management process prioritises actively exploited vulnerabilities, whether you have a process for emergency patching when critical flaws are disclosed, and whether your organisation can identify and patch Linux systems quickly when CISA or other authoritative sources flag active exploitation. Consider whether your security monitoring can detect exploitation attempts targeting kernel vulnerabilities, and whether your incident response plans account for the possibility of privileged access or lateral movement following kernel compromise.

Source: CISA

News and blog posts
Today's brief highlights the growing operational reality of AI-assisted...
The BBC reports that Google's Gemini AI model successfully accessed the...
The Guardian reports that an official UK security assessment found that vast...
CISA has added three Linux kernel vulnerabilities to its Known Exploited...