Linux kernel actively exploited flaws (multiple vulnerabilities)
Vulnerability
Summary
Hide ▲
Show ▼
Three Linux kernel vulnerabilities—CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964—were added to CISA KEV after evidence of active exploitation. The flaws expose affected systems to memory disclosure, denial-of-service, local privilege escalation, and data integrity problems. Red Hat updated advisories on September 19, 2026, and FCEB agencies were told to apply fixes by September 21, 2026.
Related Happenings
Red Hat Linux kernel advisory update for active exploitation
Advisory/Mitigation
H score53
First: 19.09.2026 09:24
Last: 19.09.2026 09:24
Sources 1
How related:
This CVE is high risk and there are known public exploits leveraging this vulnerability," Red Hat said. "Address this vulnerability with high priority.
About this happening:
Red Hat updated its Linux kernel advisories on September 19, 2026 to flag active exploitation of CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964, pu...
Red Hat Linux kernel advisory update for active exploitation
Advisory/MitigationHow related: This CVE is high risk and there are known public exploits leveraging this vulnerability," Red Hat said. "Address this vulnerability with high priority.
About this happening: Red Hat updated its Linux kernel advisories on September 19, 2026 to flag active exploitation of CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964, pu...
CISA adds Linux kernel flaws to KEV catalog under BOD 26-04
Public Sector Action
H score36
First: 19.09.2026 09:24
Last: 19.09.2026 09:24
Sources 1
How related:
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
About this happening:
CISA added three Linux kernel flaws to its KEV catalog after evidence of active exploitation, forcing federal remediation prioritization. Under BOD 26-04, FC...
CISA adds Linux kernel flaws to KEV catalog under BOD 26-04
Public Sector ActionHow related: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
About this happening: CISA added three Linux kernel flaws to its KEV catalog after evidence of active exploitation, forcing federal remediation prioritization. Under BOD 26-04, FC...
Linux kernel local root escalation flaws multiple vulnerabilities memory corruption flaw (CVE-2026-80844)
Vulnerability
H score26
First: 18.09.2026 21:02
Last: 18.09.2026 21:02
Sources 1
About this happening:
Linux kernel local-privilege-escalation flaws across DirtyAH6, TUNderflow, PPPoEject, and DiagSpill now have public exploit code, leaving older systems exp...
Linux kernel local root escalation flaws multiple vulnerabilities memory corruption flaw (CVE-2026-80844)
VulnerabilityAbout this happening: Linux kernel local-privilege-escalation flaws across DirtyAH6, TUNderflow, PPPoEject, and DiagSpill now have public exploit code, leaving older systems exp...
CISA BOD 26-04 prioritizes vulnerability remediation for federal civilian agencies
Public Sector Action
H score27
First: 10.06.2026 15:00
Last: 10.06.2026 15:00
Sources 1
About this happening:
CISA issued Binding Operational Directive 26-04 for federal civilian agencies, directing them to prioritize vulnerability remediation using Asset Exposure, KEV S...
CISA BOD 26-04 prioritizes vulnerability remediation for federal civilian agencies
Public Sector ActionAbout this happening: CISA issued Binding Operational Directive 26-04 for federal civilian agencies, directing them to prioritize vulnerability remediation using Asset Exposure, KEV S...
Linux kernel Dirty Frag local root escalation privilege-escalation flaw
Vulnerability
H score30
First: 08.05.2026 10:45
Last: 08.05.2026 10:45
Sources 1
About this happening:
Dirty Frag is a newly disclosed Linux kernel zero-day that can give local attackers root privileges on most major Linux distributions. The flaw is anchored in the...
Linux kernel Dirty Frag local root escalation privilege-escalation flaw
VulnerabilityAbout this happening: Dirty Frag is a newly disclosed Linux kernel zero-day that can give local attackers root privileges on most major Linux distributions. The flaw is anchored in the...
Timeline
-
19.09.2026 09:24 2 articles · 2h ago
CISA adds three Linux kernel vulnerabilities to KEV after active exploitation
Detection Ioc UpdateCISA added CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 to the Known Exploited Vulnerabilities catalog after evidence of active exploitation against the Linux kernel, indicating that local authenticated users or local attackers could trigger memory disclosure, denial of service, local privilege escalation, or cryptographic data corruption.
Show sources
- CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild — thehackernews.com — 19.09.2026 09:24
- CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild — thehackernews.com — 19.09.2026 09:24
-
19.09.2026 09:24 1 articles · 2h ago
Red Hat updates Linux kernel advisories and urges high-priority remediation
Mitigation Patch UpdateRed Hat updated advisories for CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 at 2 a.m. UTC on September 19, 2026, said CVE-2025-39682 has known public exploits, and tied remediation to BOD 26-04 by recommending that Federal Civilian Executive Branch agencies apply the necessary fixes by September 21, 2026.
Show sources
- CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild — thehackernews.com — 19.09.2026 09:24