Find notable cyber news and cases, enriched with sources, timelines, and signals.

Linux kernel active exploitation wave (CVE-2025-39964, CVE-2026-53266, CVE-2025-39682)

Exploitation Wave
First reported
Last updated
Happening score
H score 35
1 unique sources, 1 articles

Summary

Hide ▲

CISA has warned that three Linux kernel vulnerabilities are being exploited in attacks, including one critical flaw, creating immediate risk for exposed systems. The wave covers CVE-2025-39964, CVE-2026-53266, and CVE-2025-39682, with public exploits available for at least one issue and a known exploit for another. Federal agencies were ordered to apply available security updates and mitigations by end of today and to perform forensic triage on affected assets.

Related Happenings

Linux kernel race condition, out-of-bounds write, and TLS flaw (multiple vulnerabilities)

Vulnerability
H score36 First: 21.09.2026 23:12 Last: 21.09.2026 23:12 Sources 1

How related: The three vulnerabilities are: CVE-2025-39964: a race condition in the kernel’s AF_ALG cryptographic socket interface that allows concurrent writes to corrupt per-socket state and potentially crash systems or alter cryptographic results. CVE-2026-53266: an out-of-bounds write vulnerability in the Linux kernel’s ebtables SNAT implementation that can cause an ARP address rewrite to modify shared file-backed memory without first making the affected packet range writable. CVE-2025-39682: a Linux kernel TLS receive-path logic flaw that mishandles zero-length records queued for later processing, potentially allowing different TLS record types to be processed together when kTLS is in use.

About this happening: Attackers are actively exploiting three Linux kernel vulnerabilities in AF_ALG, ebtables SNAT, and kTLS, and CISA has ordered urgent mitigation for federal sys...

CISA orders federal agencies to patch Linux kernel flaws

Public Sector Action
H score30 First: 21.09.2026 23:12 Last: 21.09.2026 23:12 Sources 1

How related: CISA marked all three flaws with the highest priority for federal agencies, ordering them to apply available security updates and mitigations by the end of today.

About this happening: CISA ordered federal agencies to apply security updates and mitigations for three Linux kernel flaws by end of today, putting the response on an urgent federal...

Linux kernel Open vSwitch datapath memory corruption memory corruption flaw (CVE-2026-64531)

Vulnerability
H score34 First: 05.08.2026 14:43 Last: 05.08.2026 14:43 Sources 1

About this happening: CVE-2026-64531 in the Linux kernel Open vSwitch datapath lets ordinary local users escalate to root on a broad set of default-configured distributions. A public exploi...

Linux kernel maintainers security patch release for CVE-2026-43503

Security Patch Release
H score34 First: 26.06.2026 14:51 Last: 26.06.2026 14:51 Sources 1

About this happening: Linux kernel merged and shipped the DirtyClone security fix for CVE-2026-43503, closing a CVSS 8.8 local privilege-escalation path that could let affected systems...

Linux kernel DirtyClone privilege escalation (CVE-2026-43503)

Vulnerability
H score29 First: 26.06.2026 14:51 Last: 26.06.2026 14:51 Sources 1

About this happening: CVE-2026-43503 in the Linux kernel gives a local user a path to root on affected systems, including multi-tenant servers, CI runners, container hosts, and...

Timeline

  1. 21.09.2026 23:12 2 articles · 1h ago

    CISA warns of active exploitation of three Linux kernel vulnerabilities

    Initial Disclosure

    CISA warned that attackers are actively exploiting three Linux kernel vulnerabilities—CVE-2025-39964, CVE-2026-53266, and CVE-2025-39682—and ordered federal agencies to apply available security updates and mitigations by the end of today. CISA also required forensic triage for affected assets to look for signs that exploitation already occurred.

    Show sources