Linux kernel active exploitation wave (CVE-2025-39964, CVE-2026-53266, CVE-2025-39682)
Exploitation Wave
Summary
Hide ▲
Show ▼
CISA has warned that three Linux kernel vulnerabilities are being exploited in attacks, including one critical flaw, creating immediate risk for exposed systems. The wave covers CVE-2025-39964, CVE-2026-53266, and CVE-2025-39682, with public exploits available for at least one issue and a known exploit for another. Federal agencies were ordered to apply available security updates and mitigations by end of today and to perform forensic triage on affected assets.
Related Happenings
Linux kernel race condition, out-of-bounds write, and TLS flaw (multiple vulnerabilities)
Vulnerability
H score36
First: 21.09.2026 23:12
Last: 21.09.2026 23:12
Sources 1
How related:
The three vulnerabilities are:
CVE-2025-39964: a race condition in the kernel’s AF_ALG cryptographic socket interface that allows concurrent writes to corrupt per-socket state and potentially crash systems or alter cryptographic results.
CVE-2026-53266: an out-of-bounds write vulnerability in the Linux kernel’s ebtables SNAT implementation that can cause an ARP address rewrite to modify shared file-backed memory without first making the affected packet range writable.
CVE-2025-39682: a Linux kernel TLS receive-path logic flaw that mishandles zero-length records queued for later processing, potentially allowing different TLS record types to be processed together when kTLS is in use.
About this happening:
Attackers are actively exploiting three Linux kernel vulnerabilities in AF_ALG, ebtables SNAT, and kTLS, and CISA has ordered urgent mitigation for federal sys...
Linux kernel race condition, out-of-bounds write, and TLS flaw (multiple vulnerabilities)
VulnerabilityHow related: The three vulnerabilities are: CVE-2025-39964: a race condition in the kernel’s AF_ALG cryptographic socket interface that allows concurrent writes to corrupt per-socket state and potentially crash systems or alter cryptographic results. CVE-2026-53266: an out-of-bounds write vulnerability in the Linux kernel’s ebtables SNAT implementation that can cause an ARP address rewrite to modify shared file-backed memory without first making the affected packet range writable. CVE-2025-39682: a Linux kernel TLS receive-path logic flaw that mishandles zero-length records queued for later processing, potentially allowing different TLS record types to be processed together when kTLS is in use.
About this happening: Attackers are actively exploiting three Linux kernel vulnerabilities in AF_ALG, ebtables SNAT, and kTLS, and CISA has ordered urgent mitigation for federal sys...
CISA orders federal agencies to patch Linux kernel flaws
Public Sector Action
H score30
First: 21.09.2026 23:12
Last: 21.09.2026 23:12
Sources 1
How related:
CISA marked all three flaws with the highest priority for federal agencies, ordering them to apply available security updates and mitigations by the end of today.
About this happening:
CISA ordered federal agencies to apply security updates and mitigations for three Linux kernel flaws by end of today, putting the response on an urgent federal...
CISA orders federal agencies to patch Linux kernel flaws
Public Sector ActionHow related: CISA marked all three flaws with the highest priority for federal agencies, ordering them to apply available security updates and mitigations by the end of today.
About this happening: CISA ordered federal agencies to apply security updates and mitigations for three Linux kernel flaws by end of today, putting the response on an urgent federal...
Linux kernel Open vSwitch datapath memory corruption memory corruption flaw (CVE-2026-64531)
Vulnerability
H score34
First: 05.08.2026 14:43
Last: 05.08.2026 14:43
Sources 1
About this happening:
CVE-2026-64531 in the Linux kernel Open vSwitch datapath lets ordinary local users escalate to root on a broad set of default-configured distributions. A public exploi...
Linux kernel Open vSwitch datapath memory corruption memory corruption flaw (CVE-2026-64531)
VulnerabilityAbout this happening: CVE-2026-64531 in the Linux kernel Open vSwitch datapath lets ordinary local users escalate to root on a broad set of default-configured distributions. A public exploi...
Linux kernel maintainers security patch release for CVE-2026-43503
Security Patch Release
H score34
First: 26.06.2026 14:51
Last: 26.06.2026 14:51
Sources 1
About this happening:
Linux kernel merged and shipped the DirtyClone security fix for CVE-2026-43503, closing a CVSS 8.8 local privilege-escalation path that could let affected systems...
Linux kernel maintainers security patch release for CVE-2026-43503
Security Patch ReleaseAbout this happening: Linux kernel merged and shipped the DirtyClone security fix for CVE-2026-43503, closing a CVSS 8.8 local privilege-escalation path that could let affected systems...
Linux kernel DirtyClone privilege escalation (CVE-2026-43503)
Vulnerability
H score29
First: 26.06.2026 14:51
Last: 26.06.2026 14:51
Sources 1
About this happening:
CVE-2026-43503 in the Linux kernel gives a local user a path to root on affected systems, including multi-tenant servers, CI runners, container hosts, and...
Linux kernel DirtyClone privilege escalation (CVE-2026-43503)
VulnerabilityAbout this happening: CVE-2026-43503 in the Linux kernel gives a local user a path to root on affected systems, including multi-tenant servers, CI runners, container hosts, and...
Timeline
-
21.09.2026 23:12 2 articles · 1h ago
CISA warns of active exploitation of three Linux kernel vulnerabilities
Initial DisclosureCISA warned that attackers are actively exploiting three Linux kernel vulnerabilities—CVE-2025-39964, CVE-2026-53266, and CVE-2025-39682—and ordered federal agencies to apply available security updates and mitigations by the end of today. CISA also required forensic triage for affected assets to look for signs that exploitation already occurred.
Show sources
- CISA alerts of active exploitation of three Linux kernel flaws — www.bleepingcomputer.com — 21.09.2026 23:12
- CISA alerts of active exploitation of three Linux kernel flaws — www.bleepingcomputer.com — 21.09.2026 23:12