CISA alerts of active exploitation of three Linux kernel flaws

Summary
CISA warned that three Linux kernel vulnerabilities are being actively exploited, including CVE-2025-39964, which is rated critical and existed in the kernel for 14 years. Federal agencies were ordered to apply available updates and mitigations and perform forensic triage by September 21, 2026.
Key points
- CISA added CVE-2025-39964, CVE-2026-53266, and CVE-2025-39682 to its highest-priority remediation requirements for federal agencies.
- CVE-2025-39964 affects the AF_ALG cryptographic socket interface and was demonstrated by STAR Labs for privilege escalation and container escape in Google’s kernelCTF.
- CVE-2026-53266 is an ebtables SNAT out-of-bounds write flaw; a potential privilege-escalation chain has been proposed, but public exploit code has not demonstrated it.
- CVE-2025-39682 affects Linux kernel TLS receive-path processing, and public exploits are available according to the source and Red Hat.
- CISA confirmed exploitation but provided no details about the incidents or threat actors.
- CISA requires forensic triage of affected assets; none of the vulnerabilities is currently associated with ransomware groups.
Tags
Security NewsActive ExploitationLinux Kernel VulnerabilitiesVulnerability ManagementPrivilege EscalationContainer Escape