Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Identifies Critical Linux Kernel Vulnerabilities

CISA Identifies Critical Linux Kernel Vulnerabilities

Posted on September 19, 2026 By CWS

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently included three significant vulnerabilities affecting the Linux kernel in its Known Exploited Vulnerabilities (KEV) catalog, pointing to evidence of these being actively exploited.

Details of the Vulnerabilities

The first vulnerability, identified as CVE-2025-39682, carries a CVSS score of 9.8 and involves an inadequate check for exceptional conditions in the TLS receive path. This flaw allows local authenticated users to potentially trigger memory leaks or denial-of-service (DoS) attacks. Meanwhile, CVE-2026-53266, with a CVSS score of 8.8, pertains to an out-of-bounds write issue in the ebtables SNAT ARP rewrite path. This vulnerability could enable a local attacker to cause unintended system behavior, DoS, or elevate their privileges locally. Lastly, CVE-2025-39964, rated at 7.8, is a race condition vulnerability that could permit concurrent writes to the same AF_ALG socket, leading to system crashes or corruption of cryptographic operations, thereby causing DoS or compromising data integrity.

Exploitation and Advisories

Despite these discoveries, details on how these vulnerabilities are being exploited in real-world scenarios remain scarce. There is also uncertainty about whether they are being used in a coordinated attack chain. In response, Red Hat has updated its advisories as of September 19, 2026, to reflect the active exploitation status of these vulnerabilities.

Red Hat has emphasized the severity of these vulnerabilities, stating, “This CVE is high risk and there are known public exploits leveraging this vulnerability. Address this vulnerability with high priority.”

Recommended Actions

In accordance with Binding Operational Directive (BOD) 26-04, which prioritizes security updates based on risk, Federal Civilian Executive Branch (FCEB) agencies have been advised to implement the necessary patches by September 21, 2026.

In related developments, security researcher Asim Manizada has disclosed four additional local privilege escalation vulnerabilities impacting the Linux kernel, further highlighting the need for vigilance and timely updates in the face of evolving threats.

As the cybersecurity landscape continues to evolve, it is crucial for organizations to remain proactive in addressing vulnerabilities, ensuring robust defenses against potential exploits.

The Hacker News Tags:BOD 26-04, CISA, Cybersecurity, Exploits, Kernel, Linux, Red Hat, Security, Threats, Vulnerabilities

Post navigation

Previous Post: Critical WordPress Flaw Allows Remote Code Execution
Next Post: CrowdSec’s GitHub Repositories Exposed in TanStack Attack

Related Posts

DeepLoad Malware Exploits ClickFix for Credential Theft DeepLoad Malware Exploits ClickFix for Credential Theft The Hacker News
New Phishing Kit Targeting US and EU Enterprises New Phishing Kit Targeting US and EU Enterprises The Hacker News
Microsoft Fixes 114 Windows Flaws in January 2026 Patch, One Actively Exploited Microsoft Fixes 114 Windows Flaws in January 2026 Patch, One Actively Exploited The Hacker News
Microsoft Defender Zero-Day Vulnerability Exposes System Access Microsoft Defender Zero-Day Vulnerability Exposes System Access The Hacker News
How AI Adoption Transforms Security Operations Centers How AI Adoption Transforms Security Operations Centers The Hacker News
Interlock Ransomware Exploits Cisco Flaw for Root Access Interlock Ransomware Exploits Cisco Flaw for Root Access The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Orkes Conductor Platform Vulnerability Exploited in the Wild
  • CrowdSec’s GitHub Repositories Exposed in TanStack Attack
  • CISA Identifies Critical Linux Kernel Vulnerabilities
  • Critical WordPress Flaw Allows Remote Code Execution
  • BragJack Exploit Threatens AI Agents on Major Browsers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Orkes Conductor Platform Vulnerability Exploited in the Wild
  • CrowdSec’s GitHub Repositories Exposed in TanStack Attack
  • CISA Identifies Critical Linux Kernel Vulnerabilities
  • Critical WordPress Flaw Allows Remote Code Execution
  • BragJack Exploit Threatens AI Agents on Major Browsers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark