CISA adds three Linux kernel flaws to its exploited vulnerability catalog
The US Cybersecurity and Infrastructure Security Agency has added three specific Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog with a patch deadline of September 21, 2026.

Vulnerability details and severity ratings
The agency identified CVE-2025-39682 as a critical issue carrying a severity score of 9.8 out of 10. The other two flaws, CVE-2026-53266 and CVE-2025-39964, received high severity scores of 8.8 and 7.8 respectively. These bugs allow attackers to cause denial-of-service attacks or escalate user privileges within the system.
Patch availability for Linux users
Red Hat confirmed that active exploitation is occurring against these specific kernel versions. Fixes are available in stable releases for kernels 6.1, 6.6, 6.12, and 6.16. Users must update their systems before the September deadline to avoid mandatory discontinuation of use.
Reported by one outlet
Only one outlet has published this. Nothing here has been checked against a second report, so read it as that outlet's account and follow the link below for the original.
Reported by
1 independent outlet. Headline as published. Links open the original report.