· · Single source ·Updated

CISA adds three Linux kernel flaws to its exploited vulnerability catalog

The US Cybersecurity and Infrastructure Security Agency has added three specific Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog with a patch deadline of September 21, 2026.

Linux users beware — CISA flags three major security issues you need to patch right now
File photo Linux users beware — CISA flags three major security issues you need to patch right now Photo: TechRadar

Vulnerability details and severity ratings

The agency identified CVE-2025-39682 as a critical issue carrying a severity score of 9.8 out of 10. The other two flaws, CVE-2026-53266 and CVE-2025-39964, received high severity scores of 8.8 and 7.8 respectively. These bugs allow attackers to cause denial-of-service attacks or escalate user privileges within the system.

Patch availability for Linux users

Red Hat confirmed that active exploitation is occurring against these specific kernel versions. Fixes are available in stable releases for kernels 6.1, 6.6, 6.12, and 6.16. Users must update their systems before the September deadline to avoid mandatory discontinuation of use.

Reported by one outlet

Only one outlet has published this. Nothing here has been checked against a second report, so read it as that outlet's account and follow the link below for the original.

Reported by

1 independent outlet. Headline as published. Links open the original report.