CISA Adds Two Known Exploited Vulnerabilities to Catalog
Summary
CISA has added two new vulnerabilities, CVE-2025-39964 and CVE-2026-53266, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. These vulnerabilities, affecting the Linux Kernel, are identified as frequent attack vectors posing significant risks to federal agencies. The article also references Binding Operational Directive (BOD) 26-04, which mandates federal agencies to prioritize remediation of high-risk vulnerabilities listed in the KEV Catalog.
IFF Assessment
The article highlights newly identified exploited vulnerabilities, indicating potential new attack vectors that defenders must address.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 21, 2026. Known ransomware use: Unknown.
Defender Context
Defenders should prioritize patching the newly listed vulnerabilities in the KEV Catalog, as they are known to be actively exploited. Organizations should review CISA's Binding Operational Directive (BOD) 26-04 for guidance on risk-based vulnerability management and timely remediation, especially for publicly exposed assets.