CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

Summary

CISA has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog, indicating they are actively being exploited in the wild. One of these vulnerabilities, CVE-2025-39682, is a high-severity flaw in the TLS receive path.

IFF Assessment

FOE

The active exploitation of Linux kernel vulnerabilities poses a direct threat to system security and data integrity, making it bad news for defenders.

Severity

9.8 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 21, 2026. Known ransomware use: Unknown.

Defender Context

Defenders should prioritize patching these identified Linux kernel vulnerabilities to mitigate the risk of exploitation. Monitoring systems for signs of compromise related to these flaws is also crucial, especially given CISA's alert of active exploitation.

Read Full Story →