Cyber Insights: CISA Warns of Linux Kernel Vulnerabilities Actively Exploited in Attacks

10th September 2026

10th September 2026

CISA has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalogue, confirming that all three are being used in real-world attacks.
The affected flaws are CVE-2025-39682, CVE-2026-53266 and CVE-2025-39964, impacting different parts of the Linux kernel, including networking, firewalling and cryptographic functionality.
The most serious is CVE-2025-39682, a critical vulnerability with a CVSS score of 9.8 affecting the kernel TLS (kTLS) receive path. Where kTLS is enabled on internet-facing services, exploitation may be possible remotely.
The remaining two vulnerabilities require more specific local conditions but can still lead to memory corruption, denial of service, privilege escalation or broader host compromise.
Importantly, CISA has advised that affected systems should undergo forensic triage as well as remediation, meaning organisations should not assume patching alone is sufficient.
The three vulnerabilities affect separate Linux kernel components.
CVE-2025-39682 affects the kTLS receive path and can result in socket-buffer and memory corruption. Red Hat has indicated that the affected code path may be remotely reachable where kTLS is in use, making externally accessible systems the highest priority.
CVE-2026-53266 affects the Linux bridge/netfilter ebtables SNAT functionality. A local attacker with access to the relevant configuration could potentially trigger memory corruption, cause kernel crashes or escalate privileges.
CVE-2025-39964 is a race condition within the AF_ALG cryptographic interface. It requires local access but may allow a low-privileged user to corrupt kernel state and potentially escalate privileges.
Although the attack paths differ, all three now carry a more important distinction: confirmed exploitation in the wild.
From a SOC perspective, CVE-2025-39682 presents the most immediate concern because it may be remotely exploitable on systems using kTLS.
kTLS allows parts of TLS encryption and decryption to be handled inside the Linux kernel rather than entirely within an application. The vulnerability affects the way certain TLS records are processed, potentially leading to memory corruption when a specific sequence of records is received.
That means internet-facing services relying on kTLS may expose the vulnerable code path directly to remote traffic.
For organisations running Linux-based web services, appliances or cloud workloads, determining whether kTLS is enabled should therefore be an immediate priority.
Kernel vulnerabilities sit at a particularly sensitive layer of the operating system.
An application compromise is often restricted by user permissions and process boundaries. A kernel-level exploit can potentially bypass those controls, giving attackers broader access to the underlying host.
This is particularly important in cloud and container environments, where the Linux kernel often forms the security boundary between workloads and the host operating system.
A successful kernel exploit could therefore have implications beyond a single application or container, potentially affecting:
For organisations relying heavily on Linux, confirmed exploitation should move these vulnerabilities ahead of normal patch queues.
Patching should be accompanied by threat hunting, particularly because CISA has explicitly identified the vulnerabilities as requiring forensic investigation.
Security teams should review affected hosts for signs of unusual kernel or privilege-related activity, including:
For systems potentially exposed to CVE-2025-39682, analysts should correlate suspicious TLS or network activity with host events such as kernel instability, service failures or unexpected privilege changes.
The absence of public indicators of compromise means behavioural and host-level telemetry will be particularly important.
Organisations should first identify Linux systems running affected kernel versions or configurations and prioritise any internet-facing systems where kTLS is enabled.
Vendor or distribution-specific kernel updates should be applied without delay. After patching, systems must also be rebooted into the updated kernel and the actively running kernel version verified.
This final step is important because installing a new kernel package does not automatically mean the system is protected if it is still running the old kernel.
Where immediate patching is not possible, temporary mitigations may include disabling unused kTLS functionality, restricting CAP_NET_ADMIN access, removing unnecessary ebtables SNAT rules or preventing the AF_ALG module from loading where it is not operationally required.
The inclusion of CVE-2025-39682, CVE-2026-53266 and CVE-2025-39964 in CISA’s KEV catalogue confirms that these vulnerabilities have moved beyond theoretical risk.
CVE-2025-39682 is the most urgent of the three because of its potential remote attack surface on kTLS-enabled systems. The other vulnerabilities require local access or specific configurations, but both can still provide attackers with powerful privilege-escalation opportunities after an initial foothold has been established.
For defenders, the appropriate response is therefore twofold: patch quickly and investigate retrospectively.
Any vulnerable internet-facing Linux system should be treated as a potential compromise candidate until sufficient evidence confirms otherwise.
Kernel vulnerabilities can be difficult to detect because successful exploitation may not leave behind a conventional malware file or obvious signature.
NormCyber’s Managed Detection and Response (MDR) service provides continuous monitoring across endpoints, servers, identities and network activity, helping organisations identify the behaviours that can follow successful exploitation, including privilege escalation, unexpected root-level activity, suspicious process execution and persistence.
Our SOC analysts correlate host telemetry with network events to identify unusual behaviour around exposed Linux services, helping determine whether a vulnerable system may already have been targeted. This is particularly valuable where public indicators are limited and defenders need to rely on behavioural evidence rather than static IOCs.
With 24/7 monitoring and expert-led investigation, NormCyber MDR helps organisations move beyond simply patching vulnerabilities to understanding whether exploitation has already occurred and containing any follow-on activity before it develops into a wider compromise.
Primary: CISA – Known Exploited Vulnerabilities Catalogue
Secondary: Cyber Security News – Linux Kernel Vulnerabilities Actively Exploited in Attacks