Lily
Anne

CISA KEV Update: Three Linux Kernel Vulnerabilities Exploited in the Wild

Lily Anne

Sep 21, 2026

5 min read

CISA KEV Update Three Linux Kernel Vulnerabilities Exploited in the Wild

TL; DR

The latest CISA KEV Linux kernel update adds three actively exploited vulnerabilities affecting kernel TLS, ebtables, and AF_ALG cryptographic sockets, requiring rapid exposure assessment and verified remediation.

  • Impact ranges from memory disclosure and denial of service to privilege escalation and cryptographic data-integrity issues, with exposure depending on kernel configuration and distribution-specific patches.
  • Enterprises should map each CVE to vendor advisories, patch and reboot where required, verify the active kernel, and investigate suspicious activity in parallel.
  • Hexnode UEM can support automated Linux patch deployment, scoped rollouts, maintenance windows, retries, and installation-status tracking on supported distributions.

 

The CISA KEV Linux kernel update puts three vulnerabilities on the urgent remediation list. The flaws affect kernel TLS processing, ebtables network handling, and cryptographic sockets, creating risks that include memory disclosure, service disruption, and privilege escalation.

The Hacker News reported that CISA added CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 to its Known Exploited Vulnerabilities catalog on September 18, 2026. Its report identifies September 21 as the recommended remediation date for Federal Civilian Executive Branch agencies. Public reporting has not established a shared attack chain.

For IT and security teams, the immediate task is to identify affected systems, validate vendor fixes, and investigate suspicious activity.

What does the CISA KEV Linux kernel update cover?

These vulnerabilities affect separate kernel components. Exposure depends on the installed kernel, distribution patches, and relevant system configuration.

CVE-2025-39682: Kernel TLS receive processing

This flaw involves mishandling zero-length records in the kernel TLS receive path. Red Hat explains that mixed record types can bypass a receive-call constraint. Crucially, its advisory describes remote triggering when kernel TLS is enabled and attached to the relevant sockets. Teams should therefore avoid treating this solely as a local authenticated-user issue. Assess whether affected services actually use kernel TLS.

CVE-2026-53266: ebtables ARP rewriting

The ebtables SNAT flaw affects ARP hardware-address rewriting. Red Hat identifies potential privilege escalation, memory corruption, and denial of service, with exposure tied to specific bridge netfilter configurations. Review hosts using these networking rules before deciding remediation priority. The advisory also describes disabling the affected rewriting behavior as a mitigation, subject to operational validation.

CVE-2025-39964: Concurrent cryptographic socket writes

AF_ALG sockets allow unprivileged userspace applications to interact with the kernel crypto API where system policy permits. CVE-2025-39964 allows concurrent writes to the same socket, interleaving payloads and corrupting internal state. A local attacker could exploit this flaw to crash the system or corrupt cryptographic results. The fix prevents concurrent writes by enforcing exclusive write ownership.

cybersecurity-kit

Cybersecurity kit

Access essential cybersecurity resources to strengthen security, reduce risk, and improve cyber resilience.

Download the Resource Kit

How should enterprise teams respond?

Start with an inventory of Linux workstations, servers, and infrastructure hosts. Assign an owner to each affected asset and record its distribution, kernel package, operational role, and remediation status.

Validate exposure to CISA KEV Linux kernel flaws

Check each CVE against the distribution vendor’s advisory. Use Hexnode’s Live Terminal to run uname -r on individual Linux devices. For fleet-wide checks, use Execute Custom Script to deploy a script containing this command and collect running kernel versions. Compare the results and installed package versions against vendor advisories to validate exposure.

Patch and investigate in parallel

Test applicable updates, deploy them through an expedited change process, and complete any vendor-required reboot. Verify the running kernel afterward and confirm that critical services remain healthy. Track unsuccessful installations and deferred restarts until someone resolves them.

For investigation, review unexpected privileged processes, unfamiliar SSH access, new persistence mechanisms, and unexplained kernel crashes. These are general hunting leads, not published indicators specific to these exploits. Preserve relevant evidence before making disruptive changes.

How can Hexnode support Linux remediation?

Hexnode UEM provides automated Linux patch deployment for supported devices running Ubuntu 18.04 LTS and later, Linux Mint 21 and later, and Fedora 36 and later. Devices must be enrolled and have the Hexnode Linux Agent installed.

Administrators can configure Auto Patch to select updates using criteria such as severity, classification, and update name. Group assignments and target filters help scope deployment. Approval requirements support testing before rollout, while maintenance-window controls coordinate installation and reboots.

Technician notifications report installation status and failures, and configurable retries help address failed automation actions. For these CVEs, administrators should first map vendor fixes to available updates, then verify deployment results and the active kernel. These capabilities support patch execution; they do not establish that every listed CVE is automatically detected or remediated.

FAQs

CISA KEV additions indicate that there is evidence of active exploitation associated with the listed vulnerabilities. The three flaws affect different Linux kernel components, and public reporting does not establish that attackers are using them together as a single exploit chain.

No. Exposure depends on factors such as the installed kernel package, distribution-specific patches and relevant subsystem configuration. Administrators should check each CVE against their Linux distribution vendor’s advisory rather than relying only on upstream kernel version numbers.

Red Hat describes remote triggering when kernel TLS is enabled and attached to the relevant sockets. Teams should therefore determine whether affected services actually use kernel TLS instead of treating the vulnerability solely as a local-user issue.

Turn exploitation evidence into verified remediation

Active exploitation demands prompt action. Identify affected assets, apply appropriate fixes, verify completion, and investigate suspicious behavior. Keep unresolved systems visible until remediation is confirmed.

Share

Lily Anne

Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.