Ethical Hacking News
CISA has identified three Linux kernel vulnerabilities that are currently being exploited in the wild. These vulnerabilities, which have been identified through a thorough analysis of recent security incidents, have been ranked with a CVSS score of 7.8, 8.8, and 9.8, respectively. Organizations are advised to apply the necessary fixes as soon as possible to protect themselves against these types of threats.
Three Linux kernel vulnerabilities have been identified by CISA as being actively exploited in the wild, with CVSS scores of 7.8, 8.8, and 9.8. These vulnerabilities are related to improper checks, out-of-bounds writes, and race conditions, which could allow local attackers to trigger memory disclosure, DoS attacks, or local privilege escalation. Organizations are advised to apply the necessary fixes as soon as possible, with a recommended deadline of September 21, 2026. Red Hat has acknowledged active exploitation of these vulnerabilities, and the use of Linux kernel vulnerabilities in attacks is becoming increasingly common. Organizations should take steps to ensure that their systems are protected against these types of threats, and keep their software up to date to avoid potential damage.
In a recent update to its Known Exploited Vulnerabilities (KEV) catalog, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has highlighted three Linux kernel vulnerabilities that have been found to be actively exploited in the wild. These vulnerabilities, which were identified through a thorough analysis of recent security incidents, have been ranked with a Common Vulnerability Scoring System (CVSS) score of 7.8, 8.8, and 9.8, respectively.
The first vulnerability, CVE-2025-39682, has been identified as an improper check for unusual or exceptional conditions in the TLS receive path. This vulnerability could potentially allow local authenticated users to trigger memory disclosure or denial-of-service (DoS) attacks. The severity of this vulnerability is high, with Red Hat warning that "this CVE is high risk and there are known public exploits leveraging this vulnerability." As a result, organizations are advised to apply the necessary fixes as soon as possible, with a recommended deadline of September 21, 2026.
The second vulnerability, CVE-2026-53266, has been found to be an out-of-bounds write vulnerability in the ebtables Source Network Address Translation (SNAT) Address Resolution Protocol (ARP) rewrite path. This vulnerability could potentially allow a local attacker to trigger unintended system behavior, DoS, or local privilege escalation. The CVSS score for this vulnerability is 8.8, indicating that it is considered to be of high risk.
The third vulnerability, CVE-2025-39964, has been identified as a race condition vulnerability that could allow concurrent writes to the same AF_ALG socket. This vulnerability could potentially allow a local attacker to crash the system or corrupt cryptographic operation results, causing DoS or data integrity issues. The severity of this vulnerability is moderate, with a CVSS score of 7.8.
It is worth noting that there are currently no details available on how these vulnerabilities are being exploited in the wild, and it is unclear whether they are being used as part of a single attack chain. However, Red Hat has updated the advisories for all three vulnerabilities as of September 19, 2026, at 2 a.m. UTC, to acknowledge active exploitation.
In addition to the vulnerabilities identified by CISA, it is also worth noting that a security researcher named Asim Manizada has disclosed four local privilege escalation flaws impacting the Linux kernel. These vulnerabilities, which have been identified as CVE-2026-80844, CVE-2026-81000, CVE-2026-68121, and CVE-2026-74469, respectively, have been ranked with a CVSS score of 9.8, indicating that they are of extremely high risk.
The identification of these vulnerabilities highlights the importance of keeping software up to date and applying patches as soon as possible. Organizations that fail to do so may leave themselves vulnerable to attack, and could potentially suffer significant damage as a result. It is also worth noting that the use of Linux kernel vulnerabilities in attacks is becoming increasingly common, and organizations should take steps to ensure that their systems are protected against these types of threats.
In conclusion, the recent update by CISA to its KEV catalog has highlighted three Linux kernel vulnerabilities that are currently being exploited in the wild. These vulnerabilities, which have been identified through a thorough analysis of recent security incidents, have been ranked with a CVSS score of 7.8, 8.8, and 9.8, respectively. Organizations are advised to apply the necessary fixes as soon as possible, and to take steps to ensure that their systems are protected against these types of threats.
Related Information:
https://www.ethicalhackingnews.com/articles/CISA-Identifies-Three-Linux-Kernel-Vulnerabilities-Currently-Being-Exploited-in-the-Wild-ehn.shtml
https://thehackernews.com/2026/09/cisa-flags-three-linux-kernel.html
Published: Sat Sep 19 02:43:27 2026 by llama3.2 3B Q4_K_M