CVE Tools

CISA alerts of active exploitation of three Linux kernel flaws

BleepingComputerBy Bill Toulas

Reported exploitedLinux Kernel

Our summary

CISA has added CVE-2025-39964, CVE-2026-53266, and CVE-2025-39682 in the Linux Kernel to its Known Exploited Vulnerabilities catalog after confirming their use in attacks. The flaws involve AF_ALG cryptographic sockets, ebtables SNAT, and the kTLS receive path, with potential consequences including memory corruption, system crashes, altered cryptographic behavior, and privilege escalation. Federal agencies must apply available mitigations and updates and perform forensic triage on affected assets.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store