CVE Tools

CISA BOD 26-04 Timelines for Three Linux Kernel CVEs

Qualys Security BlogBy Maihar Arora3 min read

Reported exploitedLinux Kernel

Our summary

CISA added actively exploited Linux kernel flaws CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 to its KEV Catalog, with the shortest BOD 26-04 remediation deadline expiring on September 21, 2026. CVE-2025-39682 can expose memory or cause denial of service, CVE-2026-53266 can corrupt memory and potentially enable local privilege escalation, and CVE-2025-39964 can crash systems or produce corrupted cryptographic output. Organizations should urgently update affected Linux systems, prioritizing internet-facing assets.

Read at Qualys Security Blog

Below is the opening; the full story is at Qualys Security Blog.

From Qualys Security Blog


Executive Summary

CISA added three actively exploited Linux kernel vulnerabilities: CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 to its KEV Catalog on September 18, 2026, triggering a 3-day remediation deadline that passed on September 21. Under CISA BOD 26-04, a 3-day window applies to CVE-2025-39682 across all assets, and for the other two, the deadline is 3 days for publicly exposed assets and 14 days for internal assets. With the September 21 deadline now passed, affected systems should be patched immediately. Qualys TruRisk Eliminate identifies affected assets with vulnerability context and provides High-Reliability Patches to support remediation and verification.…

Continue at Qualys Security Blog

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store