Linux Kernel Actively Exploited Vulnerabilities Remain Unpatched Past Federal Deadline (CVE-2025-39682 / CVE-2026-53266 / CVE-2025-39964)
Scope: Linux Kernel (All Distributions Running Affected Kernel Versions, Including Servers, Container Hosts, and CI/CD Runners)
Severity: Red
CISA added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog on September 18, 2026, after Red Hat confirmed active exploitation with known public exploits available for all three, and set a federal remediation deadline of September 21, 2026, which has now passed. CVE-2025-39682 (CVSS 9.8) is a flaw in the kernel's TLS receive path where a zero-length record can bypass normal message handling, leading to memory disclosure or denial of service. CVE-2026-53266 (CVSS 8.8) is an out-of-bounds write in the ebtables SNAT ARP rewrite path that can trigger memory corruption, denial of service, or local privilege escalation on systems using specific bridge netfilter rules. CVE-2025-39964 (CVSS 7.8) is a race condition in the kernel's AF_ALG cryptographic interface that can crash the system or corrupt cryptographic operation results. Any system that remains unpatched past yesterday's deadline should now be treated as a live exposure rather than a routine maintenance item, particularly given that a separate researcher published four additional public root exploits for the Linux kernel on the same day these three were added to KEV. Organizations must apply their distribution's kernel update immediately, reboot into the patched kernel, verify the running version afterward, and conduct forensic review on any system that was reachable and unpatched during the exposure window.
The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.