News Room
16
Share
CISA Adds Three Linux Kernel Flaws to KEV Catalog Amid Active Exploitation Concerns
criticalZero-Day Exploits

CISA Adds Three Linux Kernel Flaws to KEV Catalog Amid Active Exploitation Concerns

The Cybersecurity and Infrastructure Security Agency (CISA) has officially added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. These flaws are currently being targeted in the wild, prompting urgent patching requirements for enterprise systems.

25 September 2026Last updated 25 September 20264 min readCISA
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
Critical
Actor Type:
Unknown
Geography:
Global
Confidence:
Confirmed
CVE:
CVE-2025-39964
Source:
CISA
Read Time:
4 min

Executive Summary

On September 19, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities (KEV) catalog to include three critical security flaws impacting the Linux kernel. These vulnerabilities, which include CVE-2025-39964, have been confirmed as actively exploited in the wild. The inclusion of these flaws in the KEV catalog signals a high-priority threat to organizations relying on Linux-based infrastructure, necessitating immediate remediation efforts.

Threat Analysis

The active exploitation of these Linux kernel vulnerabilities represents a significant escalation in the threat landscape for enterprise environments. While specific details regarding the threat actors behind these campaigns remain limited, the nature of the vulnerabilities—which allow for local privilege escalation and potential system crashes—suggests that attackers are focusing on gaining unauthorized control over server environments. The rapid addition of these flaws to the CISA KEV catalog underscores the severity of the risk posed to critical infrastructure and cloud-native deployments.

Technical Details

The primary vulnerability highlighted is CVE-2025-39964, which carries a CVSS score of 7.8. This flaw is characterized as a race condition vulnerability that occurs within the AF_ALG socket implementation. By exploiting this condition, a local attacker can perform concurrent writes to the same socket, leading to system instability, denial-of-service (DoS) conditions, or the corruption of cryptographic operations. This could potentially allow an attacker to bypass security controls or exfiltrate sensitive data processed by the kernel.

Attribution Assessment

At this time, there is no definitive attribution to a specific Advanced Persistent Threat (APT) group or cybercriminal syndicate. However, the exploitation of kernel-level vulnerabilities is a hallmark of sophisticated actors seeking to establish persistence or escalate privileges within compromised networks. Security researchers are currently monitoring for patterns that might link these exploits to known campaigns, but the lack of public exploit chains suggests a targeted approach by well-resourced adversaries.

Implications

The exploitation of these vulnerabilities poses a severe risk to the integrity and availability of Linux-based systems. Organizations that fail to patch these flaws are susceptible to local privilege escalation, which could serve as a stepping stone for lateral movement within a network. Given the ubiquity of the Linux kernel in cloud environments and enterprise servers, the potential for widespread impact is substantial.

Recommendations

  1. Immediate Patching: Organizations must prioritize the application of the latest Linux kernel security updates provided by their respective distributions (e.g., Red Hat, Debian, Ubuntu).
  2. Vulnerability Scanning: Conduct comprehensive scans across all Linux assets to identify systems running vulnerable kernel versions.
  3. Monitoring: Implement enhanced logging and monitoring for AF_ALG socket activity to detect potential exploitation attempts.
  4. Least Privilege: Enforce strict access controls to limit the number of users capable of executing local commands, thereby reducing the attack surface for local privilege escalation exploits.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo