
CISA Adds Three Linux Kernel Vulnerabilities to KEV Catalog Amid Active Exploitation Reports
CISA has officially added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. Security teams are urged to prioritize patching to mitigate active in-the-wild threats.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- High
- Actor Type:
- Unknown
- Geography:
- Global
- Confidence:
- Confirmed
- CVE:
- CVE-2025-39964
- Source:
- CISA
- Read Time:
- 4 min
Executive Summary
On September 19, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities (KEV) catalog to include three critical Linux kernel flaws. These vulnerabilities are currently being leveraged by threat actors in the wild, necessitating immediate attention from system administrators and security operations centers (SOCs) globally. Red Hat has issued updated advisories confirming the active exploitation status of these flaws.
Threat Analysis
The inclusion of these vulnerabilities in the KEV catalog indicates that malicious actors have successfully weaponized these flaws to compromise Linux-based infrastructure. While specific details regarding the identity of the threat actors remain under investigation, the nature of the vulnerabilities suggests a focus on privilege escalation and system disruption. The lack of a unified attack chain description implies that these exploits may be utilized across diverse campaigns, ranging from targeted espionage to opportunistic ransomware deployment.
Technical Details
The primary vulnerability, CVE-2025-39964 (CVSS 7.8), involves a race condition within the AF_ALG socket implementation. This flaw allows a local attacker to perform concurrent writes to the same socket, leading to memory corruption or system crashes. By manipulating cryptographic operation results, an attacker can potentially bypass security controls or cause a denial-of-service (DoS) condition. The other two vulnerabilities, while less publicized, are being tracked in conjunction with this flaw as part of the broader Linux kernel security update package released by major distributions.
Attribution Assessment
At this stage, attribution remains difficult. The exploitation of kernel-level vulnerabilities is a hallmark of sophisticated Advanced Persistent Threat (APT) groups capable of developing custom exploit code. However, the rapid transition of these flaws into the KEV catalog suggests that the exploits may have been commoditized or shared within underground forums, potentially lowering the barrier to entry for less sophisticated cybercriminal syndicates.
Implications
Organizations running Linux-based servers, particularly those utilizing AF_ALG for cryptographic acceleration, are at high risk. Successful exploitation could lead to full system compromise, data exfiltration, or the deployment of persistent backdoors. Given the ubiquity of the Linux kernel in cloud environments and enterprise infrastructure, the potential blast radius is significant.
Recommendations
- Immediate Patching: Apply the latest kernel updates provided by your Linux distribution vendor immediately.
- Vulnerability Scanning: Utilize automated tools to identify systems running vulnerable kernel versions across the enterprise environment.
- Monitoring: Enhance logging for AF_ALG socket activity and monitor for anomalous system crashes or unexpected privilege escalation attempts.
- Segmentation: Isolate critical Linux infrastructure to limit the potential lateral movement of an attacker in the event of a successful exploit.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

CISA Adds Three Linux Kernel Flaws to KEV Catalog Amid Active Exploitation Concerns

Arista Networks Issues Urgent Warning Over Actively Exploited VeloCloud Zero-Day Vulnerability

