News Room
16
Share
CISA Adds Three Linux Kernel Vulnerabilities to KEV Catalog Amid Active Exploitation Reports
highZero-Day Exploits

CISA Adds Three Linux Kernel Vulnerabilities to KEV Catalog Amid Active Exploitation Reports

CISA has officially added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. Security teams are urged to prioritize patching to mitigate active in-the-wild threats.

25 September 2026Last updated 25 September 20264 min readCISA
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
High
Actor Type:
Unknown
Geography:
Global
Confidence:
Confirmed
CVE:
CVE-2025-39964
Source:
CISA
Read Time:
4 min

Executive Summary

On September 19, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities (KEV) catalog to include three critical Linux kernel flaws. These vulnerabilities are currently being leveraged by threat actors in the wild, necessitating immediate attention from system administrators and security operations centers (SOCs) globally. Red Hat has issued updated advisories confirming the active exploitation status of these flaws.

Threat Analysis

The inclusion of these vulnerabilities in the KEV catalog indicates that malicious actors have successfully weaponized these flaws to compromise Linux-based infrastructure. While specific details regarding the identity of the threat actors remain under investigation, the nature of the vulnerabilities suggests a focus on privilege escalation and system disruption. The lack of a unified attack chain description implies that these exploits may be utilized across diverse campaigns, ranging from targeted espionage to opportunistic ransomware deployment.

Technical Details

The primary vulnerability, CVE-2025-39964 (CVSS 7.8), involves a race condition within the AF_ALG socket implementation. This flaw allows a local attacker to perform concurrent writes to the same socket, leading to memory corruption or system crashes. By manipulating cryptographic operation results, an attacker can potentially bypass security controls or cause a denial-of-service (DoS) condition. The other two vulnerabilities, while less publicized, are being tracked in conjunction with this flaw as part of the broader Linux kernel security update package released by major distributions.

Attribution Assessment

At this stage, attribution remains difficult. The exploitation of kernel-level vulnerabilities is a hallmark of sophisticated Advanced Persistent Threat (APT) groups capable of developing custom exploit code. However, the rapid transition of these flaws into the KEV catalog suggests that the exploits may have been commoditized or shared within underground forums, potentially lowering the barrier to entry for less sophisticated cybercriminal syndicates.

Implications

Organizations running Linux-based servers, particularly those utilizing AF_ALG for cryptographic acceleration, are at high risk. Successful exploitation could lead to full system compromise, data exfiltration, or the deployment of persistent backdoors. Given the ubiquity of the Linux kernel in cloud environments and enterprise infrastructure, the potential blast radius is significant.

Recommendations

  1. Immediate Patching: Apply the latest kernel updates provided by your Linux distribution vendor immediately.
  2. Vulnerability Scanning: Utilize automated tools to identify systems running vulnerable kernel versions across the enterprise environment.
  3. Monitoring: Enhance logging for AF_ALG socket activity and monitor for anomalous system crashes or unexpected privilege escalation attempts.
  4. Segmentation: Isolate critical Linux infrastructure to limit the potential lateral movement of an attacker in the event of a successful exploit.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo