importantSYS.SOURCE: The Hacker News• 2026-09-19T11:54:10+05:30
CISA Identifies Three Actively Exploited Linux Kernel Vulnerabilities
CISA added three Linux kernel vulnerabilities to its KEV catalog due to active exploitation, with CVSS scores ranging from 7.8 to 9.8, posing risks of memory disclosure, DoS, and privilege escalation. Federal agencies are urged to apply fixes by September 21, 2026, following Red Hat's advisories on imminent threats.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The vulnerabilities are listed below -
CVE-2025-39682 (CVSS score: 9.8) - An improper check for unusual or exceptional conditions vulnerability in the TLS receive path
*** END OF TRANSMISSION ***