{"id":3000,"date":"2026-09-19T07:08:56","date_gmt":"2026-09-19T07:08:56","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=3000"},"modified":"2026-09-19T07:08:56","modified_gmt":"2026-09-19T07:08:56","slug":"cisa-flags-three-linux-kernel-vulnerabilities-exploited-in-the-wild","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=3000","title":{"rendered":"CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 19, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Linux<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgcKuQ4GC9r1-4fQ3Ap_CQko0y3nMI0SnATF3WNSv48uFtNskrV4PqnyW4s0L7sXcojrHoJCEZRazGJNz5JhxrTTSYZSAQeD-xwdquE3X7pJ_ylBUerrybIiaE3V-i1vXdiLr_N1KCM9GTmeAKLlgySqEr0QeCB5ckvnppiEHSZhnEqv0IfUnqCKdA1kKsN\/s1700-nu-rw-lo-l85-e365\/cisa-linux.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/09\/18\/cisa-adds-two-known-exploited-vulnerabilities-catalog\" target=\"_blank\">three security flaws<\/a> impacting the <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/09\/18\/cisa-adds-one-known-exploited-vulnerability-catalog\" target=\"_blank\">Linux kernel<\/a> to its Known Exploited Vulnerabilities (<a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\">KEV<\/a>) catalog, citing evidence of active exploitation.<\/p>\n<p>The vulnerabilities are listed below &#8211;<\/p>\n<ul>\n<li><strong><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-39682\" target=\"_blank\">CVE-2025-39682<\/a><\/strong> (CVSS score: 9.8) &#8211; An improper check for unusual or exceptional conditions vulnerability in the TLS receive path that could allow local authenticated users to trigger memory disclosure or denial-of-service (DoS).<\/li>\n<li><strong><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-53266\" target=\"_blank\">CVE-2026-53266<\/a><\/strong> (CVSS score: 8.8) &#8211; An out-of-bounds write vulnerability in the ebtables Source Network Address Translation (SNAT) Address Resolution Protocol (ARP) rewrite path that could allow a local attacker to trigger unintended system behavior, DoS, or local privilege escalation.<\/li>\n<li><strong><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-39964\" target=\"_blank\">CVE-2025-39964<\/a><\/strong> (CVSS score: 7.8) &#8211; A race condition vulnerability that could allow concurrent writes to the same AF_ALG socket, allowing a local attacker to crash the system or corrupt cryptographic operation results, causing DoS or data integrity issues.<\/li>\n<\/ul>\n<p>There are currently no details on how the three vulnerabilities are being exploited in the wild, and if they are being weaponized as part of a single attack chain. However, Red Hat has <a href=\"https:\/\/access.redhat.com\/security\/cve\/cve-2025-39682\" target=\"_blank\">updated<\/a> the <a href=\"https:\/\/access.redhat.com\/security\/cve\/cve-2026-53266\" target=\"_blank\">advisories<\/a> for <a href=\"https:\/\/access.redhat.com\/security\/cve\/cve-2025-39964\" target=\"_blank\">all the flaws<\/a> as of September 19, 2026, at 2 a.m. UTC to acknowledge active exploitation.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abThis CVE is high risk and there are known public exploits leveraging this vulnerability,\u00bb Red Hat said. \u00abAddress this vulnerability with high priority.\u00bb<\/p>\n<p>Pursuant to Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the necessary fixes by September 21, 2026.<\/p>\n<p>The development comes as a security researcher named Asim Manizada disclosed four local privilege escalation flaws impacting the Linux kernel: CVE-2026-80844 (aka DirtyAH6), CVE-2026-81000 (aka TUNderflow), CVE-2026-68121 (aka PPPoEject), and CVE-2026-74469 (aka DiagSpill).<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 19, 2026Vulnerability \/ Linux The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV)&hellip;<\/p>\n","protected":false},"author":1,"featured_media":3001,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[62,128,542,1571,181,474,656],"class_list":["post-3000","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-cisa","tag-exploited","tag-flags","tag-kernel","tag-linux","tag-vulnerabilities","tag-wild"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3000","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3000"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3000\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/3001"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3000"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3000"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3000"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}