logo

CISA Flags Active Exploitation of Linux Kernel Vulnerabilities

ID: 2fcfff7b-6039-5181-b706-a882967dcb0b

STIX ID: report--2fcfff7b-6039-5181-b706-a882967dcb0b

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-09-19

Date Updated: 2026-09-19

...
...

CISA has listed three actively exploited Linux kernel vulnerabilities (including CVE-2025-39964, a race condition in AF_ALG sockets) in its Known Exploited Vulnerabilities catalog; the flaws can lead to crashes, DoS, and local privilege escalation, and Red Hat has issued advisories while federal agencies are mandated to apply patches by September 21, 2026. The vulnerabilities mainly affect multi-tenant Linux servers, container hosts, and systems running untrusted local code, and researchers are continuing to monitor exploitation activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.