kevregulatorNewsThe Broadside1 min read

CISA Adds Two Linux Kernel CVEs to KEV Catalog

A kernel race condition and an out-of-bounds write, both under active exploitation, now carry BOD 26-04 remediation deadlines for federal agencies.


TL;DR

CISA added two Linux kernel vulnerabilities to its Known Exploited Vulnerabilities Catalog on September 18, citing confirmed active exploitation. CVE-2025-39964 is a race condition; CVE-2026-53266 is an out-of-bounds write. Under Binding Operational Directive 26-04, federal civilian agencies must prioritize patching these on internet-facing assets. CISA didn't disclose the exploitation timeline or the actors involved, and offered no information on whether the attacks tie to known intrusions.

CISA added CVE-2025-39964 and CVE-2026-53266 to its Known Exploited Vulnerabilities Catalog on September 18, citing confirmed active exploitation of both Linux kernel flaws. CVE-2025-39964 is a race condition; CVE-2026-53266 is an out-of-bounds write. The agency didn't disclose when exploitation began, which threat actors are involved, or whether specific organizations have been targeted.

Binding Operational Directive 26-04 requires Federal Civilian Executive Branch agencies to prioritize remediation of KEV-listed vulnerabilities on publicly exposed assets. The directive also sets expectations for determining whether threat actors compromised affected systems before patches were applied. While BOD 26-04 binds only FCEB agencies, CISA encourages all organizations, including contractors and primes, to adopt the same risk-based prioritization.

This follows a three-CVE KEV addition on September 11 and marks the latest in a series of catalog updates this month. For vulnerability management teams, the steady pace of additions means new remediation deadlines arrive on a recurring rhythm, and Linux kernel entries carry particular weight given the breadth of the attack surface.


Published ·Deep Fathom