Patch Alert: Linux Kernel Flaws Now Actively Exploited; Critical Cisco ISE, WordPress, and libheif Vulnerabilities Also Disclosed

CISA KEV adds Linux kernel flaws (active exploitation). Cisco ISE auth-bypass zero-day, libheif and WordPress core issues disclosed. Patch and monitor.

  • CISA added Linux kernel flaws to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild; patch all Linux systems promptly.
  • Cisco also disclosed an authentication bypass in Identity Services Engine (ISE), and researchers reported critical issues in libheif (HEIC image processing) and a set of WordPress core flaws that includes a forced theme-install vector. Verify exact CVSS scores and affected versions with each vendor's advisory.
  • K-12 and government agencies should prioritize internet-facing and identity systems, restrict administrative access, enforce MFA, and verify backups; no education-sector targeting has been reported.

What to do now

  1. Patch as advisories are released: apply the latest Linux kernel from your distribution (the KEV listing is the priority), the vendor fix for Cisco ISE per its advisory, the latest WordPress core update, and any libheif/OS updates. Prioritize internet-facing and identity systems.
  2. If patching is delayed: restrict administrative interfaces with VPN/firewall/WAF rules, limit API exposure to trusted networks, disable or sandbox untrusted HEIC upload processing, and warn admins against opening unexpected administrative links (especially in email).
  3. Enforce MFA and least privilege everywhere, especially for WordPress and Cisco ISE administrator accounts, and disable unused admin accounts and remote-management features.
  4. Review logs for anomalies: ISE authentication events, WordPress theme installations or unexpected admin activity, Linux kernel panics or privilege-escalation attempts, and HEIC processing errors.
  5. Validate offline, tested backups of WordPress and other critical services, and confirm an incident response plan is documented and practiced; note that surveys continue to show many WordPress operators lack a recovery plan.