CISA Flags Three Linux Kernel Flaws as Exploited; Critical Bugs Also Hit Cisco ISE, Orkes Conductor and libheif

CISA KEV adds three exploited Linux kernel flaws; plus reported critical Cisco ISE, Orkes Conductor and libheif bugs. Patch priorities for K-12 IT.

  • CISA added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog in two separate alerts — CVE-2025-39682, CVE-2025-39964 and CVE-2026-53266 — indicating evidence of exploitation in the wild.
  • Separately, reporting describes a maximum-severity authentication bypass in Cisco ISE (CVE-2026-76460), a pre-authentication remote code execution flaw in Orkes Conductor (CVE-2026-58138) said to be already exploited, and a critical libheif flaw disclosed by Wordfence with no CVE assigned at publication.
  • Any district server, VM, container, NAS or appliance running a Linux kernel is in scope, as is any WordPress site that accepts HEIC photo uploads — verify exact affected versions and scores with each vendor's advisory.

What to do now

  1. Inventory Linux kernel versions across physical servers, VMs, containers, network appliances and NAS devices, then map each system to CVE-2025-39682, CVE-2025-39964 and CVE-2026-53266 using your distribution's advisory (Red Hat, Ubuntu, Debian, SUSE) — confirm the exact affected version ranges there rather than assuming them.
  2. Patch internet-facing and high-value hosts first, then schedule the rest of the fleet by risk; reboot where the kernel update requires it, and treat live patching only as a temporary bridge.
  3. Isolate or restrict hosts that cannot be patched immediately, and enable enhanced logging for privilege escalation, unexpected kernel module loads, new local accounts and unusual outbound connections; hunt for those indicators.
  4. For Cisco ISE (CVE-2026-76460), apply the vendor fix immediately or block external access to ISE API endpoints; for Orkes Conductor (CVE-2026-58138), take the service offline until patched, rotate every credential and API key it held, and restrict egress.
  5. For libheif/HEIC processing, disable HEIC upload and decoding where it is not required, sandbox image conversion in a low-privilege container, and apply WAF or virtual patching rules while awaiting an upstream patch and CVE.

Related items