CISA Flags Three Linux Kernel Flaws as Exploited; Critical Bugs Also Hit Cisco ISE, Orkes Conductor and libheif
CISA KEV adds three exploited Linux kernel flaws; plus reported critical Cisco ISE, Orkes Conductor and libheif bugs. Patch priorities for K-12 IT.
- CISA added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog in two separate alerts — CVE-2025-39682, CVE-2025-39964 and CVE-2026-53266 — indicating evidence of exploitation in the wild.
- Separately, reporting describes a maximum-severity authentication bypass in Cisco ISE (CVE-2026-76460), a pre-authentication remote code execution flaw in Orkes Conductor (CVE-2026-58138) said to be already exploited, and a critical libheif flaw disclosed by Wordfence with no CVE assigned at publication.
- Any district server, VM, container, NAS or appliance running a Linux kernel is in scope, as is any WordPress site that accepts HEIC photo uploads — verify exact affected versions and scores with each vendor's advisory.
What to do now
- Inventory Linux kernel versions across physical servers, VMs, containers, network appliances and NAS devices, then map each system to CVE-2025-39682, CVE-2025-39964 and CVE-2026-53266 using your distribution's advisory (Red Hat, Ubuntu, Debian, SUSE) — confirm the exact affected version ranges there rather than assuming them.
- Patch internet-facing and high-value hosts first, then schedule the rest of the fleet by risk; reboot where the kernel update requires it, and treat live patching only as a temporary bridge.
- Isolate or restrict hosts that cannot be patched immediately, and enable enhanced logging for privilege escalation, unexpected kernel module loads, new local accounts and unusual outbound connections; hunt for those indicators.
- For Cisco ISE (CVE-2026-76460), apply the vendor fix immediately or block external access to ISE API endpoints; for Orkes Conductor (CVE-2026-58138), take the service offline until patched, rotate every credential and API key it held, and restrict egress.
- For libheif/HEIC processing, disable HEIC upload and decoding where it is not required, sandbox image conversion in a low-privilege container, and apply WAF or virtual patching rules while awaiting an upstream patch and CVE.
Related items
- Cisco Zero-Day Highlights API Endpoint Authentication Issues
- In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
- Most WordPress pros still lack a breach recovery plan
- Wordfence Argus Discovers Critical Vulnerability in libheif, the Library That Opens iPhone Photos on Your Server
- CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
- CISA Adds One Known Exploited Vulnerability to Catalog
- CISA Adds Two Known Exploited Vulnerabilities to Catalog
- Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild