CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

High · The Hacker News ·

CISA KEV · Exploited

What happened

CISA added three Linux kernel flaws to KEV, including CVE-2025-39682 (CVSS 9.8) in TLS receive path, with active exploitation. Linux systems are affected.

What to do now

Apply Linux kernel security updates from your distro vendor now; prioritize internet-facing/TLS servers. Verify all three CVEs with vendor advisory. If kTLS is unused, disable it; monitor for exploitation.

CVE references

  • CVE-2025-39682

Original source

The Hacker News

AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.

← All cyber news