CISA Adds Two Known Exploited Vulnerabilities to Catalog
High · CISA Advisories ·
CISA KEV · Exploited
What happened
CISA added two actively exploited Linux kernel flaws (CVE-2025-39964 race condition, CVE-2026-53266 out-of-bounds write) to its KEV catalog; Linux systems are at risk.
What to do now
Patch Linux kernel on all servers, appliances, and endpoints per vendor guidance; prioritize internet-facing assets. If patch unavailable, restrict access, monitor logs, and verify with vendor advisory.
CVE references
- CVE-2025-39964
- CVE-2026-53266
Original source
AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.