CISA Adds Two Known Exploited Vulnerabilities to Catalog

High · CISA Advisories ·

CISA KEV · Exploited

What happened

CISA added two actively exploited Linux kernel flaws (CVE-2025-39964 race condition, CVE-2026-53266 out-of-bounds write) to its KEV catalog; Linux systems are at risk.

What to do now

Patch Linux kernel on all servers, appliances, and endpoints per vendor guidance; prioritize internet-facing assets. If patch unavailable, restrict access, monitor logs, and verify with vendor advisory.

CVE references

  • CVE-2025-39964
  • CVE-2026-53266

Original source

CISA Advisories

AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.

← All cyber news