CISA alerts of active exploitation of three Linux kernel flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical.

The three security issues were added separately last week and have severity ratings ranging from medium to critical. One of them, tracked as CVE-2025-39964, existed in the Linux kernel for 14 years.

CISA marked all three flaws with the highest priority for federal agencies, ordering them to apply available security updates and mitigations by the end of today.

CISA says [1, 2] the vulnerabilities have been exploited in attacks but has not revealed any details about the incidents or the nature of the threat actors.

Offensive security company STAR Labs found CVE-2025-39964, saying that its researchers found the issue with no help from an AI system. They demonstrated the vulnerability by achieving privilege escalation and container escape in Google’s kernelCTF.

For CVE-2025-39682, there are public exploits available, as also confirmed by Red Hat in its security bulletin. Red Hat also confirmed a known exploit available for CVE-2026-53266.

Researcher Kimmo Suominen has published a technical analysis and patch-status tracker for CVE-2026-53266 on GitHub, outlining a potential privilege-escalation path involving modifications to file-backed memory.

However, the researcher notes that the proposed exploitation chain is inferred by analogy with Dirty Pipe and has not been demonstrated with public exploit code.

CISA has marked all three flaws as requiring “forensic triage.” This means that for every affected asset, federal agencies need to examine it for signs that exploitation already occurred.

Currently, none of the three flaws is flagged as exploited by ransomware groups.

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

CISA orders urgent patching of actively exploited Zimbra flaw

Critical Progress LoadMaster flaw now actively exploited in attacks

Cisco warns of FMC static credential flaw exploited in zero-day attacks

Check Point warns of SmartConsole zero-day exploited in attacks

CISA orders urgent action on actively exploited Langflow RCE flaw

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

North Korean WaterPlum hackers infected 30,000 devices worldwide

Researchers escape OpenAI Codex sandbox to run commands on host

Overdue a password health-check? Audit your Active Directory for free

Watch a working exploit hit live controls and see exactly what blocks, detects, or misses

Find out how long recovery really takes — and what it costs. Read the 2025 BCDR Report.

Automate Onboarding and Access Reviews with No-Code IGA: See how it works

Overdue a password health-check? Audit your Active Directory for free

Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure

Read our posting guidelinese to learn what content is prohibited.