Government Advisory

CISA Flags Two Actively Exploited Linux Kernel Flaws

CISA · 18 Sept 2026
Key Takeaway Ask your IT provider or hosting service whether your Linux-based systems have been patched against these two actively exploited kernel vulnerabilities.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added two new flaws to its Known Exploited Vulnerabilities (KEV) Catalog: a race condition vulnerability (CVE-2025-39964) and an out-of-bounds write vulnerability (CVE-2026-53266), both affecting the Linux kernel. Both have been confirmed as actively exploited by attackers, making them a real and current risk rather than a theoretical one.

These vulnerability types are commonly used by cybercriminals to gain unauthorised access or take control of systems. While CISA's related directive only legally binds US federal agencies, the agency is urging all organisations, including businesses outside the US, to prioritise patching vulnerabilities listed in the KEV catalog, especially on systems exposed to the internet.

Many Australian businesses run Linux-based servers, network devices, or cloud infrastructure without realising it, so these kernel flaws could affect systems managed by IT providers or hosting platforms. Checking with vendors and IT support about patch status is a sensible precaution.

CISA Linux vulnerability management KEV catalog patching

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.