Close Menu
NCIJ Network NCIJ Network
    What's Hot

    UNGA 2026: Trump, Iran, China, AI, and the Secretary-General Race

    September 22, 2026

    US strikes on alleged drug boats may be ‘crimes against humanity’, UN says | News

    September 22, 2026

    Reform-Agenda: Merz‘ neue Suche nach Gerechtigkeit – POLITICO

    September 22, 2026
    Facebook X (Twitter) Instagram
    Trending
    • UNGA 2026: Trump, Iran, China, AI, and the Secretary-General Race
    • US strikes on alleged drug boats may be ‘crimes against humanity’, UN says | News
    • Reform-Agenda: Merz‘ neue Suche nach Gerechtigkeit – POLITICO
    • The Search for Silicon Valley’s Most Powerful Woman
    • RatHat Android Trojan Uses AI for Automation
    • Bitcoin price news: BTC eyes $90,000 as leverage is building
    • Brain scans reveal a possible cause of long COVID fatigue and brain fog
    • Tourism has potential to slow coral decline at Bali travel hotspot: Study
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 22
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    CISA alerts of active exploitation of three Linux kernel flaws

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 22, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical.

    The three security issues were added separately last week and have severity ratings ranging from medium to critical. One of them, tracked as CVE-2025-39964, existed in the Linux kernel for 14 years.

    CISA marked all three flaws with the highest priority for federal agencies, ordering them to apply available security updates and mitigations by the end of today.

    The three vulnerabilities are:

    • CVE-2025-39964: a race condition in the kernel’s AF_ALG cryptographic socket interface that allows concurrent writes to corrupt per-socket state and potentially crash systems or alter cryptographic results.
    • CVE-2026-53266: an out-of-bounds write vulnerability in the Linux kernel’s ebtables SNAT implementation that can cause an ARP address rewrite to modify shared file-backed memory without first making the affected packet range writable.
    • CVE-2025-39682: a Linux kernel TLS receive-path logic flaw that mishandles zero-length records queued for later processing, potentially allowing different TLS record types to be processed together when kTLS is in use.

    CISA says [1, 2] the vulnerabilities have been exploited in attacks but has not revealed any details about the incidents or the nature of the threat actors.

    Offensive security company STAR Labs found CVE-2025-39964, saying that its researchers found the issue with no help from an AI system. They demonstrated the vulnerability by achieving privilege escalation and container escape in Google’s kernelCTF.

    For CVE-2025-39682, there are public exploits available, as also confirmed by Red Hat in its security bulletin. Red Hat also confirmed a known exploit available for CVE-2026-53266.

    Researcher Kimmo Suominen has published a technical analysis and patch-status tracker for CVE-2026-53266 on GitHub, outlining a potential privilege-escalation path involving modifications to file-backed memory.

    However, the researcher notes that the proposed exploitation chain is inferred by analogy with Dirty Pipe and has not been demonstrated with public exploit code.

    CISA has marked all three flaws as requiring “forensic triage.” This means that for every affected asset, federal agencies need to examine it for signs that exploitation already occurred.

    Currently, none of the three flaws is flagged as exploited by ransomware groups.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    active alerts CISA exploitation flaws Kernel Linux
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    RatHat Android Trojan Uses AI for Automation

    US Proposes AI Incident Alert System in Talks With China, Bessent Says

    Google Fined €403 Million Over GDPR Violations Tied to Location Data

    Dragos Completes NetRise and runZero Acquisitions Following Accenture Deal

    BigCommerce alerts merchants of data breach linked to Ribon apps

    Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    UNGA 2026: Trump, Iran, China, AI, and the Secretary-General Race

    September 22, 2026

    US strikes on alleged drug boats may be ‘crimes against humanity’, UN says | News

    September 22, 2026

    Reform-Agenda: Merz‘ neue Suche nach Gerechtigkeit – POLITICO

    September 22, 2026

    The Search for Silicon Valley’s Most Powerful Woman

    September 22, 2026
    Latest Posts

    Google Assistant will disappear from your phone next month

    August 5, 2026

    Pope Leo Will Visit Peru, Where He Lived for Years, in November

    August 5, 2026

    Forget the goals and PBs – just enjoy it | Sport

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    UNGA 2026: Trump, Iran, China, AI, and the Secretary-General Race

    September 22, 2026

    US strikes on alleged drug boats may be ‘crimes against humanity’, UN says | News

    September 22, 2026

    Reform-Agenda: Merz‘ neue Suche nach Gerechtigkeit – POLITICO

    September 22, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.