Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

    September 20, 2026

    Treasury Sanctions Crypto Exchange Behind Iran’s Bitcoin Tolls on Hormuz Ships

    September 20, 2026

    Cultural treasures are being destroyed by war, and people want justice

    September 20, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files
    • Treasury Sanctions Crypto Exchange Behind Iran’s Bitcoin Tolls on Hormuz Ships
    • Cultural treasures are being destroyed by war, and people want justice
    • Meta’s Muse is creepy, but maybe not for the reasons you think
    • CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
    • Gen Z are investing like Boomers
    • Saudi-led coalition says defences intercept Houthi missile fired at Riyadh | Houthis News
    • Kemi Badenoch accuses Andy Burnham of ‘fiddling while Europe risks burning’ | Kemi Badenoch
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Sunday, September 20
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 20, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 19, 2026Vulnerability / Linux

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

    The vulnerabilities are listed below –

    • CVE-2025-39682 (CVSS score: 9.8) – An improper check for unusual or exceptional conditions vulnerability in the TLS receive path that could allow local authenticated users to trigger memory disclosure or denial-of-service (DoS).
    • CVE-2026-53266 (CVSS score: 8.8) – An out-of-bounds write vulnerability in the ebtables Source Network Address Translation (SNAT) Address Resolution Protocol (ARP) rewrite path that could allow a local attacker to trigger unintended system behavior, DoS, or local privilege escalation.
    • CVE-2025-39964 (CVSS score: 7.8) – A race condition vulnerability that could allow concurrent writes to the same AF_ALG socket, allowing a local attacker to crash the system or corrupt cryptographic operation results, causing DoS or data integrity issues.

    There are currently no details on how the three vulnerabilities are being exploited in the wild, and if they are being weaponized as part of a single attack chain. However, Red Hat has updated the advisories for all the flaws as of September 19, 2026, at 2 a.m. UTC to acknowledge active exploitation.

    Cybersecurity

    “This CVE is high risk and there are known public exploits leveraging this vulnerability,” Red Hat said. “Address this vulnerability with high priority.”

    Pursuant to Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the necessary fixes by September 21, 2026.

    The development comes as a security researcher named Asim Manizada disclosed four local privilege escalation flaws impacting the Linux kernel: CVE-2026-80844 (aka DirtyAH6), CVE-2026-81000 (aka TUNderflow), CVE-2026-68121 (aka PPPoEject), and CVE-2026-74469 (aka DiagSpill).

    CISA Exploited flags Kernel Linux Vulnerabilities wild
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

    SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

    Identity Visibility in 2026: The Foundation of Identity Security

    Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

    Viral AI actress’ hotline face-scans every caller, watches their mood

    North Korean WaterPlum hackers infected 30,000 devices worldwide

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

    September 20, 2026

    Treasury Sanctions Crypto Exchange Behind Iran’s Bitcoin Tolls on Hormuz Ships

    September 20, 2026

    Cultural treasures are being destroyed by war, and people want justice

    September 20, 2026

    Meta’s Muse is creepy, but maybe not for the reasons you think

    September 20, 2026
    Latest Posts

    AIPAC Spending Dominates the Michigan Democratic Senate Primary

    August 5, 2026

    Labour members ‘have tougher view on welfare than you might think’, poll suggests | Labour

    August 5, 2026

    Palantir funnels earnings to US to avoid European taxes, report finds – POLITICO

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

    September 20, 2026

    Treasury Sanctions Crypto Exchange Behind Iran’s Bitcoin Tolls on Hormuz Ships

    September 20, 2026

    Cultural treasures are being destroyed by war, and people want justice

    September 20, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.