CISA issues urgent three-day patch deadline for critical Linux kernel vulnerabilities

The US Cybersecurity and Infrastructure Security Agency (CISA) has added three critical Linux kernel vulnerabilities—CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964—to its Known Exploited Vulnerabilities (KEV) catalog. These flaws, which enable denial-of-service attacks, privilege escalation, and data corruption, are currently being exploited in the wild. Red Hat has confirmed the high-risk nature of these bugs and provided necessary patches across various kernel versions. Due to the severity of the threats, CISA has mandated that federal agencies apply security updates within an unusually short three-day window, expiring September 21, 2026. While some vulnerabilities offer temporary mitigations, such as disabling specific modules or rules, experts strongly recommend immediate patching as the only definitive security measure. Users are urged to verify their kernel versions and apply the latest stable updates provided by their distribution maintainers to mitigate potential system compromise.
This is a summary. Read the full article at the original source:
TechRadarRelated stories
Researchers demonstrate InjectEave: A technique to intercept audio through walls
Researchers from HKUST (Guangzhou) and HK PolyU have unveiled 'InjectEave,' a sophisticated eavesdropping technique capable of extracting audio from h…
The article discusses an innovative approach to digital content authentication, proposing the use of 'spymarks' as a superior alternative to tradition…
Cybersecurity researchers at Zimperium have identified a sophisticated new Android malware strain dubbed RatHat. Unlike traditional malware that relie…


