INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

CISA Adds Linux Kernel Flaws to Known Exploited Vulnerabilities List

| 2026-09-21 09:31 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
Hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers have been actively exploiting these flaws since at least September 21st, with the most recent vulnerability existing in the Linux kernel for 14 years. CISA marked all three flaws as requiring "forensic triage," meaning federal agencies need to examine affected assets for signs of exploitation. Currently, none of the three vulnerabilities is flagged as exploited by ransomware groups. The attacks work by taking advantage of a race condition, an out-of-bounds write vulnerability, and a Linux kernel TLS receive-path logic flaw, allowing hackers to potentially crash systems or alter cryptographic results. As of now, no details about the incidents or nature of the threat actors have been revealed.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-81000, CVE-2026-53266 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-81000CVE-2026-81000 CVE-2026-53266CVE-2026-53266 CVE-2026-80844CVE-2026-80844 CVE-2026-74469CVE-2026-74469 CVE-2025-39682CVE-2025-39682 CVE-2026-68121CVE-2026-68121 CVE-2025-39964CVE-2025-39964
Target & Sectors
Global Scope governmentgovernment
Incident Timeline
‎2026/09/14
Threat actors exploited three separately added Linux kernel vulnerabilities with severity ratings ranging from medium to critical.
‎September 19, 2026
Threat actors used the three exploited Linux kernel vulnerabilities to target organizations before Red Hat updated its advisories on September 19, 2026.
general_metric 2 following vulnerabilities
organisation UTC
‎Sep 19, 2026
Threat actors used three exploited Linux kernel vulnerabilities to launch attacks on organizations worldwide.
‎September 20, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Linux Kernel vulnerabilities to its Known Exploited Vulnerabilities catalog on September 20, 2026.
infrastructure Linux
tactic T1588.006 - Vulnerabilities
attribution Known Exploited
‎2026/09/21
CISA marked three exploited Linux kernel vulnerabilities with the highest priority for federal agencies, ordering them to apply available security updates and mitigations by September 21, 2026.
‎September 21, 2026
Federal Civilian Executive Branch agencies are ordered by CISA to apply necessary fixes for three exploited Linux kernel vulnerabilities by September 21, 2026.
attribution FCEB
attribution Pursuant to Binding Operational Directive (
attribution Federal Civilian Executive Branch
general_metric 26 Binding Operational Directive
‎2026/09/21
Threat actors are exploiting three Linux kernel vulnerabilities, including CVE-2025-39682 and CVE-2026-53266, which have been added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog.
infrastructure Linux
organisation Known Exploited
organisation KEV
organisation CVE-2025-39964
organisation CVE-2025-39682
organisation CVE-2026-74469
organisation TUNderflow
organisation DiagSpill
organisation Microsoft Patches
organisation Kaspersky
organisation BIND
organisation TLS
organisation Red Hat
organisation DoS
organisation STAR Labs
organisation DATA
organisation rx_list
organisation Google
organisation Dirty Pipe
organisation NFL
organisation CHANEL
organisation Source Network Address Translation
Tactical Metrics
Metrics
infrastructure
‎Linux
Affected Product
Intelligence Sources