CISA added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on 18 September, citing evidence of active exploitation: CVE-2025-39682 (9.8), an improper check for unusual or exceptional conditions in the TLS receive path that could let a local authenticated user trigger memory disclosure or denial of service; CVE-2026-53266 (8.8), an out-of-bounds write in the ebtables SNAT ARP rewrite path that could allow a local attacker to cause unintended system behaviour, denial of service or local privilege escalation; and CVE-2025-39964 (7.8), a race condition permitting concurrent writes to the same AF_ALG socket, which could crash the system or corrupt cryptographic operation results. Red Hat updated its advisories for all three on 19 September at 02:00 UTC to acknowledge active exploitation, describing them as high risk with known public exploits and urging high-priority remediation. Under BOD 26-04, federal civilian executive branch agencies are directed to apply fixes by 21 September 2026. There is no public detail yet on how the flaws are being exploited, or whether they are chained. Separately, researcher Asim Manizada disclosed four local privilege escalation flaws — CVE-2026-80844 ("DirtyAH6"), CVE-2026-81000 ("TUNderflow"), CVE-2026-68121 ("PPPoEject") and CVE-2026-74469 ("DiagSpill") — adding to a fortnight in which kernel privilege escalation has been the most crowded corner of the disclosure queue.
| Attribute | Detail |
|---|---|
| **Sector | Government |
| **Date | 2026-09-20 |
| **Source | The Hacker News |
| **Reliability | Tier 2 |
| **CVEs | CVE-2025-39682, CVE-2025-39964, CVE-2026-53266, CVE-2026-68121, CVE-2026-74469, CVE-2026-80844, CVE-2026-81000 |