CISA added CVE-2025-39964 (Linux kernel race condition) and CVE-2026-53266 (Linux kernel out-of-bounds write) to its Known Exploited Vulnerabilities catalog on 18 September, both on evidence of active exploitation, alongside the earlier additions this week of CVE-2026-58704 (Google Pixel), CVE-2026-76460 (Cisco Identity Services Engine) and CVE-2026-87886 (Acronis Backup). The KEV alert explicitly ties the catalog to BOD 26-04, the binding directive that requires federal civilian agencies to prioritise KEV-listed flaws on publicly exposed assets that grant total control post-exploitation, and to check for prior compromise before patching. Separately, CISA confirmed it will discontinue its weekly vulnerability bulletins effective 28 September, describing the move as consistent with its shift from severity-based to risk-based vulnerability management — a doctrine being stress-tested by disclosure volume, with Microsoft's most recent monthly release approaching 1,000 CVEs as AI-assisted discovery accelerates.
| Attribute | Detail |
|---|---|
| Sector | Government |
| Date | 2026-09-19 |
| Source | CISA |
| Reliability | Tier 1 |
| CVEs | CVE-2025-39964, CVE-2026-53266, CVE-2026-58704, CVE-2026-76460, CVE-2026-87886 |