CISA added CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 to its Known Exploited Vulnerabilities (KEV) Catalog after evidence of active exploitation. The vulnerabilities affect the Linux kernel TLS receive path, ebtables SNAT ARP rewrite handling, and AF_ALG sockets, respectively. CVE-2025-39682 can cause TLS records to be handled using incorrect zero-copy and queueing assumptions; CVE-2026-53266 is an ebtables SNAT out-of-bounds write; and CVE-2025-39964 is an AF_ALG race condition that can interleave data and leave socket state inconsistent.
CISA said the flaws can create denial-of-service, memory-disclosure, data-integrity, or local privilege-escalation risk, although public details on the observed attacks and whether the vulnerabilities were chained have not been released. Federal civilian executive branch agencies must apply vendor mitigations by September 21, 2026, conduct required forensic triage, and follow BOD 26-04 risk-based update guidance; Red Hat has also updated advisories to recognize active exploitation and prioritize remediation. Ransomware use is currently listed as unknown for all three vulnerabilities.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
Red Hat updated its advisories for CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 to acknowledge active exploitation. It characterized the flaws as high risk, noted public exploits were known, and urged prioritized remediation.
CISA added CVE-2025-39682 to its KEV Catalog based on evidence of active exploitation. The Linux kernel TLS receive-path flaw allows a zero-length record to bypass intended recvmsg() record-type handling, potentially causing later records to be processed with incorrect zero-copy and queueing assumptions.
CISA released KEV Catalog version 2026.09.18, adding CVE-2025-39964, an AF_ALG socket race condition, and CVE-2026-53266, an ebtables SNAT out-of-bounds write. CISA cited active exploitation, required forensic triage, and directed affected organizations to apply vendor mitigations under BOD 26-04.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.