[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fAQ9gzyvrgcGx_uQuD-KfGT0R0-cIl4lcp_zaUyFC3SY":3},{"article":4,"iocs":54},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":31,"category":32,"article_tags":36},"a2c8d141-bc05-48cd-a5cc-459e37ad17b2","CISA BOD 26-04 Timelines for Three Linux Kernel CVEs","cisa-bod-26-04-timelines-for-three-linux-kernel-cves-0be39c","Executive Summary CISA added three actively exploited Linux kernel vulnerabilities: CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 to its KEV Catalog on September 18, 2026, triggering a 3-day remediation deadline that passed on September 21. Under CISA BOD 26-04, a 3-day window applies to CVE-2025-39682 across all assets, and for the other two, the deadline is 3 days […]","CISA has added three actively exploited Linux kernel vulnerabilities (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964) to its Known Exploited Vulnerabilities (KEV) Catalog. These vulnerabilities, affecting the core Linux kernel, have passed their remediation deadlines under CISA BOD 26-04, requiring immediate patching of affected systems. The vulnerabilities include a TLS zero-length record flaw, a Netfilter ebtables SNAT vulnerability, and an AF_ALG socket race condition, all of which are being actively exploited in the wild.","CISA adds three actively exploited Linux kernel CVEs to KEV catalog, with remediation deadlines passed.","Table of ContentsThe Three Linux Kernel CVEs in KEVCISA BOD 26-04 Remediation TimelineWhy This MattersOur Recommendation: Deploy the Kernel Updates with Qualys TruRisk Eliminate Executive Summary CISA added three actively exploited Linux kernel vulnerabilities: CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 to its KEV Catalog on September 18, 2026, triggering a 3-day remediation deadline that passed on September 21. Under CISA BOD 26-04, a 3-day window applies to CVE-2025-39682 across all assets, and for the other two, the deadline is 3 days for publicly exposed assets and 14 days for internal assets. With the September 21 deadline now passed, affected systems should be patched immediately. Qualys TruRisk Eliminate identifies affected assets with vulnerability context and provides High-Reliability Patches to support remediation and verification. The Three Linux Kernel CVEs in KEV Red Hat has updated its advisories for all three to acknowledge active exploitation and reports that public exploits are known. Observed exposure across organizations shows these vulnerabilities can affect a substantial number of systems, including internet-facing assets, making timely remediation essential. CVE-2025-39682 | Linux Kernel TLS Zero-Length Record Vulnerability A flaw in how the kernel’s TLS receive path handles zero-length records. After zero-copy decryption, a crafted zero-length record can break the logic that assumes the record type cannot change, resulting in memory disclosure or a denial of service. It carries the highest severity of the three. CVE-2026-53266 | Linux Kernel Netfilter ebtables SNAT Vulnerability An out-of-bounds write in the bridge Netfilter ebtables SNAT target. A crafted packet with an ARP payload can make the kernel write outside the intended packet buffer, corrupting memory. Depending on the conditions, this can lead to denial-of-service or local privilege escalation. CVE-2025-39964 | Linux Kernel AF_ALG Socket Race Condition A race condition in the AF_ALG socket interface. Two writes to the same socket can interleave unpredictably, leaving the socket in an inconsistent state and causing a system crash or corrupted cryptographic results. Average number of affected assets observed across organizations CISA BOD 26-04 Remediation Timeline Under CISA BOD 26-04, the remediation window is either 3 or 14 days, depending on the CVE classification and whether the affected asset is publicly exposed. For assets subject to the 3-day requirement, the September 21 deadline has passed. Therefore, these assets should be prioritized for patching to ensure compliance with the required remediation timeline. Qualys TruRisk Eliminate™ offers the necessary visibility needed to identify addressable exposure and move these systems toward remediation. BOD 26-04 remediation deadlines by CVE classification Why This Matters A KEV (Known Exploited Vulnerability) listing indicates that exploitation has been confirmed, rather than being merely theoretical. CISA also marked all three flaws as requiring forensic triage. These vulnerabilities exist in the Linux kernel, the core component of the host system. This means that successful exploitation could potentially affect the entire system rather than just a single application. Therefore, kernel-level vulnerabilities demand immediate attention and remediation to prevent any compromise from penetrating deeper into the host. Our Recommendation: Deploy the Kernel Updates with Qualys TruRisk Eliminate It’s important to patch immediately, starting with exposed assets. TruRisk Eliminate assists teams in moving from identifying vulnerable Linux assets to selecting the appropriate patches for remediation. For kernel vulnerabilities, it highlights the available High-Reliability Patches, giving teams greater confidence to accelerate remediation while reducing concerns about patch-related disruption. Teams can then deploy the chosen kernel updates, perform the necessary reboot, and verify the remediation status to confirm that the vulnerabilities have been successfully addressed. See which of your Linux assets are still exposed. Start a free trial of Qualys TruRisk Eliminate. Start Free Trial Related","https:\u002F\u002Fblog.qualys.com\u002Fproduct-tech\u002F2026\u002F09\u002F23\u002Fcisa-bod-26-04-timelines-for-three-linux-kernel-cves","https:\u002F\u002Fik.imagekit.io\u002Fqualys\u002Fwp-content\u002Fuploads\u002F2026\u002F09\u002FBlog-Images-1080x1080.Cloud_.Agent_.2025.Updates-5-5.png","2026-09-23T15:00:00+00:00","2026-09-23T20:00:08.373276+00:00",9,[18,21,24,27,29],{"name":19,"type":20},"Linux Kernel","product",{"name":22,"type":23},"CISA","vendor",{"name":25,"type":26},"TLS","technology",{"name":28,"type":26},"Netfilter",{"name":30,"type":26},"AF_ALG","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":31,"icon":33,"name":34,"slug":35},null,"Vulnerabilities","vulnerabilities",[37,42,47,49],{"category":38},{"id":39,"icon":33,"name":40,"slug":41},"217d3263-c763-41ca-875e-06901f522fe0","NIST","nist",{"category":43},{"id":44,"icon":33,"name":45,"slug":46},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":48},{"id":31,"icon":33,"name":34,"slug":35},{"category":50},{"id":51,"icon":33,"name":52,"slug":53},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[55,59,62],{"type":56,"value":57,"context":58},"cve","CVE-2025-39682","Linux Kernel TLS Zero-Length Record Vulnerability, actively exploited",{"type":56,"value":60,"context":61},"CVE-2026-53266","Linux Kernel Netfilter ebtables SNAT Vulnerability, actively exploited",{"type":56,"value":63,"context":64},"CVE-2025-39964","Linux Kernel AF_ALG Socket Race Condition, actively exploited"]