[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fa4ayABMxt2mgU1-mYk87qpS6jgU432Pooq2-52apseo":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":41},"be53dd7e-89e7-4bc1-83e8-924937bccc21","active-linux-kernel-exploits-added-to-cisa-kev-catalog","3d77eea0-f9fa-4953-b018-d2327a0ec421","Active Linux Kernel Exploits Added to CISA KEV Catalog","CISA has added two actively exploited Linux kernel vulnerabilities (CVE-2025-39964 and CVE-2026-53266) to its Known Exploited Vulnerabilities Catalog, signaling confirmed exploitation in the wild. Federal agencies are legally bound under Binding Operational Directive (BOD) 26-04 to remediate KEV entries within prescribed timeframes, but the risk extends to all organizations running affected Linux systems. Linux kernel vulnerabilities are particularly dangerous due to their low-level access and widespread deployment across servers, cloud infrastructure, and embedded systems. Failure to act on KEV Catalog entries in a timely manner leaves organizations exposed to threats that adversaries are already leveraging in active campaigns.","**Immediate Actions:**\n- Apply vendor-supplied patches for CVE-2025-39964 and CVE-2026-53266 to all affected Linux systems immediately.\n- Cross-reference your asset inventory against the CISA KEV Catalog to identify all exposed systems within your environment.\n\n**Long-Term Improvements:**\n- Implement a risk-based vulnerability management program that prioritizes KEV Catalog entries and CVSS critical\u002Fhigh findings for accelerated remediation.\n- Maintain a continuously updated and accurate inventory of all Linux-based assets, including cloud instances and containerized workloads.\n- Establish formal SLA-driven patching policies aligned with BOD 26-04 timelines, even for non-federal organizations, as a security best practice.\n\n**Detection Measures:**\n- Deploy kernel-level intrusion detection or eBPF-based monitoring tools to detect anomalous kernel activity indicative of exploitation attempts.\n- Integrate CISA KEV Catalog feeds into your vulnerability scanner or SIEM to trigger automated alerts when newly cataloged CVEs affect your environment.",[12,13,14,15,16,17,18,19,20],"CIS Control 7: Continuous Vulnerability Management","CIS Control 2: Inventory and Control of Software Assets","NIST SP 800-40 Rev. 4: Guide to Enterprise Patch Management Planning","NIST SP 800-53 SI-2: Flaw Remediation","NIST SP 800-53 RA-5: Vulnerability Monitoring and Scanning","CISA Binding Operational Directive (BOD) 26-04","CISA Known Exploited Vulnerabilities (KEV) Catalog","ITIL 4: Change Enablement (emergency change procedures)","NIST CSF 2.0: Identify (ID.RA-1) – Asset vulnerability identification","published","2026-09-18T16:21:37.90611+00:00","2026-09-18T16:21:37.6+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Falerts\u002F2026\u002F09\u002F18\u002Fcisa-adds-two-known-exploited-vulnerabilities-catalog","cisa-adds-two-known-exploited-vulnerabilities-to-catalog-16075e","CISA Adds Two Known Exploited Vulnerabilities to Catalog",[29,35],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]