[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fsWhQFWthDcZZMkvXi-vYc9lfgMM7qeuWGtlkUfaqJ9k":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":41},"7ff67d78-ab60-4e56-ad37-bfffd78305b4","three-actively-exploited-linux-kernel-cves-miss-cisa-remediation-deadlines","a2c8d141-bc05-48cd-a5cc-459e37ad17b2","Three Actively Exploited Linux Kernel CVEs Miss CISA Remediation Deadlines","Three critical Linux kernel vulnerabilities — covering TLS handling, Netfilter ebtables SNAT, and AF_ALG socket race conditions — are being actively exploited in the wild and have surpassed their mandatory remediation deadlines under CISA Binding Operational Directive (BOD) 26-04. The root cause is a failure in timely patch management, where organizations did not apply available fixes before active exploitation began. This matters because Linux underpins a vast portion of enterprise infrastructure, cloud environments, and critical systems, meaning unpatched kernels present a broad and severe attack surface. Delayed patching of known, catalogued vulnerabilities is particularly indefensible given that CISA's KEV Catalog provides explicit, actionable deadlines for remediation.","**Immediate Actions:**\n- Apply the latest Linux kernel patches immediately for all systems affected by CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964.\n- Cross-reference your asset inventory against CISA's KEV Catalog to identify any additional overdue remediations.\n- Isolate or restrict network access to unpatched Linux systems until patches can be applied.\n\n**Long-Term Improvements:**\n- Establish a formal, time-bound emergency patching process aligned with CISA BOD deadlines for all KEV-listed vulnerabilities.\n- Maintain a continuously updated and accurate asset inventory that tracks kernel versions across all Linux-based systems.\n- Implement automated patch compliance reporting to alert teams when remediation deadlines are approaching or breached.\n\n**Detection Measures:**\n- Deploy kernel-level monitoring and EDR tooling capable of detecting exploitation attempts targeting TLS, Netfilter, and socket-layer vulnerabilities.\n- Enable centralized logging of kernel events and anomalous socket or network filter activity for rapid threat detection.\n- Integrate threat intelligence feeds tied to the KEV Catalog into your SIEM to trigger alerts when newly catalogued CVEs affect your environment.",[12,13,14,15,16,17,18,19,20],"CIS Control 7: Continuous Vulnerability Management","CIS Control 2: Inventory and Control of Software Assets","NIST SP 800-40 Rev. 4: Guide to Enterprise Patch Management Planning","NIST SI-2: Flaw Remediation","NIST RA-5: Vulnerability Monitoring and Scanning","CISA BOD 26-04: Increasing Cybersecurity Resilience Through Known Exploited Vulnerabilities","CISA KEV Catalog","ITIL Change Management: Emergency Change Procedures","NIST CSF 2.0: RS.MI-3 (Vulnerabilities are mitigated or documented as accepted risks)","published","2026-09-23T21:21:09.472439+00:00","2026-09-23T21:21:09.2+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fblog.qualys.com\u002Fproduct-tech\u002F2026\u002F09\u002F23\u002Fcisa-bod-26-04-timelines-for-three-linux-kernel-cves","cisa-bod-26-04-timelines-for-three-linux-kernel-cves-0be39c","CISA BOD 26-04 Timelines for Three Linux Kernel CVEs",[29,35],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]