CISA added three Linux kernel vulnerabilities to the Known Exploited Vulnerabilities catalog on September 18, 2026: CVE-2025-39682 in the kernel TLS receive path (CVSS 9.8), CVE-2026-53266 in the netfilter bridge SNAT target (8.8), and CVE-2025-39964 in the af_alg crypto socket interface (7.8). Each has an upstream fix already.
CISA lists on evidence of exploitation, so this is not a batch of theoretical findings being cleared out — it is three defects in three unrelated kernel subsystems, all of which had exploitation evidence behind them by the same date.
The three flaws, highest severity first
CVE-2025-39682 — kernel TLS receive path (CVSS 9.8)
The kernel’s TLS implementation requires each recvmsg() call to process either a run of contiguous data records or a single non-data record. When the record type changes mid-processing, the pending record is queued to the rx_list for the next call to pick up. That queueing is incompatible with zero-copy decryption, where the plaintext has already been written directly into the user-space buffer and there is no socket buffer left to queue.
Per the upstream fix, the missed case is a zero-length record arriving from the rx_list as the initial record. NVD classifies it under CWE-754, improper check for unusual or exceptional conditions — agreed by CISA KEV — and scores it CVSS 3.1 base 9.8 with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
One caveat on that score, stated as our assessment rather than as sourced fact: the AV:N / PR:N combination assumes the affected socket is using kernel TLS in the first place. That is a real and growing configuration — kTLS backs offloaded TLS termination and some high-throughput networking stacks — but it is not the default posture of an arbitrary Linux host, and CVSS does not encode that precondition.
CVE-2026-53266 — netfilter bridge SNAT ARP rewrite (CVSS 8.8)
The ebtables SNAT target’s optional ARP sender-hardware-address rewrite writes through skb_store_bits() at an offset relative to skb->data. A safe read of the ARP header, which is what the code performed, does not by itself guarantee that the sender-hardware-address bytes can be written to. Where that range was still held in a nonlinear socket-buffer fragment backed by a spliced-in file page, the write landed in that mapped page. The fix ensures the range is writable before the header is read and before the store.
NVD, CISA KEV and VulnCheck KEV all classify it under CWE-787, out-of-bounds write. NVD scores it CVSS 3.1 base 8.8, vector AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H — local, low privileges required, with a scope change. The scope change is what carries a local flaw to 8.8; an out-of-bounds kernel write does not stay inside the subsystem that performed it.
This is the only one of the three that both KEV catalogs list, and VulnCheck additionally records its exploit availability as active.
CVE-2025-39964 — af_alg concurrent writes (CVSS 7.8)
af_alg exposes the kernel crypto API to user space through a socket interface. Issuing two concurrent writes to the same socket interleaved the data unpredictably and could leave the internal socket state inconsistent. The upstream fix adds an exclusive write-ownership flag to the context so concurrent writers are rejected rather than raced.
NVD classifies it under CWE-362, race condition, and scores it CVSS 3.1 base 7.8, vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H — local, authenticated at low privilege, full impact within scope. It is the classic local privilege escalation shape: a user-space-reachable kernel interface whose state machine assumed serialisation it never enforced.
What the evidence actually supports
| Claim | Value | Sources agreeing | Confidence |
|---|---|---|---|
| Exploitation, all three | KEV-listed 2026-09-18 | CISA KEV (53266: + VulnCheck) | High |
| Weakness classes | CWE-754 / CWE-787 / CWE-362 | NVD and CISA KEV agree on each | High |
| Vendor and product | Linux (product string varies) | CISA KEV, cve.org (53266: + VC) | High |
| CVSS scores and vectors | 9.8 / 8.8 / 7.8 | NVD only | Medium |
| Root-cause descriptions | as summarised above | NVD and cve.org agree on each | High |
| EPSS | 0.00505 / 0.00121 / 0.00323 | FIRST EPSS | Medium |
Exploitation confidence is high on the strength of the CISA listing, which this publication treats as authoritative for exploitation status. Everything about how they are being exploited is absent — see the gaps section.
Why this matters
Every EPSS score here is below 0.6%. CVE-2026-53266 sits at the 2nd percentile — effectively the bottom of the distribution — and CISA lists it as exploited anyway.
Read that as a statement about coverage rather than a contradiction. EPSS is trained on observable signal, heavily weighted toward internet-facing scan telemetry and public disclosure activity. Two of these three flaws are local: they are reached after an attacker already has code execution on the host, as the second stage of a chain that begins somewhere else entirely. That activity produces almost nothing EPSS can see. Our assessment: for kernel local-privilege-escalation CVEs specifically, a low EPSS score carries close to no prioritisation information, and a KEV listing should override it without argument.
The practical consequence for patch scheduling is that these three should not be triaged the way their individual scores suggest. A 7.8 local race condition looks deferrable next to an internet-facing critical. But a kernel LPE is what converts a contained web-application compromise into host-level control, and CISA’s listing records that conversion being performed in the wild. Binding Operational Directive 26-04 obligations apply to all three, since all three carry a CISA KEV listing.
The remediation is at least uniform in kind. Each of the three has an upstream fix, and none has a per-CVE mitigation to evaluate or a configuration change that substitutes — in practice the answer is a current distribution kernel package plus a reboot. What operators should not assume is that any single update closes all three: backport cadence varies by distribution, and these CVEs were published across three different dates in 2025 and 2026. Confirm your vendor’s advisory covers all three CVE IDs rather than inferring it from one kernel version bump.
This continues a week in which CISA’s KEV additions concentrated on infrastructure rather than applications: CVE-2026-76460, the CVSS 10.0 Cisco Identity Services Engine authentication bypass listed on September 16, was the same kind of target — a component that everything else trusts, rather than an endpoint that merely holds data.
What we don’t have
- No exploitation detail whatsoever. CISA’s catalog entries state that these are exploited and nothing more: no actor, no campaign, no observed technique, no volume. We are reporting a confirmed fact with no context attached, and we will not invent the context.
- No affected kernel version ranges. Our ingested data carries none. For CVE-2025-39682 the reference list carries stable-tree commit hashes, which operators must map to their distribution’s kernel package rather than to an upstream release number; for the other two our data records the fix description without an equivalent version marker.
- CVSS is single-sourced. All three scores come from NVD alone. This matters more than usual for kernel CVEs, where automated scoring of a subsystem fix frequently produces a maximal vector that the flaw’s real preconditions do not support — the
AV:N/PR:Non CVE-2025-39682 is a candidate. At least one third-party summary of that CVE characterises it as a denial-of-service issue rather than a full confidentiality-integrity-availability compromise. We report NVD’s figures as published and flag the disagreement rather than silently adopting either reading. - No CWE→ATT&CK mapping with a real basis in our data for any of the three, so none is asserted.
Frequently Asked Questions
Which Linux kernel CVEs did CISA add to KEV on September 18, 2026? Three: CVE-2025-39682, an improper-check flaw (CWE-754) in the kernel TLS receive path scored CVSS 9.8; CVE-2026-53266, an out-of-bounds write (CWE-787) in the netfilter bridge SNAT target scored 8.8; and CVE-2025-39964, a race condition (CWE-362) in the af_alg crypto socket interface scored 7.8.
How do I fix all three? Apply your distribution’s current kernel update and reboot. Each of the three has an upstream fix and none has a per-CVE configuration mitigation, so a kernel package update is the remediation path — but confirm against your distribution’s own advisory that its update covers all three CVE IDs, since backport cadence varies by vendor.
Are these Linux kernel flaws remotely exploitable?
Only CVE-2025-39682 carries a network attack vector (AV:N) in NVD’s scoring, and that assumes the socket in question is using kernel TLS. CVE-2026-53266 and CVE-2025-39964 are both scored AV:L — local access is required, which in practice means they are privilege-escalation steps used after an initial compromise.
Why are the EPSS scores so low if CISA says they are exploited? EPSS forecasts exploitation from observable signal such as internet-wide scanning telemetry and public disclosure activity. Local kernel privilege-escalation flaws used inside post-compromise chains generate very little of that signal, so EPSS systematically under-rates them. A KEV listing is an observation of exploitation; an EPSS score is a forecast, and the observation wins.
Does BOD 26-04 apply to these three CVEs? Yes. All three are on CISA’s KEV catalog as of September 18, 2026, which is what triggers Binding Operational Directive 26-04 remediation obligations for federal civilian agencies.
Data sourced from the National Vulnerability Database (NVD), the CISA Known Exploited Vulnerabilities Catalog, VulnCheck KEV, FIRST EPSS and cve.org, aggregated September 19, 2026. See more vulnerability intelligence.