The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a high-priority alert warning that hackers are actively exploiting three critical vulnerabilities in the Linux kernel, with one of them having existed for 14 years. The affected flaws have been assigned severity ratings ranging from medium to critical, and federal agencies are being ordered to apply available security updates and mitigations by the end of today.
The three vulnerabilities, tracked as CVE-2025-39964, CVE-2026-53266, and CVE-2025-39682, were added separately last week to the list of known Linux kernel issues. They can potentially allow hackers to crash systems, alter cryptographic results, or even gain unauthorized access to sensitive data. One of the vulnerabilities, CVE-2025-39964, is a race condition in the kernel’s AF_ALG cryptographic socket interface that can lead to system crashes or corrupted encryption.
CISA has confirmed that these flaws have been exploited in real-world attacks, but has not provided any details about the nature of the threat actors or the scope of the incidents. However, researchers from Offensive security company STAR Labs and Red Hat have demonstrated the vulnerabilities’ potential impact by successfully exploiting them to gain privilege escalation and container escape.
The exploitation of CVE-2026-53266 has been confirmed by Red Hat, which also noted that public exploits are available for this vulnerability. Researcher Kimmo Suominen has published a technical analysis and patch-status tracker on GitHub, outlining a potential privilege-escalation path involving modifications to file-backed memory. However, the researcher notes that this exploitation chain is inferred by analogy with Dirty Pipe and has not been demonstrated with public exploit code.
CISA’s high-priority alert means that federal agencies must take immediate action to mitigate these vulnerabilities. This includes forensic triage of all affected assets to examine them for signs of potential exploitation. While none of the three flaws is currently linked to ransomware groups, it’s essential for organizations using Linux-based systems to review their security posture and apply available updates as soon as possible.
In practical terms, this means that system administrators should prioritize applying security updates and mitigations for these vulnerabilities as soon as they become available. This will help prevent exploitation and minimize the risk of system crashes or data breaches. Additionally, it’s crucial for organizations to regularly review their systems’ configuration and security settings to ensure they are up-to-date with the latest patches and best practices.
By taking proactive steps to address these critical vulnerabilities, organizations can significantly reduce the risk of cyberattacks and protect sensitive data from unauthorized access. It’s essential for system administrators and IT teams to stay vigilant and prioritize cybersecurity in today’s rapidly evolving threat landscape.
Source: Bleeping Computer — 2026-09-21