Act
active
CISA Adds Three Linux Kernel CVEs to KEV; One Rated CVSS 9.8
- Engineer — Act: All three CVEs are CISA KEV-listed with confirmed active exploitation; CVE-2025-39682 carries CVSS 9.8 with a public GitHub PoC. Apply available Linux kernel patches immediately across all hosts, prioritizing internet-facing or TLS-terminating systems.
- SOC/IR — Act: Active exploitation is confirmed by CISA KEV for kernel-level flaws — assume-breach posture is warranted on Linux hosts. Run an EDR sweep for unusual kernel module loads, privilege escalations, or post-exploitation behavior on Linux systems since the date of first exploitation disclosure.
- Leader — Plan: Three actively exploited Linux kernel CVEs including a CVSS 9.8 flaw warrant confirming your team’s patch response this week; direct engineering to validate patch status across Linux infrastructure and report back before the next leadership sync.
- Signals: CVE-2025-39682 — CISA KEV: listed, EPSS 0.01, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.