CuraSec

Act active

CISA Adds Three Linux Kernel CVEs to KEV; One Rated CVSS 9.8

2026-09-19 14:22 UTC · The Hacker News · read the source ↗ #linux-kernel#cisa-kev#active-exploitation
  • Engineer — Act: All three CVEs are CISA KEV-listed with confirmed active exploitation; CVE-2025-39682 carries CVSS 9.8 with a public GitHub PoC. Apply available Linux kernel patches immediately across all hosts, prioritizing internet-facing or TLS-terminating systems.
  • SOC/IR — Act: Active exploitation is confirmed by CISA KEV for kernel-level flaws — assume-breach posture is warranted on Linux hosts. Run an EDR sweep for unusual kernel module loads, privilege escalations, or post-exploitation behavior on Linux systems since the date of first exploitation disclosure.
  • Leader — Plan: Three actively exploited Linux kernel CVEs including a CVSS 9.8 flaw warrant confirming your team’s patch response this week; direct engineering to validate patch status across Linux infrastructure and report back before the next leadership sync.
  • Signals: CVE-2025-39682 — CISA KEV: listed, EPSS 0.01, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.