Linux users beware — CISA flags three major security issues you need to patch right now
Two flaws have available mitigations, too, but it's best to patch up.
The US Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux kernel flaws to its Known Exploited Vulnerabilities (KEV) catalog, signaling active exploitation and a three-day deadline for affected agencies to patch them or discontinue use. The three vulnerabilities—CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964—all have critical severity scores and have already been patched in the Linux kernel.
CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 can be exploited to launch memory disclosure attacks, privilege escalation, and data corruption, respectively. No specific cyberattacks have been reported, but CISA has expressed concern. Mitigations are available for two of the flaws, but none exist for the third.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.