What is confirmed
Three KEV entries, three different exposure paths
CISA added CVE-2025-39964, CVE-2026-53266, and CVE-2025-39682 on 18 September 2026. Its catalog gives federal civilian agencies a 21 September due date and marks each entry for forensic triage. The catalog records ransomware use as unknown for all three.
KEV inclusion establishes that CISA has evidence of exploitation. It does not identify the attackers, affected organizations, or the method used in observed intrusions. CISA has not said these bugs were chained together. The three entries should be investigated as separate vulnerabilities.
Threat Field Notes assessment
Exposure
Check the feature and the package that is actually running
| CVE | Affected path | Exposure question |
|---|---|---|
| CVE-2025-39964 | AF_ALG cryptographic socket interface | Can a local user or workload write concurrently to the same AF_ALG socket on a vulnerable kernel? Red Hat describes a race that can disrupt socket state. |
| CVE-2026-53266 | Bridge netfilter ebtables SNAT | Are the relevant bridge rules rewriting ARP sender hardware addresses? Red Hat says this configuration is required for its identified attack path. |
| CVE-2025-39682 | Kernel TLS receive path | Is kernel TLS enabled and attached to the service’s TCP sockets? Ordinary HTTPS use alone does not establish exposure. |
Confirm affected package versions against the Linux distribution or appliance vendor’s advisory. Distributors may backport kernel fixes, so an upstream version number alone can give the wrong answer. A host that installed a fixed package may still be running its previous kernel until it reboots or receives an approved live patch.
Response
Patch, verify, then review the exposure window
- 1
Make a focused inventory. Record distribution, vendor advisory status, installed and running kernels, and whether AF_ALG, ebtables ARP rewriting, or kTLS is used. Include container hosts, shared systems, CI workers, and network appliances.
- 2
Prioritise vulnerable, reachable systems. Start with systems processing untrusted traffic or code and hosts where a local foothold could cross a container or tenant boundary. Use each flaw’s actual prerequisites to order the work.
- 3
Apply and verify vendor fixes. Install the supported kernel or appliance update. Reboot or use the vendor’s approved live-patching procedure, then confirm the running kernel and workload images are fixed.
- 4
Triage before the patch. Review relevant kernel crashes, unexpected privilege changes, container-to-host activity, changes to bridge rules or loaded modules, and gaps in host telemetry. Preserve evidence and escalate suspicious findings through the incident-response process.
If immediate patching is impossible, assess vendor-supported feature restrictions. Red Hat documents disabling AF_ALG or kTLS where those functions are unused, and removing the affected ARP-rewrite ebtables rules. Test operational impact and treat these controls as temporary until the kernel fix is verified.
Editorial note
How this analysis was prepared
This story was surfaced by The Cyber Security Hub newsletter. Threat Field Notes checked CISA’s catalog data and vendor descriptions, then wrote this independent defender response.