NewsTradingSentimentCalendarCommunityBriefing
Tech

CISA Lists Three Exploited Linux Kernel Flaws

By Tech Desk · 2026-09-19 · 2 min read
A complex, interlocking mechanical gear system with a small, glowing red warning light embedded in the center
Illustration: Tradingbird

The U.S. government has flagged three critical Linux kernel bugs as actively exploited, urging immediate fixes for federal systems.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three security flaws in the Linux kernel to its Known Exploited Vulnerabilities catalog. The agency confirmed that these issues are currently being used by attackers in the wild, marking a significant escalation in risk for systems running this foundational software.

According to reporting by The Hacker News, these vulnerabilities allow local attackers to crash systems, steal memory data, or escalate privileges. With no public details yet on specific attack methods, organizations are advised to treat these as urgent threats rather than routine updates, especially given the high severity scores assigned to each flaw.

Critical flaws target core system functions

The most severe issue, rated 9.8 out of 10, involves a failure in how the kernel handles secure network connections. This gap can let a local user access sensitive memory data or force the system to stop working. Two other bugs, rated 8.8 and 7.8, target network address translation and cryptographic operations. These can lead to system crashes or allow attackers to gain higher-level control over the machine.

Red Hat, a major provider of Linux-based technologies, has updated its security advisories to acknowledge the active exploitation. The company explicitly warned that public exploits exist and urged administrators to address these vulnerabilities with high priority. This guidance aligns with the broader recommendation from federal agencies to patch these systems immediately.

Federal agencies face strict patch deadlines

Under Binding Operational Directive 26-04, federal civilian agencies are required to apply fixes for these specific vulnerabilities by September 21, 2026. This directive prioritizes security updates based on risk, reflecting the government's concern that these flaws could be leveraged for broader cyber operations. Private sector organizations are also strongly encouraged to follow suit to avoid similar exposure.

Recent disclosures highlight ongoing kernel risks

This development follows recent disclosures of four additional local privilege escalation flaws in the Linux kernel. While the CISA-listed bugs are confirmed exploited, the newer issues remain under active investigation. The pattern of frequent, high-severity kernel bugs underscores the need for continuous monitoring and rapid response capabilities in any infrastructure relying on Linux.

Based on reporting by The Hacker News, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories