CISA added two actively exploited Linux kernel flaws on Thursday
Key takeaways
- CISA added CVE-2025-39682 and CVE-2026-53266, both Linux kernel flaws, to its Known Exploited Vulnerabilities catalogue on 18 September, citing evidence of exploitation in the wild.
- Check Point Security Management and Log Servers were confirmed affected by a critical flaw allowing remote code execution with root privileges.
- CISA has moved to remediation deadlines that scale with risk level, so the old fixed 21 day window no longer applies to everything.
Two Linux kernel bugs moved from theoretical to confirmed this week. CISA added CVE-2025-39682, an improper check for unusual or exceptional conditions, and CVE-2026-53266, an out-of-bounds write, to its Known Exploited Vulnerabilities catalogue on 18 September. The catalogue only accepts entries with evidence of active exploitation in the wild, so both are being used against real targets now.
Kernel flaws are the ones that matter most in a patch queue because the blast radius is the whole machine. An out-of-bounds write in kernel space is a privilege escalation waiting for a delivery mechanism, and anything running Linux at any scale is in scope, which in practice means almost everything.
The rest of this week's queue
The kernel entries were not the only additions to the list. Check Point Security Management and Log Servers were confirmed affected by a critical vulnerability allowing remote code execution with root privileges, which is an unpleasant place to find a bug given what those servers hold. CVE-2026-58138 was disclosed separately as an unauthenticated remote code execution flaw exploitable through inline workflow definitions.
Microsoft's own round of fixes across Azure and its AI-branded products was dominated by privilege escalation rather than remote execution. That is the quieter category and the one most likely to sit unpatched, because escalation bugs read as less urgent right up until they are chained with something else.
The structural change underneath
The more consequential item this week is not any single CVE. CISA has moved to vulnerability remediation deadlines that scale with risk level rather than applying one fixed window to everything.
If your internal policy assumes a standard 21 day clock on every KEV entry, that assumption no longer holds. Some items will now carry a shorter deadline than you have planned for, which matters for anyone with a change control process that takes longer than the deadline itself.
This is the second time in recent months that a CISA deadline has landed faster than the usual patching rhythm, and it follows a run of critical remote execution flaws in management infrastructure, from Cisco ISE to N-able N-central. The pattern is consistent: attackers keep going after the tools that administer everything else.
What to do
Patch the two kernel CVEs first. They have confirmed exploitation and the widest exposure.
Then check your Check Point management estate, because a root-level remote execution flaw on a log server is a route to both the network and the evidence of what happened on it.
Then, separately from any of this week's patching, go and read your own remediation SLA and confirm it matches the new tiered deadlines rather than the old fixed one. That is the item nobody will chase you about until the audit.