CISA Adds Linux Kernel CVE-2026-53266 to Known Exploited Vulnerabilities Catalog
On 18 September 2026 CISA added CVE-2026-53266, a Linux kernel out-of-bounds write, to its Known Exploited Vulnerabilities catalog, along with CVE-2025-39964, a kernel race condition. Binding Operational Directive 26-04 requires rapid remediation on publicly exposed assets and a check for prior compromise.
- CISA listed CVE-2026-53266 and CVE-2025-39964 in KEV on 18 September 2026
- CVE-2026-53266 is a Linux kernel out-of-bounds write with evidence of exploitation
- Directive 26-04 mandates out-of-band patching for publicly exposed systems
- Kernel patches only take effect after a reboot, a common silent failure point
Read next
Security