Skip to content

cve

2 posts with the tag “cve”

Three Linux Kernel Flaws Are Being Exploited Now — Patch by Monday

Three Linux Kernel Flaws Are Being Exploited Now — Patch by Monday

Section titled “Three Linux Kernel Flaws Are Being Exploited Now — Patch by Monday”

CISA added three Linux kernel flaws to its Known Exploited Vulnerabilities catalog on September 18, 2026 (CISA KEV, 2026). All three are under active exploitation (The Hacker News, 2026). Federal civilian agencies must remediate by September 21 under Binding Operational Directive 26-04 (TechTimes, 2026). The deadline applies to the whole industry in practice. These are kernel bugs with public exploits, and they sit under nearly every Linux workload you run.

CVECVSSSubsystemWhat it does
CVE-2025-396829.8kTLS receive pathZero-length record bypasses record-type handling, corrupting TLS processing (CyberSecurityNews, 2026)
CVE-2026-532668.8ebtables SNATOut-of-bounds write in packet filtering, local privilege escalation (SecurityOnline, 2026)
CVE-2025-399647.8AF_ALGRace condition corrupts crypto results or crashes the system (CyberSecurityNews, 2026)

Red Hat updated its advisories for all three on September 19, 2026 and acknowledged active exploitation. It rated them high risk with known public exploits and told customers to patch with high priority (The Hacker News, 2026; Red Hat, 2026).

CVE-2025-39682 is a critical improper-condition check in the kernel’s software TLS receive path (CyberSecurityNews, 2026). Software TLS lives in net/tls/tls_sw.c. An application enables it by setting TCP_ULP to "tls" on a TCP socket (TechTimes, 2026).

The flaw is a corner case. A zero-length record pulled from the receive list bypasses the normal record-type handling in recvmsg(). Later TLS records then get processed with wrong zero-copy and queueing assumptions (CyberSecurityNews, 2026).

The exposure window is wide. A public proof-of-concept has circulated since September 2025, so vulnerable hosts may have faced exploitation attempts for up to a year before the KEV addition (TechTimes, 2026). Affected versions span Linux 6.0 through 6.16.3, plus release candidates 6.17-rc1 and 6.17-rc2 (TechTimes, 2026).

The fix is a code change in tls_sw_recvmsg() that handles the zero-length record case. There is no configuration-only workaround. Disabling kTLS entirely is the only mitigation short of patching (TechTimes, 2026).

CVE-2026-53266: out-of-bounds write in ebtables

Section titled “CVE-2026-53266: out-of-bounds write in ebtables”

CVE-2026-53266 is a high-severity out-of-bounds write in the netfilter bridge ebtables SNAT target (CyberSecurityNews, 2026). It lets a local attacker escalate to root (SecurityOnline, 2026).

The bug sits in the Address Resolution Protocol rewrite path. During an optional sender hardware-address rewrite, the kernel can call skb_store_bits() without confirming the destination range is writable. If the data lives in a nonlinear socket-buffer fragment backed by a splice-imported file page, the write lands directly in the underlying page (CyberSecurityNews, 2026).

The upstream fix adds skb_ensure_writable() to the ebt_snat path, forcing the buffer to be writable before the copy (TechTimes, 2026).

CVE-2025-39964 is a race condition in AF_ALG, the kernel interface that exposes cryptographic operations to userspace through socket file descriptors (TechTimes, 2026). The data path allowed two concurrent writers on the same socket. Request payloads from separate threads interleave unpredictably inside the kernel’s crypto processing queue, leaving the per-socket context inconsistent (SecurityOnline, 2026). The result is corrupted cryptographic output or a denial of service (CyberSecurityNews, 2026).

The fix adds exclusive write ownership. Only one writer may call sendmsg() on the socket at a time (CyberSecurityNews, 2026).

Watch the scope, not just the score. The flaw carries a CVSS of 7.8, but it affects kernels from 2.6.38 through 6.16.9 and 6.17-rc6. That is a much older and broader exposure surface than the score suggests (TechTimes, 2026).

All three fixes require a kernel update followed by a system reboot. None of them has a configuration-only fix (TechTimes, 2026). Plan the reboot window now, because the calendar is short.

BOD 26-04 adds a step the old directive never required. Agencies must determine whether a system was already compromised before the patch arrived. Forensic triage is now part of the remediation, not an afterthought (TechTimes, 2026).

CISA has not published how the three flaws are being exploited in the wild, or whether they form a single attack chain (The Hacker News, 2026). Treat that gap as a reason to move faster, not slower.

  1. Inventory kernel versions. Run uname -r on every fleet, then compare against the affected ranges for each CVE (TechTimes, 2026). Legacy distro kernels are the most likely to miss the fixes.
  2. Apply vendor updates. CISA directs affected organizations to apply vendor mitigations under BOD 26-04 (CyberSecurityNews, 2026). Red Hat, Canonical, SUSE, and Debian each shipped or are shipping kernel errata.
  3. Reboot after the update. No fix takes effect without a reboot. Schedule rolling reboots so no workload stays on a vulnerable kernel past September 21 (TechTimes, 2026).
  4. Prioritize kTLS hosts. CVE-2025-39682 is the critical one, and its proof-of-concept is a year old. Multi-tenant hosts and anything that terminates TLS in-kernel get patched first (TechTimes, 2026).
  5. Run forensic triage on exposed hosts. Even patched hosts that were previously exposed may have been compromised before the fix. Review kernel logs and check for persistence before you call the ticket closed (TechTimes, 2026).

The KEV catalog is a list of bugs that attackers already use. Three of those bugs are in the Linux kernel, one of them is a year old, and the federal deadline is tomorrow (CISA KEV, 2026; TechTimes, 2026). Kernel patching is rarely urgent, and that is exactly why this batch matters. Inventory, update, reboot, and triage this weekend, not next sprint.

Cisco FMC CVSS 10.0 bypass is exploited in the wild: Sandworm and ransomware crews are in

Cisco FMC CVSS 10.0 bypass is exploited: take the management plane off the internet

Section titled “Cisco FMC CVSS 10.0 bypass is exploited: take the management plane off the internet”

The device that configures every firewall on your network is itself compromised. On September 9, Cisco Talos said three threat crews are actively exploiting CVE-2026-20079, a CVSS 10.0 authentication bypass in Cisco Secure Firewall Management Center (FMC) (Cisco Talos). The crews run a web shell, a Java command executor, Sandworm’s Cyclops Blink, and Qilin ransomware through the same console (BleepingComputer). This is not a theory. This is the management plane of your firewall fleet, hit where it cannot defend itself.

CVE-2026-20079 lets an unauthenticated remote attacker bypass login controls entirely (Cisco Talos). The flaw starts in a system process created when the FMC boots. If no legitimate user claims the resulting session, an attacker can hijack it and walk in as that user (Cyber Security News).

Cisco disclosed the flaw on March 4, 2026 (SOCRadar). Cisco released fixes on July 29, 2026 for customer-managed FMC (BleepingComputer). Security teams have had weeks to patch. Cisco said in August its team became aware of active exploitation, while indicators in a July advisory point to activity on July 23 (BleepingComputer).

The second bug, CVE-2026-20316, is a static credential issue with a CVSS score of 5.3. Alone it offers limited access. Chained with the bypass, it helps an attacker climb to full control (Cyber Security News). CISA added it to the Known Exploited Vulnerabilities catalog in late July 2026 (The Hacker News).

Talos tracks three attack clusters in the same management plane (Cisco Talos).

  1. UAT-12197: web shell plus credential theft. They plant a JSP web shell inside the FMC Tomcat webroot, then drop an executable archive command executor named cmd.jar (Cyber Security News). The chain sips authentication data and credentials from the compromised box.

  2. UAT-11823: Sandworm (GRU Unit 74455). The Russian state group swaps the license file for a malicious copy, then executes it as root through the legitimate package_info.pl utility. The file is actually a Makeself package that sets up a Netcat-based reverse shell to its command-and-control server (Cisco Talos). It collects configuration data from every managed firewall into archives, then installs a modular Linux implant: Cyclops Blink, the family US and UK agencies previously tied to Sandworm (Cisco Talos). This variant persists through init directories, resolves its command server through DNS over HTTPS, and harvests credentials (Cisco Talos).

  3. UAT-11988: Qilin ransomware. A third crew logs in with the static credentials from CVE-2026-20316, maps the environment, steals more credentials, and builds the target list it will later encrypt (Cisco Talos). It then deploys the Qilin ransomware family across the fleet (The Hacker News).

One console controls every firewall rule, every VPN policy, every network access boundary on the fleet (SecurityWeek). Whoever sits in FMC does not break one firewall. They get to re-draw the whole network’s rule base.

FMC is the single place your firewall rules are pushed from. A compromise there does not just read secrets. It can modify the rules the whole perimeter enforces (Alvaka). An attacker can add their own rules, delete yours, or hand your wire directly to their callbacks.

FCEB agencies must patch known exploited FMC before September 12, 2026, per CISA’s KEV catalog (BleepingComputer). CVE-2026-20079 is the third FMC vulnerability CISA added to KEV in 2026, so this family of flaws keeps drawing attackers (SecurityWeek). No work-around fully covers the issue. The only fix is the patch (SOCRadar).

Cisco has hot fixes for every supported release branch, including 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0 (SOCRadar). Apply them. This is the only full fix.

1.Patch FMC this week. Apply the hotfix to every FMC instance, even isolated ones. The attacker does not care about your change window (Help Net Security). 2.Pull the management interface off the public internet. Restricting which networks can reach FMC materially reduces the chance of exploitation (SecurityWeek). FMC never needs to be a public endpoint. 3.Treat Friday’s date as the industry floor. Even if you are not federal, apply the KEV deadline to your own fleet (BleepingComputer). 4.Sweep for the artifacts. Look for a JSP web shell in the Tomcat webroot, a cmd.jar executable, a tampered license file, and a Netcat-based reverse shell spawned via the package utility (Cyber Security News). 5.Reset the admin credential chain. Assume sessions. Rotate FMC admin accounts, change static credentials, and check every identity provider that can log in to it (Cyber Security News). 6.Audit the managed config. Export every firewall policy and diff it against the last known-good baseline. A rule you did not write lives somewhere (Help Net Security).

A perfect 10.0 bug in your firewall control plane is being actively exploited by three crews today. Sandworm’s implant and Qilin ransomware both route through FMC. The fix has existed since July and the CISA deadline lands tomorrow. Patch the box, and take the management console itself off the internet (Cisco Talos).