Critical

CISA Adds One Known Exploited Vulnerability to Catalog

All CISA Advisories
Actively Exploited

Overview

CISA has added a new vulnerability, identified as CVE-2025-39682, to its Known Exploited Vulnerabilities Catalog due to evidence of active exploitation. This vulnerability affects the Linux Kernel and involves improper checks for unusual or exceptional conditions, making it a target for attackers. It poses significant risks particularly to federal agencies, as outlined in the Binding Operational Directive (BOD) 26-04, which mandates that these agencies prioritize rapid remediation of high-risk vulnerabilities. While this directive specifically applies to Federal Civilian Executive Branch agencies, CISA encourages all organizations to adopt similar risk-based vulnerability management practices. Organizations aware of other exploited vulnerabilities that are not listed can submit them for consideration through CISA's nomination form.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Linux Kernel
  • Action Required: Federal agencies must prioritize rapid remediation of this vulnerability on publicly exposed assets.
  • Timeline: Newly disclosed

Original Article Summary

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-39682 Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.

Impact

Linux Kernel

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Federal agencies must prioritize rapid remediation of this vulnerability on publicly exposed assets. General remediation steps include applying security patches as they become available, checking for system compromises before patching, and adhering to guidelines provided by CISA.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Linux, CVE, Vulnerability, and 1 more.

Related Coverage

Early Scattered Spider member pleads guilty to cybercrime spree

CyberScoop

Ahmed Elbadawy, a member of the cybercrime group known as Scattered Spider, has pleaded guilty to participating in a series of cybercrimes that allowed him to amass significant wealth. Prosecutors have indicated they are pursuing the forfeiture of approximately $17.6 million in virtual currencies, along with luxury vehicles, jewelry, and designer bags linked to his illegal activities. This case exemplifies the ongoing challenges law enforcement faces in tackling organized cybercrime. The financial proceeds from such crimes not only enrich the perpetrators but also fund further illicit activities, making it crucial for authorities to act decisively against such networks. The resolution of this case could have implications for how similar crimes are prosecuted in the future.

Sep 18, 2026

MFA Won't Save You From OAuth Consent Abuse

darkreading

The article discusses the limitations of Multi-Factor Authentication (MFA) in protecting against OAuth consent abuse. While MFA adds an extra layer of security, it doesn't address the need for proper governance of OAuth protocols, which can lead to unauthorized access when users mistakenly grant permissions. Companies must implement least-privilege scopes and actively monitor consent to ensure that users are not giving away more access than necessary. Additionally, quick revocation of permissions is crucial in mitigating potential breaches. This issue is particularly relevant as OAuth is widely used across various applications, making proper management essential to safeguard user data.

Sep 18, 2026

Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root

The Hacker News

A security researcher has made public exploit code for four vulnerabilities in the Linux kernel that allow local users to gain root access, which is the highest level of control on a computer. These vulnerabilities have been patched in recent updates, meaning that systems with the latest kernel versions are not at risk. However, machines running older versions of the kernel could be vulnerable, putting them at potential risk of exploitation. Users and administrators are strongly advised to update their systems to the latest kernel version to prevent unauthorized access. The release of this exploit code increases the urgency for users to ensure their systems are secure, as it makes it easier for attackers to leverage these flaws if they remain unpatched.

Sep 18, 2026

Researchers use AI to find widespread software decoder flaw

CyberScoop

Researchers have identified a significant software decoder flaw that was able to grant attackers remote code execution privileges. This vulnerability, which has since been patched, put user accounts and production environments at risk, affecting major platforms like Meta's product suite and an OpenAI software repository. The ability for attackers to exploit this flaw raises serious concerns about the security of widely used software components. Organizations that rely on these products should ensure they have implemented the necessary patches to protect their systems. This incident serves as a reminder of the ongoing challenges in software security and the need for vigilant monitoring and updates.

Sep 18, 2026

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

The Hacker News

WordPress has patched several vulnerabilities in its core software, including a serious flaw that could let attackers install themes from the official WordPress.org directory without user consent. This vulnerability, dubbed Click2Shell by researchers at pwn.ai, specifically affects logged-in administrators who click on a specially crafted link. While the flaw requires user interaction to exploit, it poses significant risks as it could lead to unauthorized code execution on compromised sites. Website owners using WordPress should ensure they update their installations promptly to protect against potential exploitation. The discovery of this vulnerability emphasizes the ongoing need for vigilance in web application security.

Sep 18, 2026

Gyazo server flaw exploited to steal 23.6 million user records

BleepingComputer

Gyazo, a popular image-sharing platform, has confirmed a significant data breach due to a vulnerability in its server. Hackers exploited this flaw to access and steal approximately 23.6 million user records, which raises serious concerns about data privacy and security for those affected. The breach likely includes sensitive information that could be used for identity theft or other malicious purposes. This incident serves as a reminder for users to be vigilant about their online security and for companies to prioritize robust security measures. Gyazo has not yet released specific details on how they plan to address this vulnerability or secure their systems moving forward.

Sep 18, 2026