Three KEV-listed Linux kernel CVEs (CVE-2025-39964, CVE-2026-53266, CVE-2025-39682)

Incident Report for CloudLinux

Identified

On September 18, 2026, the US Cybersecurity and Infrastructure Security Agency (CISA) added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalogue: CVE-2025-39964 (a crypto-socket flaw), CVE-2026-53266 (a bridge-firewall flaw), and CVE-2025-39682 (a kernel-TLS flaw). They are three separate bugs in different parts of the kernel. Fixing one has nothing to do with the others.

Which versions each one affects is in the affected table. In short: the crypto flaw affects every CloudLinux version; the bridge flaw affects every version but is reachable by an ordinary account only on some; the TLS flaw affects only CloudLinux 8 LTS, 9, 9 LTS, and 10.

The three flaws:
CVE-2025-39964, the crypto-socket flaw: a public exploit escalates an ordinary account to root. → details
CVE-2026-53266, the bridge-firewall flaw: memory corruption or privilege escalation, reachable by an ordinary account only where private network spaces are open. → details
CVE-2025-39682, the kernel-TLS flaw: can leak kernel memory or crash the machine on affected systems. → details

Two fix routes: a KernelCare livepatch applies with no reboot where one is available; otherwise the fix is a kernel update and reboot. The fix-status table gives both routes per version, and the update instructions carry the streams.

Check whether a server is patched → How to verify

How the bugs work → Technical details
Posted Oct 07, 2026 - 12:48 UTC