← All briefs
Brief·3 sources19 Sept 2026

CVE-2025-39682 Added To CISA KEV Catalog Following Active Exploitation

zero-day-exploitvulnerability-disclosurepatch-managementcritical-infrastructurecloud-security

Summary

CVE-2025-39682, a CVSS 9.8-rated flaw in the Linux kernel TLS receive path, has been added to CISA's Known Exploited Vulnerabilities (KEV) catalogue following confirmed evidence of active exploitation in the wild. The vulnerability arises from an improper check for unusual or exceptional conditions in the kernel's TLS processing logic, a class of flaw that has historically enabled privilege escalation and remote code execution in susceptible environments.

CISA's addition to the KEV catalogue on 18 September 2026 triggers mandatory remediation timelines for Federal Civilian Executive Branch (FCEB) agencies under Binding Operational Directive (BOD) 26-04. CISA explicitly characterised this vulnerability type as a frequent attack vector for malicious cyber actors, citing significant risk to the federal enterprise. The urgency of federal guidance signals that exploitation is unlikely to remain confined to government-adjacent targets.

Timeline

  1. 19 September 2026
    CISA Flags CVE-2025-39682 Alongside Two Further Linux Kernel Flaws
    Security reporting confirmed CISA's action, noting CVE-2025-39682 as part of a broader advisory covering three Linux kernel vulnerabilities observed being exploited in the wild.
  2. 18 September 2026
    CISA Adds CVE-2025-39682 to Known Exploited Vulnerabilities Catalogue
    CISA formally added CVE-2025-39682 to its KEV catalogue, citing evidence of active exploitation. Federal agencies were placed under mandatory remediation timelines per BOD 26-04.

Want the full picture?

Each brief contains detailed narrative, impact assessments, technical analysis, IOCs and response recommendations, all available inside the Deltabridge platform.

CVE-2025-39682 Added To CISA KEV Catalog Following Active Exploitation | Deltabridge