WORLDTECH NEWS Global technology intelligence.
โ† Back to WORLDTECH
Cybersecurity

CISA Adds Two Known Exploited Vulnerabilities to Catalog

Requested translation is not available. Showing the stored EN version.

WORLDTECH illustration for the Cybersecurity story "CISA Adds Two Known Exploited Vulnerabilities to Catalog": abstract concentric protective hexagonal rings. Not a photograph of the event.
WORLDTECH illustration

What happened

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-39964 Linux Kernel Race Condition Vulnerability CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.

BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.

Sources & evidence