[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-cisa-gives-agencies-three-days-to-patch-three-linux-kernel-bugs":10,"sections":35},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":24,"tags":25,"sources":30,"feedback":34,"feedback_at":22,"cost_usd":34,"total_tokens":34},7174,"cisa-gives-agencies-three-days-to-patch-three-linux-kernel-bugs","CISA Gives Agencies Three Days to Patch Three Linux Kernel Bugs","Three actively exploited Linux kernel flaws now carry a rare three-day federal patch deadline, with one bug possibly exploitable remotely over TLS.","CISA just gave federal agencies three days, not the usual three weeks, to patch three Linux kernel bugs that are already being exploited.\n\nOn September 18, 2026, CISA added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2025-39682, a critical 9.8-severity flaw in the kernel's TLS (the encryption layer that secures network traffic) handling code; CVE-2026-53266, an 8.8-severity bug in a firewall feature called ebtables; and CVE-2025-39964, a 7.8-severity race condition in a cryptographic subsystem. Red Hat confirmed all three have public exploits circulating and are being actively abused, though neither Red Hat nor CISA has said who is behind the attacks or who has been targeted. Patches exist for every affected kernel branch, from older 5.10 releases up through 6.16. The catch is the clock: agencies had until September 21, just three days, to apply them or stop using the vulnerable systems.\n\nCISA typically gives federal agencies three weeks to patch even serious bugs, so a three-day window signals these are considered unusually dangerous. The TLS flaw stands out because Red Hat says it may be triggerable remotely by an unauthenticated attacker sending a crafted TLS record, while the other two require a local foothold to escalate privileges. A plausible remote entry point paired with local privilege escalation bugs is the kind of chain that turns one compromised account into full system control.\n\nThis is at least the second wave of serious Linux kernel disclosures this year, following the DirtyAH6, TUNderflow, PPPoEject, and DiagSpill privilege escalation flaws reported earlier in 2026. Two of these three bugs have workaround mitigations if patching isn't immediate; the crypto race condition does not, so procrastinating on that one isn't really an option.","[\"linux\",\"cisa\",\"vulnerabilities\",\"kernel-security\"]","2026-09-22T01:35:00.000Z","2026-09-22T02:33:03.932Z","2026-09-22T02:33:15.860Z","published",null,[],"security",[26,27,28,29],"linux","cisa","vulnerabilities","kernel-security",[31],{"name":32,"url":33},"TechRadar","https:\u002F\u002Fwww.techradar.com\u002Fpro\u002Fsecurity\u002Flinux-users-beware-cisa-flags-three-major-security-issues-you-need-to-patch-right-now",0,{"sections":36},[37,42,45,50,55,60,65,70,75,80,85,90,94,99],{"name":38,"slug":39,"count":40,"latest_published_at":41},"AI","ai",4180,"2026-09-21T17:30:24.000Z",{"name":43,"slug":24,"count":44,"latest_published_at":18},"Security",687,{"name":46,"slug":47,"count":48,"latest_published_at":49},"Policy","policy",358,"2026-09-21T22:33:45.000Z",{"name":51,"slug":52,"count":53,"latest_published_at":54},"Deals","deals",186,"2026-09-21T17:13:06.000Z",{"name":56,"slug":57,"count":58,"latest_published_at":59},"Hardware","hardware",162,"2026-09-21T17:08:52.000Z",{"name":61,"slug":62,"count":63,"latest_published_at":64},"Science","science",130,"2026-09-20T13:48:11.000Z",{"name":66,"slug":67,"count":68,"latest_published_at":69},"Consumer Tech","consumer-tech",102,"2026-09-21T18:26:11.000Z",{"name":71,"slug":72,"count":73,"latest_published_at":74},"Dev Tools","dev-tools",78,"2026-09-18T04:00:00.000Z",{"name":76,"slug":77,"count":78,"latest_published_at":79},"Software","software",75,"2026-09-10T20:41:21.000Z",{"name":81,"slug":82,"count":83,"latest_published_at":84},"Startups","startups",57,"2026-09-21T18:23:05.000Z",{"name":86,"slug":87,"count":88,"latest_published_at":89},"Gaming","gaming",43,"2026-09-10T12:18:06.000Z",{"name":91,"slug":92,"count":88,"latest_published_at":93},"General","general","2026-09-21T23:48:56.000Z",{"name":95,"slug":96,"count":97,"latest_published_at":98},"Reviews","reviews",24,"2026-09-21T17:00:25.000Z",{"name":100,"slug":101,"count":102,"latest_published_at":103},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]