CISA BOD 26-04 Timelines for Three Linux Kernel CVEs

2026-09-24T20:51:42Z•b3ba51ec3f4a3f98b4e48df60c21b94018063ff28ceea8d57392f3942a4ca362
CVE-2025-39682CVE-2025-39964CVE-2026-53266AdobeBOD 26-04CISA KEVLinux kernelMicrosoftOracleactively exploitedpatchingremediation deadlinesvulnerability management

What happened

Qualys reports that CISA added CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964—actively exploited Linux kernel vulnerabilities—to the Known Exploited Vulnerabilities Catalog on September 18, 2026. Under CISA BOD 26-04, federal agencies faced a three-day remediation deadline that passed on September 21, 2026. The feed also covers large Oracle, Microsoft, and Adobe security updates and vulnerability remediation practices.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
qualys_blog
Record identifier
b3ba51ec3f4a3f98b4e48df60c21b94018063ff28ceea8d57392f3942a4ca362
Enrichment time
2026-09-24T20:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CISA BOD 26-04 Timelines for Three Linux Kernel CVEs · Baitaphish