CISA BOD 26-04 Timelines for Three Linux Kernel CVEs
2026-09-23T20:51:42Z•e9e629b67ed598916216c33f9fdf5436b6d69de8be8cfa2208525950e2ac5616
CVE-2025-39682CVE-2025-39964CVE-2026-53266CISA BOD 26-04CISA KEVLinux kernelactively exploited vulnerabilitiesasset isolationpatch managementvulnerability remediation
What happened
Qualys reports that CISA added CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 to the Known Exploited Vulnerabilities Catalog on September 18, 2026. Under CISA BOD 26-04, organizations faced a three-day remediation deadline, which passed on September 21, 2026. The items are Linux kernel vulnerabilities and are actively exploited, requiring urgent patching, mitigation, or asset isolation.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- qualys_blog
- Record identifier
- e9e629b67ed598916216c33f9fdf5436b6d69de8be8cfa2208525950e2ac5616
- Enrichment time
- 2026-09-23T20:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.