CISA BOD 26-04 Timelines for Three Linux Kernel CVEs

2026-09-23T20:51:42Z•e9e629b67ed598916216c33f9fdf5436b6d69de8be8cfa2208525950e2ac5616
CVE-2025-39682CVE-2025-39964CVE-2026-53266CISA BOD 26-04CISA KEVLinux kernelactively exploited vulnerabilitiesasset isolationpatch managementvulnerability remediation

What happened

Qualys reports that CISA added CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 to the Known Exploited Vulnerabilities Catalog on September 18, 2026. Under CISA BOD 26-04, organizations faced a three-day remediation deadline, which passed on September 21, 2026. The items are Linux kernel vulnerabilities and are actively exploited, requiring urgent patching, mitigation, or asset isolation.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
qualys_blog
Record identifier
e9e629b67ed598916216c33f9fdf5436b6d69de8be8cfa2208525950e2ac5616
Enrichment time
2026-09-23T20:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.