U.S. CISA adds a flaw in Linux Kernel to its Known Exploited Vulnerabilities catalog

2026-05-04T14:51:52Z61c60c94d9171aaa4d7c258e102ec431e1291b5e7cd6f0875da721c69129ed16
AI-driven vulnerability discoveryBluekitCISACVE-2026-31431CVE-2026-41940GoogleIBM ItalyKnown Exploited Vulnerabilities (KEV)Linux kernelNCSCSalt TyphoonSistemi InformativiTrellixWebProsautomated domain registrationbug bountycPanelcode repository breachpatch managementphishing kitransomwaresupply-chain breachvoice cloning

What happened

Multiple Security Affairs items: CISA added two actively exploited flaws to its KEV list including CVE-2026-31431 (Linux kernel, CVSS 7.8) and CVE-2026-41940 (WebPros cPanel, CVSS 9.3). UK NCSC warns that AI is accelerating vulnerability discovery and may prompt large, urgent patch waves. New threats include Bluekit, an AI-enabled phishing kit with automated domain setup and voice-cloning features, and a reported April 2026 breach of IBM Italy subsidiary Sistemi Informativi linked to Chinese-associated actor(s) (Salt Typhoon). Additional items: Trellix disclosed a source-code repository breach

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
61c60c94d9171aaa4d7c258e102ec431e1291b5e7cd6f0875da721c69129ed16
Enrichment time
2026-05-04T14:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.