U.S. CISA adds a flaw in Linux Kernel to its Known Exploited Vulnerabilities catalog
2026-05-04T14:51:52Z•61c60c94d9171aaa4d7c258e102ec431e1291b5e7cd6f0875da721c69129ed16
AI-driven vulnerability discoveryBluekitCISACVE-2026-31431CVE-2026-41940GoogleIBM ItalyKnown Exploited Vulnerabilities (KEV)Linux kernelNCSCSalt TyphoonSistemi InformativiTrellixWebProsautomated domain registrationbug bountycPanelcode repository breachpatch managementphishing kitransomwaresupply-chain breachvoice cloning
What happened
Multiple Security Affairs items: CISA added two actively exploited flaws to its KEV list including CVE-2026-31431 (Linux kernel, CVSS 7.8) and CVE-2026-41940 (WebPros cPanel, CVSS 9.3). UK NCSC warns that AI is accelerating vulnerability discovery and may prompt large, urgent patch waves. New threats include Bluekit, an AI-enabled phishing kit with automated domain setup and voice-cloning features, and a reported April 2026 breach of IBM Italy subsidiary Sistemi Informativi linked to Chinese-associated actor(s) (Salt Typhoon). Additional items: Trellix disclosed a source-code repository breach
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 61c60c94d9171aaa4d7c258e102ec431e1291b5e7cd6f0875da721c69129ed16
- Enrichment time
- 2026-05-04T14:51:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.