
September 18, 2026 — CISA added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. Two additional vulnerabilities affecting Acronis Backup and Google Pixel were added on September 16.
The Linux additions affect three distinct kernel areas: TLS processing, cryptographic sockets, and bridge/netfilter networking.
Quick Reference
September 18, 2026
CVE-2025-39682 — Linux Kernel TLS
CWE-754: Improper Check for Unusual or Exceptional Conditions
KEV deadline: September 21, 2026
CVE-2025-39964 — Linux Kernel AF_ALG
CWE-362: Race Condition
CVSS: 7.8 High
KEV deadline: September 21, 2026
CVE-2026-53266 — Linux Kernel ebtables/Netfilter
CWE-787: Out-of-Bounds Write
CVSS: 8.8
KEV deadline: September 21, 2026
September 16, 2026
CVE-2026-87886 — Acronis Backup
CWE-276: Incorrect Default Permissions
Impact: Local privilege escalation
KEV deadline: September 19, 2026
CVE-2026-58704 — Google Pixel
Impact: Authorization bypass / privilege escalation
KEV deadline: September 19, 2026
CVE-2025-39682 — Linux Kernel TLS
This flaw affects the Linux kernel’s TLS receive path.
The issue involves the handling of zero-length TLS records during zero-copy processing. Under specific conditions, the kernel can encounter an unexpected state when processing records on the receive queue.
The vulnerability is classified as CWE-754, indicating that an unusual or exceptional condition is not handled correctly.
The relevant attack surface is therefore tied to Linux systems using the affected kernel TLS functionality.
Upstream fixes have been released for affected kernel branches. Since Linux distributions commonly backport security fixes, the distribution-specific advisory should be used to determine whether an installed kernel contains the fix.
CVE-2025-39964 — Linux Kernel AF_ALG Race Condition
This vulnerability affects AF_ALG, the Linux kernel interface that allows applications to access cryptographic operations through sockets.
The problem occurs when concurrent writes target the same AF_ALG socket. The resulting interleaving can leave internal state inconsistent.
The vulnerability is classified as CWE-362 — Race Condition and carries a CVSS 3.1 score of 7.8.
The upstream fix adds synchronization around the affected context, preventing competing writers from modifying it concurrently.
Because the vulnerability has a local attack vector, Linux systems allowing untrusted or semi-trusted workloads deserve particular attention.
CVE-2026-53266 — Linux Kernel ebtables / Netfilter
This vulnerability affects the ebtables SNAT target used with Linux bridge/netfilter functionality.
The flaw occurs during ARP sender hardware-address rewriting. Under a specific socket-buffer condition, the kernel can attempt to write the replacement MAC address into memory that is not safely writable.
This creates an out-of-bounds write, classified as CWE-787.
Potential consequences include memory corruption, denial of service and potentially local privilege escalation.
The affected functionality is particularly relevant to systems using:
- Linux bridges
- ebtables
- Netfilter
- ARP manipulation
- Bridge NAT
- Container networking
- Virtualization networking
The vulnerability therefore depends heavily on the relevant networking configuration rather than simply the presence of a Linux kernel.
CVE-2026-87886 — Acronis Backup
CISA added this vulnerability on September 16.
It affects Acronis Backup integrations for:
- cPanel & WHM
- Plesk
- DirectAdmin
The issue is incorrect default permissions (CWE-276) and can allow local privilege escalation.
Affected versions identified in the CVE record include:
- cPanel & WHM: before 1.9.3.1021
- Plesk: before 1.8.11.638
- DirectAdmin: before 1.2.3.238
The CISA remediation deadline is September 19, 2026.
CVE-2026-58704 — Google Pixel
The second September 16 addition affects the cellular modem component of Google Pixel devices.
A logic error can allow authorization checks to be bypassed, potentially resulting in privilege escalation.
Google’s September 2026 Pixel bulletin indicated that the vulnerability may have been exploited in limited, targeted attacks.
Supported Pixel devices should be updated to the 2026-09-05 security patch level or later.
CISA’s remediation deadline for the KEV entry is September 19, 2026.
Takeaway
The latest KEV additions cover kernel networking, kernel cryptography, TLS, backup infrastructure and mobile modem security.
For the three Linux vulnerabilities, exposure is highly dependent on the specific kernel version and enabled functionality. For Acronis and Pixel, affected product versions and patch levels provide the primary indicators.
The key distinction is their KEV status: these vulnerabilities have been identified by CISA as having evidence of exploitation, making them significantly different from vulnerabilities that remain only theoretical or unconfirmed in the wild.