CISA | Alerts
Follow
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added CVE-2025-39682, a Linux Kernel vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability has evidence of active exploitation, making it a significant threat. CVE-2025-39682 allows malicious actors to gain total control of an asset post-exploitation. Federal Civilian Executive Branch (FCEB) agencies must prioritize the remediation of such high-risk vulnerabilities. This requirement is established by Binding Operational Directive (BOD) 26-04, which focuses on risk-based vulnerability management. BOD 26-04 mandates rapid patching of vulnerabilities listed in the KEV Catalog on publicly exposed assets. The directive also outlines expectations for agencies to check for compromises before applying patches. While BOD 26-04 is for FCEB agencies, CISA recommends all organizations adopt similar risk-based practices. CISA will continue to update the KEV Catalog as new exploited vulnerabilities are identified. Organizations can nominate potential additions to the KEV Catalog if they have a CVE ID, proof of exploitation, and mitigation steps.