CISA | Alerts
Follow
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new Linux kernel vulnerabilities, CVE-2025-39964 and CVE-2026-53266, to its Known Exploited Vulnerabilities (KEV) Catalog. These vulnerabilities are actively being exploited by malicious actors and pose significant risks. Binding Operational Directive 26-04 requires Federal Civilian Executive Branch (FCEB) agencies to prioritize the remediation of vulnerabilities listed in the KEV Catalog, especially those on public-facing assets. This directive emphasizes a risk-based approach, focusing on vulnerabilities that grant full control of an asset upon exploitation. Agencies are also expected to check for compromise before applying patches. While BOD 26-04 is specific to FCEB agencies, CISA urges all organizations to adopt similar risk-based vulnerability management practices. CISA will continue to update the KEV Catalog with newly identified exploited vulnerabilities. Organizations can nominate vulnerabilities for inclusion in the KEV Catalog if they have a CVE ID, evidence of exploitation, and clear mitigation guidance.