“3 Linux kernel vulnerabilities” — 33 distilled results

CISA warns of active exploitation of three Linux kernel flaws

The U.S. Cybersecurity and Infrastructure Security Agency warned on September 18–21, 2026, that hackers are actively exploiting three Linux kernel vulnerabilities, including one rated critical, and added them to its Known Exploited Vulnerabilities catalog.

CISA adds three critical Linux kernel vulnerabilities to exploited catalog

The US Cybersecurity and Infrastructure Security Agency added three Linux kernel vulnerabilities (CVE-2025-39682, CVE-2025-39964, CVE-2026-53266) to its Known Exploited Vulnerabilities catalog on September 21, 2026, after observing active exploitation. The flaws affect kTLS, AF_ALG socket, and ebtables SNAT with CVSS scores up to 9.8, including public exploits available for privilege escalation and container escape.

CISA flags three Linux kernel CVEs with three-day patch deadline

The U.S. Cybersecurity and Infrastructure Security Agency added three actively exploited Linux kernel vulnerabilities (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964) to its Known Exploited Vulnerabilities catalog on 2026-09-19, giving federal agencies a three-day deadline to patch. The report also noted four additional kernel flaws with public root exploits.

SkillBloat: Token Amplification Attacks via Skill Injection in LLM Coding Agents

21929v1 Announce Type: new Abstract: Agent skills extend coding agents with task-specific instructions, scripts, and resources, but they also create a trusted instruction channel that can be abused beyond conventional security attacks. This paper studies token amplification through skill injection: an economic resource-abuse threat in which a malicious skill causes an agent to consume substantially more tokens than needed for normal task execution.

New Signal Check is live: Episode 170 - September 18, 2026. This episode covers six critical signals from the cybersecurity landscape, including emergency patches for exploited Cisco vulnerabilities,

New Signal Check is live: Episode 170 - September 18, 2026. This episode covers six critical signals from the cybersecurity landscape, including emergency patches for exploited Cisco vulnerabilities, Iranian state malware targeting dissidents, and a devastating Check Point management flaw that grants attackers root access.

Tech firms launch coalition against AI cyberattacks

OpenAI led an open letter signed by more than 100 organizations, including Anthropic, Microsoft, Google, Amazon, and others, on August 27–29, 2026, calling for coordinated defense against rising AI-enabled cyberattacks. Nvidia's new safety platform received cautious praise by November 2026, with experts noting no single solution exists to AI security risks.

Wave of cybersecurity vulnerabilities disclosed across platforms

Between August 6 and August 20, 2026, multiple critical security flaws were disclosed: the Clop extortion group exploited CVE-2026-12569 in PTC Windchill to steal engineering data; Microsoft patched CVE-2026-24301 affecting Copilot Personal; and a high-severity vulnerability (CVE-2026-0075) in Android's ContactsProvider was made public, affecting Android versions 14–16.

CISA adds seven exploited vulnerabilities to KEV catalog

On 2026-08-24, CISA added CVE-2026-21962 (Oracle HTTP Server and Weblogic Server Proxy Plug-in improper access control) to its Known Exploited Vulnerabilities catalog. On 2026-08-25 and 2026-08-26, CISA added six additional known exploited vulnerabilities including CVE-2026-60004 (Gitea code injection) and CVE-2015-3246 (Red Hat Libuser race condition).