The Linux kernel team published 432 Common Vulnerabilities and Exposures (CVEs) within a two-day period in late July 2026. This represents a significant security disclosure event for the Linux open-source project.
Mastodon posts from 2026-08-27 to 2026-08-28 highlighting authoritative cybersecurity news and research sources including Dark Reading, Krebs on Security, Linux Foundation, The Hacker News, and CISA.
The U.S. Cybersecurity and Infrastructure Security Agency warned on September 18–21, 2026, that hackers are actively exploiting three Linux kernel vulnerabilities, including one rated critical, and added them to its Known Exploited Vulnerabilities catalog.
On 28 August 2026, CERT-Bund and NCSC-NL disclosed multiple high and critical vulnerabilities affecting WatchGuard Firebox OS, SmarterTools SmarterMail, vm2 (critical), Redis, Dovecot, and PaperCut MF/NG. Security advisories were published across infosec-exchange Mastodon.
German cybersecurity authority CERT-Bund published advisories on 2026-09-11 for critical vulnerabilities across six major software products: Linux Kernel, Joplin, Palo Alto Networks Cortex XDR, Langflow, Angular, and MongoDB, all rated high-severity with network-accessible attack vectors.
Between September 14–16, 2026, security advisories from CERT-Bund and NCSC-NL disclosed multiple high-severity vulnerabilities in Linux Kernel, Squid proxy, Strapi CMS, Apple iOS, iPadOS, and macOS. One unrelated Turkish-language sports post appeared on September 14.
Between 2026-09-07 and 2026-09-09, Germany's CERT-Bund (BSI) disclosed multiple high and critical severity vulnerabilities affecting MikroTik RouterOS, rclone, Froxlor, strongSwan, Microsoft Office, and libxml2. Vulnerabilities ranged from critical remote code execution in MikroTik to high-severity issues in encryption and office software.
Canonical announced by 2026-09-11 that Ubuntu 26.10 ("Stonking Stingray"), an interim non-LTS release, will ship with Linux kernel 7.3 instead of the originally targeted 7.2. The release includes GNOME 51 and other updated components.
The US Cybersecurity and Infrastructure Security Agency added three Linux kernel vulnerabilities (CVE-2025-39682, CVE-2025-39964, CVE-2026-53266) to its Known Exploited Vulnerabilities catalog on September 21, 2026, after observing active exploitation. The flaws affect kTLS, AF_ALG socket, and ebtables SNAT with CVSS scores up to 9.8, including public exploits available for privilege escalation and container escape.
The Linux kernel team published 432 new CVE identifiers over a single weekend in July, sparking speculation about whether AI-assisted tools were used to generate bug reports. The unusually high volume has raised security concerns.
Modern container isolation was just pierced by an eighteen-year-old networking bug from 2008. Patch your kernels, restart the servers, and pretend the foundation is solid.
This cluster aggregates distinct security incidents including ChatGPT agent deployment flaws, critical vBulletin PHP execution vulnerabilities, Coca-Cola ransomware data theft, GitHub malware removal, and Dysphoria IoT botnet blockchain command infrastructure. These represent separate news items rather than coverage of a single story.
Two reports allege that Linux kernel source code has been leaked, with one sensationalized post warning users to switch to Windows. Details of the breach remain minimal across the available reports.
Garuda Linux released version 260819 ("Temeraire") on 20 August 2026, an Arch Linux-based distribution featuring Linux kernel 7.2 with emphasis on Wayland-based interfaces.
18 is now available for download with new features, enhanced hardware support through new and updated drivers, improvements to filesystems and networking, and much more.
This cluster aggregates unrelated security news: DCSync attacks, Operation STANDOFF malware, a Houston City College breach of 831,642 records, FFmpeg vulnerabilities, and PortSwigger's Burp AI tool announcement. No single narrative unifies these disparate incidents.
Between 2026-09-01 and 2026-09-03, Mastodon users shared resource spotlights for tracking iOS releases and open-source initiatives. Posts highlighted Apple Developer News for beta tracking, MacRumors for timelines and hardware support, and Linux Foundation Newsroom for open-source announcements.
The U.S. Cybersecurity and Infrastructure Security Agency added three actively exploited Linux kernel vulnerabilities (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964) to its Known Exploited Vulnerabilities catalog on 2026-09-19, giving federal agencies a three-day deadline to patch. The report also noted four additional kernel flaws with public root exploits.
MX Linux 25.3 shipped on September 20 as the latest update in the Debian-based 25 "Infinity" series, with installation images including Debian 13.7 updates and Linux Kernel 7.2.