The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added three critical vulnerabilities in the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog. This catalog is used to identify software flaws that are actively being exploited in the wild, prompting government agencies to patch systems or discontinue use of affected products. These vulnerabilities, labeled CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964, have been confirmed as being actively exploited, and CISA has given affected systems a strict three-day deadline to address the issues, which expires on September 21, 2026. Red Hat, a major provider of Linux-based operating systems, has confirmed that these vulnerabilities are being actively exploited and has issued advisories urging users to apply patches immediately. Fixes for all three flaws have been released in various Linux kernel versions. CVE-2025-39682 was addressed in several stable kernel releases, while CVE-2025-39964 has been fixed across multiple versions. CVE-2026-53266 has also been resolved and backported to ensure compatibility with supported systems. The first vulnerability, CVE-2025-39682, involves an improper check in the kernel’s handling of TLS (Transport Layer Security) receive paths. This could allow unauthenticated attackers to launch memory disclosure or denial-of-service (DoS) attacks. The second, CVE-2026-53266, is an out-of-bounds write flaw in the ebtables SNAT (Source Network Address Translation) ARP (Address Resolution Protocol) rewrite patch, which could allow local attackers to escalate privileges or cause system crashes. The third, CVE-2025-39964, involves a race condition in AF_ALG sockets that could allow malicious actors to corrupt cryptographic operations or crash the system. Typically, CISA grants government agencies a three-week window to address such vulnerabilities, but in this case, the three-day deadline indicates the severity of the threats. In a hypothetical attack, an attacker could exploit CVE-2025-39682 by sending specially crafted TLS records to trigger a system crash or execute arbitrary code. Attackers with low-level access could escalate privileges using CVE-2025-39964, while CVE-2026-53266 could be used for similar privilege escalation on specific network configurations. Red Hat notes that CVE-2025-39682 may be remotely exploitable, but only if the system is using the affected kTLS receive path. The other two flaws are local in nature. Mitigation strategies are available for two of the three flaws, such as disabling certain modules or network rules. However, for CVE-2025-39964, there are currently no known workarounds, and applying the provided patches remains the only way to ensure system security.