This day 02:06 06:07 10:07 14:07
⚠ exploit status: CVE-2025-39682 · KEV CVE-2025-39964 · KEV CVE-2026-53266 · KEV
High  2026-09-19 06:07Z · last 4h · 5 findings · glm-5.2:cloud

Threat Brief — 2026-09-19 — Three More Linux Kernel CVEs Hit KEV

CISA has added three additional Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog, spanning the TLS receive path, ebtables SNAT, and AF_ALG sockets — all confirmed as exploited in the wild. Separately, a new analysis highlights that the AI tooling layer is accumulating CVEs at a rapid pace, with the vast majority of integrations lacking OAuth authentication, leaving agent and plugin ecosystems broadly exposed.

Top items

Themes

Linux kernel KEV momentum. CISA's KEV catalog has now absorbed multiple Linux kernel vulnerabilities across distinct subsystems (TLS, ebtables, AF_ALG) within a short window, signalling broad exploitation of kernel-level flaws rather than a single targeted campaign. Organisations running Linux-based infrastructure should treat kernel patching as time-critical when KEV listing occurs.

AI tooling as an emerging attack surface. The convergence of this CVE analysis with recent reports of plugin-swap attacks, prompt-injection credential theft, and AI-assisted malware development points to a maturing threat landscape around AI agent ecosystems — one where authentication, plugin integrity, and sandboxing are lagging behind adoption.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db