CISA added three kernel vulnerabilities already used in attacks on 18 September, with a deadline of 21 September. Their NVD entries date from September and October 2025 and June 2026. The problem is the machines that never got the fix.
- CVE-2026-53266 in ebtables, CVE-2025-39964 in AF_ALG and CVE-2025-39682 in kernel TLS.
- The fixes are in the stable kernel branches CISA points to.
- For two of the three CISA warns that affected products may be end-of-life.
The NVD entry for one of the three dates from September 2025. A year later CISA puts it on the list of holes being used in attacks.
Old patch, new attack. The story is about the server nobody updated.
Who is really affected
The three are different, and not every one affects everyone. ebtables works in the kernel's network bridges, AF_ALG is its interface to cryptography, and the third is in the kernel's own TLS receive path.
What they share is one thing: all three are fixed in the supported branches. The attack lives where the kernel is frozen - an old distribution, an embedded device, a server that has not been rebooted in years.
Check the kernel on your machines with uname -r and compare it with the latest version from your distribution. The NVD entry for the newest of the three dates from June 2026, so a kernel not updated since then is the first to check.