Trusence Technology, daily
Last updated 24 September 2026 Türkçe
← All stories
Security

CISA flags active exploits of three Linux kernel bugs and Zyxel switch flaw

Federal agencies must rapidly patch and investigate Linux and Zyxel devices as exploits and public PoC code drive real‑world attacks.

Updated 24 September 2026

CISA is highlighting active exploitation of multiple infrastructure vulnerabilities, including three Linux kernel bugs (CVE-2025-39964, CVE-2026-53266, CVE-2025-39682) that federal agencies must patch and forensically review by the end of the day they were added to the KEV catalog. CISA also added Zyxel GS1900 switch flaw CVE-2026-7273 to the KEV list after attackers used a stack-based buffer overflow in its CGI component to run OS commands and exfiltrate data from 996 devices across 48 countries, with patches available in updated 2.90 firmware builds. D-Link has warned that unauthenticated attackers on the local network can exploit a stack buffer overflow in the DIR-822A DHCP server and a separate critical out-of-bounds write bug (CVE-2026-86510) in the L2TP parser, both with public PoC exploits, and is urging customers to lock down and avoid exposing these routers online while fixes are developed. Eclypsium’s InfraTrust Pulse report notes that attackers are increasingly going after infrastructure management platforms, highlighting actively exploited flaws in Cisco Secure Firewall Management Center and Cisco Identity Services Engine that allow unauthenticated command execution, as well as critical, remotely exploitable issues in SonicWall SMA 1000 appliances and Check Point remote access/VPN and management servers. Several of these management-plane bugs carry CVSS 10.0 scores and have been added to CISA’s Known Exploited Vulnerabilities catalog, with vendors and national CERTs advising rapid patching and, in some SonicWall cases, full rebuilds of compromised appliances.

Why it matters

The alert means Linux systems and Zyxel GS1900 switches are not facing theoretical risks but live exploitation, including data theft across dozens of countries. Federal agencies now have to both patch and perform forensic triage on affected Linux assets, while owners of impacted Zyxel switches need to apply new firmware to stop unauthenticated remote command execution already used to compromise 996 devices worldwide.

Sources