Linux Kernel · Gravity Forms Plugin for WordPress · IBM Guardium Data Protection
Date: 2026-09-19 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership
Executive Summary
CISA added three Linux Kernel vulnerabilities to its Known Exploited Vulnerabilities catalog, with remediation due by 2026-09-21. Public exploit code is also reported for four Linux Kernel flaws, increasing urgency for unpatched systems. New high-severity exposures affect IBM Guardium Data Protection, WordPress plugins and OpenShift Console. Threat activity includes npm-based information stealers, fake GitHub repositories distributing malware and a newly reported Rust-based campaign targeting government and defence entities.
Critical Vulnerabilities
CVE-2025-39964 — Linux Kernel
- Severity: Not supplied
- EPSS: Not supplied
- Technical detail: A race condition in the AF_ALG socket implementation permits concurrent writes to the same socket, potentially corrupting internal state. The flaw is locally exploitable and may enable privilege escalation on systems where an attacker already has local execution capability.
- Exploitation status: STATUS CHANGE — Added to CISA KEV on 2026-09-18; active exploitation confirmed by CISA.
- Remediation: Apply the vendor kernel update by 2026-09-21. Prioritize internet-facing Linux systems, servers hosting untrusted workloads and multi-user environments. Reboot into the remediated kernel and verify that obsolete kernels are not still in use.
CVE-2026-53266 — Linux Kernel
- Severity: Not supplied
- EPSS: Not supplied
- Technical detail: An out-of-bounds write in the ebtables SNAT target can allow an attacker to rewrite an ARP sender hardware address into memory associated with a splice-imported file page. Exploitation requires access to the affected networking functionality; CISA notes that impacted products may be end-of-life or end-of-service.
- Exploitation status: STATUS CHANGE — Added to CISA KEV on 2026-09-18; active exploitation confirmed by CISA.
- Remediation: Patch to a supported kernel release by 2026-09-21. Identify obsolete distributions and embedded Linux deployments that cannot receive fixes, and replace or isolate them. Review firewall and ebtables configuration where patching is delayed.
CVE-2025-39682 — Linux Kernel
- Severity: Not supplied
- EPSS: Not supplied
- Technical detail: Improper handling of zero-length TLS records in the receive path can cause subsequent records to be processed under incorrect zero-copy and queuing assumptions. The vulnerability is locally exploitable and may result in memory corruption or privilege escalation depending on the kernel build and enabled functionality.
- Exploitation status: STATUS CHANGE — Added to CISA KEV on 2026-09-18; active exploitation confirmed by CISA.
- Remediation: Deploy the fixed kernel by 2026-09-21 and confirm active kernel versions across fleet-management platforms. Investigate unexpected kernel crashes, privilege transitions and anomalous local activity on systems that remain unpatched.
CVE-2026-84434 — Gravity Forms Plugin for WordPress
- Severity: CVSS 9.8
- EPSS: Not supplied
- Technical detail: Versions through 3.1.0.4 contain an arbitrary file-upload vulnerability in the
upload_filefunction. A successful attack may allow an attacker to place executable or otherwise malicious files on a WordPress installation, potentially leading to website compromise depending on server configuration and plugin permissions. - Exploitation status: NEW — Published 2026-09-19; exploitation was not confirmed in the supplied data.
- Remediation: Update Gravity Forms beyond 3.1.0.4 when the vendor fix is available. Until then, restrict upload functionality where operationally possible, review web-server logs and inspect upload directories for newly created PHP or script files.
CVE-2026-82967 — IBM Guardium Data Protection
- Severity: CVSS 9.8
- EPSS: Not supplied
- Technical detail: IBM Guardium Data Protection 12.2 has an authentication-bypass flaw allowing an unauthenticated remote attacker to bypass IP-based access controls and reach the management interface. Exposure is particularly significant when Guardium administration interfaces are reachable from untrusted networks.
- Exploitation status: NEW — Published 2026-09-18; exploitation was not confirmed in the supplied data.
- Remediation: Apply IBM’s security update for version 12.2. Immediately restrict management interfaces to trusted administration networks, review authentication and access-control logs, and investigate unauthorised changes to Guardium configuration or data sources.
ONGOING
CVE-2026-93467(HGiga OAKlouds): newly reported previously; patch or isolate exposed deployments.CVE-2026-81642(Unbound): upgrade to 1.26.1 or later; review resolver crashes and abnormal DNSSEC activity.CVE-2026-72819/CVE-2026-75827(Grav CMS): upgrade to fixed releases and hunt for web shells or modified PHP files.CVE-2026-77179(Docker Sandboxes for macOS): apply Docker’s security update and avoid untrusted workloads on affected versions.CVE-2026-76460,CVE-2026-76461(Cisco ISE/Secure Email Gateway): actively exploited; remediation remains urgent.CVE-2026-87886,CVE-2026-85706,CVE-2026-84869,CVE-2026-42016/CVE-2026-42018,CVE-2026-75650,CVE-2026-86218,CVE-2026-63520: actively exploited or KEV-listed; continue patching and compromise assessment.
European Advisories
BSI CERT-Bund issued updates for Linux Kernel, Node.js, Samba, vm2, Microsoft Windows, Synology DiskStation Manager, IBM QRadar SIEM, Dell Avamar/NetWorker, IBM DataPower Gateway and Apache Tomcat. The updates describe impacts including code execution, privilege escalation, authentication bypass, information disclosure and denial of service; review affected package versions and vendor guidance. BSI advisory index
WID-SEC-2026-2640 (Linux Kernel), WID-SEC-2026-1686 (Samba) and related entries: status updates only; incorporate the revised package information into vulnerability-management baselines.
CISA’s new KEV additions for CVE-2025-39964, CVE-2026-53266 and CVE-2025-39682 are covered in Critical Vulnerabilities. CISA KEV announcement
Active Threats and Campaigns
- Rapuncel infostealer: An ongoing campaign uses SEO-optimised GitHub repositories impersonating legitimate software providers, including LastPass Authenticator, to distribute a previously undocumented information stealer. Block suspicious repository-derived downloads and hunt for unusual browser credential, cookie and extension-storage access. Bleeping Computer
- WeaselBiscuit npm campaign: Thirteen npm packages were reported distributing a JavaScript stealer targeting Chrome extension storage. Review recent dependency changes, package-lock files and CI/CD installation logs; remove compromised packages and rotate exposed tokens. The Hacker News
- Transparent Tribe activity: A newly reported campaign uses Rust-based tools and private GitHub repositories for command and control against government and defence targets in India and Afghanistan. The regional focus is outside Germany, but organisations should monitor for suspicious GitHub-based C2 and unsigned Rust binaries. The Hacker News
- Brevo supply-chain compromise, LausivLoader malspam and RatHat Android activity: no material change supplied; continue monitoring existing detections and indicators.
Security News and Context
- Public exploit code was reportedly released for four Linux Kernel flaws enabling local root access; systems running outdated kernels should be treated as high priority. The Hacker News
- CrowdSec reported a supply-chain incident involving more than 300 repositories; the vendor assessed the impact as limited, but affected organisations should validate repository integrity and CI/CD credentials. Heise
- A new WordPress “Click2Shell” attack chain can induce a logged-in administrator to install a theme through a crafted link. Apply current WordPress core updates and strengthen administrator session protections. The Hacker News
Recommended Actions
- Patch all Linux systems affected by the three new CISA KEV entries by 2026-09-21; confirm active kernel versions after reboot.
- Identify and isolate unsupported Linux systems and exposed ebtables/AF_ALG workloads.
- Patch IBM Guardium Data Protection 12.2 and remove management interfaces from untrusted networks.
- Audit WordPress installations for vulnerable Gravity Forms and other newly reported plugins; inspect upload directories.
- Hunt for Rapuncel and WeaselBiscuit indicators across endpoints, npm registries and CI/CD pipelines.
- Validate CrowdSec and other third-party repository integrity, including tokens and build credentials.
- Continue remediation of previously reported items: OAKlouds, Unbound, Grav, Docker Sandboxes, Cisco, Acronis, GitLab, ScreenConnect, Artifactory, Magento, N-central and SharePoint.