CISA adds three Linux kernel flaws to its exploited catalog, all of them in the network plumbing
On September 18, 2026, CISA added three Linux kernel vulnerabilities to the KEV catalog: a race in AF_ALG, an out-of-bounds write in ebtables SNAT, and mishandled zero-length TLS records. Patch before September 21 and confirm your distribution has backported all three commits.