LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
CVE-2026-53266high

Linux Kernel Out-of-Bounds Write Exploited, Added to EUVD

A Linux kernel vulnerability, CVE-2026-53266, has been confirmed as exploited and added to the EUVD catalogue. This follows its inclusion in the CISA KEV list.

ZeroDay News ·

A critical out-of-bounds write vulnerability in the Linux kernel, identified as CVE-2026-53266, has been confirmed as exploited in the wild. The flaw, which affects the netfilter bridge component, was publicly disclosed on June 25, 2026, and was added to multiple known exploited vulnerabilities (KEV) catalogs on September 18, 2026, indicating active exploitation approximately 85 days after its disclosure.

The vulnerability stems from an issue within the ebtables SNAT target, specifically concerning the handling of Ethernet source address rewrites. While the Ethernet header is typically protected by `skb_ensure_writable(skb, 0)` to prevent unintended writes, the optional ARP sender hardware address rewrite was found to bypass this protection. This allows for an out-of-bounds write through `skb_store_bits()` at an incorrect offset, potentially leading to privilege escalation or denial of service.

The flaw has a CVSS v3.1 score of 8.8, classifying it as high severity. Its weakness is categorized as NVD-CWE-noinfo, indicating that a specific Common Weakness Enumeration (CWE) has not yet been assigned by the National Vulnerability Database (NVD). The Exploit Prediction Scoring System (EPSS) score is 0.83%, placing it in the 56.0th percentile, suggesting a moderate likelihood of exploitation.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-53266 to its Known Exploited Vulnerabilities catalog on September 18, 2026. On the same day, the European Union Agency for Cybersecurity (ENISA) also listed it in the European Union Vulnerability Database (EUVD), and the commercial research firm VulnCheck included it in its KEV. The Computer Incident Response Center Luxembourg (CIRCL) also aggregates these listings.

CISA has issued a directive requiring federal agencies to apply vendor-provided mitigations for this vulnerability by September 21, 2026. This mandate falls under CISA’s BOD 26-04 guidance, which prioritizes security updates based on risk. Organizations are advised to evaluate their assets' internet exposure and ensure adherence to patching guidelines. If mitigations are unavailable, discontinuing the use of affected products is recommended.

The fix for this vulnerability involves making the ebt_snat ARP rewrite writable in a controlled manner. Patches addressing the issue have been committed to the Linux kernel stable tree, with specific commits including `bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87`, `76280b78cc9f23bdc6438e10ad6dff148ef8375b`, `b7e91939ba9be805a62a257fa4e227dffbb88fa0`, and `afd64b59c3de9bbbdd3759e834fdc55cda716e0b`. These commits collectively resolve the out-of-bounds write by correctly managing the writable state of the ARP sender hardware address rewrite.

vulnerabilities in this storyCVE-2026-53266
vulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-88779

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Citrix has confirmed the active exploitation of a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler appliances. This new flaw reportedly emerged and was exploited just days after the company released patches for two other previously exploited vulnerabilities in the same product line.

CVE-2026-88779high

Citrix NetScaler Flaw Exploited Before CVE Publication

The CVE-2026-88779 vulnerability in Citrix NetScaler was exploited before its official publication date. A second independent catalogue now confirms exploitation.

CVE-2026-88779

Citrix patches NetScaler SAML zero-day exploited in attacks

Citrix has issued urgent security updates for a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler ADC and NetScaler Gateway appliances. The flaw, described as a memory buffer issue, has been actively exploited in targeted attacks, primarily leading to denial-of-service conditions.

patch

Three questions a hospital CISO should ask a healthcare fintech vendor

A cybersecurity expert has outlined key questions hospital CISOs should pose to healthcare fintech vendors to assess their security posture, particularly concerning patient data and financial transactions. Drew McCombs, who holds both CTO and CISO roles at Cylerity, emphasizes that security should be an integral part of development processes, not an afterthought, especially when patient data…

cloud

Keyorix: Open-source secrets management for teams that can’t use SaaS

Keyorix, an open-source secrets management solution, has been released, offering an on-premises alternative for organizations unable to utilize cloud-based services for credential storage. The system is designed to run entirely on a company's own infrastructure, with its core functionality requiring no internet connection.

security

How RMM abuse gives attackers a way in that looks like business as usual

Attackers are increasingly leveraging legitimate remote monitoring and management (RMM) software to gain persistent access to victim systems, a tactic observed in 45% of endpoint-related incidents recorded by security firm Huntress in the first quarter of 2026. This method allows attackers to execute commands remotely and maintain access in a way that often appears to be normal administrative…