A critical out-of-bounds write vulnerability in the Linux kernel, identified as CVE-2026-53266, has been confirmed as exploited in the wild. The flaw, which affects the netfilter bridge component, was publicly disclosed on June 25, 2026, and was added to multiple known exploited vulnerabilities (KEV) catalogs on September 18, 2026, indicating active exploitation approximately 85 days after its disclosure.
The vulnerability stems from an issue within the ebtables SNAT target, specifically concerning the handling of Ethernet source address rewrites. While the Ethernet header is typically protected by `skb_ensure_writable(skb, 0)` to prevent unintended writes, the optional ARP sender hardware address rewrite was found to bypass this protection. This allows for an out-of-bounds write through `skb_store_bits()` at an incorrect offset, potentially leading to privilege escalation or denial of service.
The flaw has a CVSS v3.1 score of 8.8, classifying it as high severity. Its weakness is categorized as NVD-CWE-noinfo, indicating that a specific Common Weakness Enumeration (CWE) has not yet been assigned by the National Vulnerability Database (NVD). The Exploit Prediction Scoring System (EPSS) score is 0.83%, placing it in the 56.0th percentile, suggesting a moderate likelihood of exploitation.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-53266 to its Known Exploited Vulnerabilities catalog on September 18, 2026. On the same day, the European Union Agency for Cybersecurity (ENISA) also listed it in the European Union Vulnerability Database (EUVD), and the commercial research firm VulnCheck included it in its KEV. The Computer Incident Response Center Luxembourg (CIRCL) also aggregates these listings.
CISA has issued a directive requiring federal agencies to apply vendor-provided mitigations for this vulnerability by September 21, 2026. This mandate falls under CISA’s BOD 26-04 guidance, which prioritizes security updates based on risk. Organizations are advised to evaluate their assets' internet exposure and ensure adherence to patching guidelines. If mitigations are unavailable, discontinuing the use of affected products is recommended.
The fix for this vulnerability involves making the ebt_snat ARP rewrite writable in a controlled manner. Patches addressing the issue have been committed to the Linux kernel stable tree, with specific commits including `bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87`, `76280b78cc9f23bdc6438e10ad6dff148ef8375b`, `b7e91939ba9be805a62a257fa4e227dffbb88fa0`, and `afd64b59c3de9bbbdd3759e834fdc55cda716e0b`. These commits collectively resolve the out-of-bounds write by correctly managing the writable state of the ARP sender hardware address rewrite.






