Organizations should prioritize patching CVE-2025-39682 by applying vendor-provided security updates as soon as they are available. Under BOD 26-04, FCEB agencies must remediate the vulnerability rapidly and check for signs of compromise before patching. All organizations are encouraged to adopt risk-based vulnerability management and monitor CISA advisories for updates.
Quick answers
What is CVE-2025-39682?
Organizations should prioritize patching CVE-2025-39682 by applying vendor-provided security updates as soon as they are available. Under BOD 26-04, FCEB agencies must remediate the vulnerability rapidly and check for signs of compromise before patching. All organizations are encouraged to adopt risk-based vulnerability management and monitor CISA advisories for updates.
How severe is CVE-2025-39682?
high
Is CVE-2025-39682 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2025-39682 be mitigated?
Organizations should prioritize patching CVE-2025-39682 by applying vendor-provided security updates as soon as they are available. Under BOD 26-04, FCEB agencies must remediate the vulnerability rapidly and check for signs of compromise before patching. All organizations are encouraged to adopt risk-based vulnerability management and monitor CISA advisories for updates.
CVSS
—
Vendor
Linux
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
Linux Kernel
Mitigation
Organizations should prioritize patching CVE-2025-39682 by applying vendor-provided security updates as soon as they are available. Under BOD 26-04, FCEB agencies must remediate the vulnerability rapidly and check for signs of compromise before patching. All organizations are encouraged to adopt risk-based vulnerability management and monitor CISA advisories for updates.
CISA has added CVE-2025-39682, a Linux Kernel vulnerability involving an improper check for unusual or exceptional conditions, to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. The vulnerability poses significant risks, particularly to publicly exposed assets, and federal agencies must prioritize remediation under BOD 26-04.