Linux Kernel Flaw Added to CISA KEV Under Active Exploitation
Key findings • Linux kernel vulnerability CVE-2022-0995 confirmed actively exploited. • Added to CISA's KEV Catalog on August 26, 2026, signaling urgent threat. • Immediate patching of al…

Key findings
- Linux kernel vulnerability CVE-2022-0995 confirmed actively exploited.
- Added to CISA's KEV Catalog on August 26, 2026, signaling urgent threat.
- Immediate patching of all Linux systems is critical to mitigate risk.
- Federal agencies must remediate by CISA's mandated deadline.
A significant Linux kernel vulnerability, identified as CVE-2022-0995, has been added to CISA's Known Exploited Vulnerabilities (KEV) Catalog, confirming its active exploitation in the wild. This addition on August 26, 2026, signals an urgent call to action for organizations and users running Linux-based systems, as threat actors are actively leveraging this flaw to compromise targets.
CVE-2022-0995, a critical kernel flaw, poses a substantial risk to the integrity and security of affected systems. While specific exploitation details are not publicly disclosed, its presence in the KEV catalog indicates that it has been observed being used by malicious actors, making it a high-priority threat that requires immediate attention. The nature of kernel vulnerabilities often allows for deep system compromise, potentially leading to privilege escalation, data exfiltration, or complete system takeover.
The inclusion of CVE-2022-0995 in the KEV catalog underscores the severity of the threat. CISA maintains this catalog to provide a definitive list of vulnerabilities that have been proven to be actively exploited, serving as a crucial resource for federal civilian executive branch (FCEB) agencies and a strong recommendation for all organizations. Active exploitation means that the window for proactive defense is closing, and systems that remain unpatched are at heightened risk of compromise.
Defenders must prioritize the immediate patching of all Linux systems to address CVE-2022-0995. Organizations should consult their Linux distribution's security advisories and apply the necessary updates without delay. For federal agencies, CISA's Binding Operational Directive (BOD) 22-01 mandates the remediation of KEV entries within specified deadlines, typically within a few weeks of listing. All other organizations are strongly advised to follow this guidance to protect their assets from ongoing attacks.