๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-53266: Linux Kernel Out-of-Bounds Write Vulnerability
Summary
The Linux Kernel contains an out-of-bounds write vulnerability (a bug where software writes data outside its intended memory area) in the ebtables SNAT target that allows attackers to manipulate network packet addresses and potentially corrupt system memory. This flaw affects end-of-life products, and users are advised to either apply vendor patches or stop using affected systems. The vulnerability is currently being exploited by attackers in real-world attacks.
Solution / Mitigation
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 guidance for patching. If mitigations are unavailable, discontinue use of the product. Multiple patches are available in the Linux stable kernel repository (referenced via the git.kernel.org commit links provided). Stakeholders must evaluate their systems' internet exposure and adhere to BOD 26-04 patching guidelines by the due date of 2026-09-21.
Vulnerability Details
EPSS: 0.1%
Yes
๐ฅ Actively Exploited
September 17, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-53266
First tracked: September 18, 2026 at 02:00 PM
Classified by LLM (prompt v3) ยท confidence: 95%