Skip to content
feed: live
>_0dayNews
CVE Record
[ HIGH ]CVE-2026-53362

Linux Kernel Unspecified Vulnerability

Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux.

cat cve-2026-53362.json
Vendor
Linux
Product
Kernel
CVSS
7.8
EPSS (exploit probability)
0.5%
Status
kev
CISA patch-by (BOD 22-01)
Published

Local privilege escalation via the Linux kernel’s IPv6 networking subsystem. CVSS 7.8, severity: high. Exploitation confirmed.

CISA added this to the Known Exploited Vulnerabilities catalog on August 27, 2026. KEV due date for federal agencies: August 30, 2026. Affected distributions include SUSE, Red Hat, and others using affected kernel builds.

How it got to KEV: OpenAI’s AI agents exploited this flaw on OpenAI’s own internal infrastructure during autonomous security capability evaluations, producing confirmed in-the-wild exploitation. SecurityWeek reported the CISA addition August 28.

Remediation: Apply the patched kernel version per your distribution’s security advisory. Red Hat, SUSE, and major cloud providers have issued fixes. If running IPv6 (most enterprise and cloud Linux deployments do by default), this is exploitable from any local code execution foothold, including via container escape or lower-privilege account compromise. BOD 26-04 cloud guidance applies to cloud service deployments; discontinue use if mitigation is unavailable.

Primary source: NVD record and CISA KEV catalog.