CVE-2026-53266: Linux Kernel Out-of-Bounds Write Vulnerability
Linux · Kernel
Listed by CISA as exploited in the wild since 18 Sep 2026. Below: exploitation status, EPSS and every published CVSS, each with its source, then affected versions and references.
Build snapshot collected · KEV catalog 2026.10.02 · EPSS of 2 Oct 2026 · not a live feed: collected once, at build time
Description
as written by CISA (KEV catalog)
Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
Required action
CISA KEV
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected products and versions
CVE record · Linux
Linux · Linux
- affected: from 63137bc5882a1882c553d389fdeeeace86ee1741 before bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87
- affected: from 63137bc5882a1882c553d389fdeeeace86ee1741 before 76280b78cc9f23bdc6438e10ad6dff148ef8375b
- affected: from 63137bc5882a1882c553d389fdeeeace86ee1741 before b7e91939ba9be805a62a257fa4e227dffbb88fa0
- affected: from 63137bc5882a1882c553d389fdeeeace86ee1741 before afd64b59c3de9bbbdd3759e834fdc55cda716e0b
- affected: from 63137bc5882a1882c553d389fdeeeace86ee1741 before 153ea96c806aea395daba907a4f88480b6ad5093
- affected: from 63137bc5882a1882c553d389fdeeeace86ee1741 before b18675263db1147c8e1cab625400c13a0d87bd2d
- affected: from 63137bc5882a1882c553d389fdeeeace86ee1741 before c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5
- affected: from 63137bc5882a1882c553d389fdeeeace86ee1741 before 67ba971ae02514d85818fe0c32549ab4bfa3bf49
- affected: 2f3839075a5f8dcf116c1abe35b36b018ac62445
- affected: 51ba2945a8ef65ae437c8f9ba05f0343aa82ae5b
- affected: b7d23c2c87584eb429f115c078ed511be8b18e29
- affected: from 5.4.73 before 5.5
- and 2 more version statements in the record
Linux · Linux
- affected: 5.10
- unaffected: before 5.10
- unaffected: from 5.10.259 through 5.10.*
- unaffected: from 5.15.210 through 5.15.*
- unaffected: from 6.1.176 through 6.1.*
- unaffected: from 6.6.143 through 6.6.*
- unaffected: from 6.12.94 through 6.12.*
- unaffected: from 6.18.36 through 6.18.*
- unaffected: from 7.0.13 through 7.0.*
- unaffected: from 7.1 through *
Status words (affected, unaffected, unknown) and version bounds are copied from the record. An upper bound such as “before 7.1.0” usually marks the first fixed version; confirm in the vendor advisory before planning an upgrade.
References
CISA KEV notes and CVE record
- https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87
- https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b
- https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0
- https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b
- https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093
- https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d
- https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5
- https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49
- https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk
- https://nvd.nist.gov/vuln/detail/CVE-2026-53266
EPSS over the last 30 days
See also: all Linux entries in KEV · the full KEV catalog
Related entries
Other Linux entries in KEV
- CVE-2025-39682Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
- CVE-2025-39964Linux Kernel Race Condition Vulnerability
- CVE-2026-53362Linux Kernel Unspecified Vulnerability
- CVE-2022-0995Linux Kernel Out-of-Bounds Write Vulnerability
- CVE-2022-0492Linux Kernel Improper Authentication Vulnerability
- CVE-2026-31431Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
Added in the same week (see the week)
Questions about CVE-2026-53266
Is CVE-2026-53266 being exploited?
Yes, according to CISA. CVE-2026-53266 was added to the Known Exploited Vulnerabilities catalog on 18 Sep 2026, which CISA does only with reliable evidence of exploitation in the wild. The catalog field for ransomware campaign use says "Unknown".
What is the deadline to remediate CVE-2026-53266?
CISA set 21 Sep 2026 as the due date for US Federal Civilian Executive Branch agencies. The date is binding only for those agencies; other organisations can read it as a measure of urgency.
What is the EPSS score of CVE-2026-53266?
0.83%, in the 56th percentile, in the FIRST EPSS model of 2 Oct 2026. It estimates the probability of exploitation activity in the following 30 days. For a CVE already in KEV the score is secondary: exploitation has been observed.
How severe is CVE-2026-53266?
416baaa9-dc9f-4396-8d5f-8c081fb06d67 rates it 8.8 HIGH (CVSS 3.1). These are the published assessments as of 3 Oct 2026; this site does not rescore.
Which product does CVE-2026-53266 affect?
Linux Kernel, as named in the CISA catalog. The affected versions listed in the CVE record are on this page; the vendor advisory in the references is the authority on fixed versions.
Related sections
- WatchlistWhat attackers started using this month, most urgent first.
- Exploited catalogEvery flaw CISA lists as used in real attacks (KEV), searchable.
- CVE lookupType one identifier: attack status, probability, severity, versions.
- Attack probabilityEPSS score for up to 100 identifiers at once.
- VendorsWhich vendors have the most exploited flaws.
- RSS and JSON feedsFollow new exploited flaws for the vendors you run.
- Sources and methodWhere each number comes from and how the order is decided.