Skip to content

Data collected

CVEs Live

CVE-2026-53362: Linux Kernel Unspecified Vulnerability

Linux · Kernel

Listed by CISA as exploited in the wild since 27 Aug 2026. Below: exploitation status, EPSS and every published CVSS, each with its source, then affected versions and references.

Build snapshot collected · KEV catalog 2026.10.02 · EPSS of 2 Oct 2026 · not a live feed: collected once, at build time

Description

as written by CISA (KEV catalog)

Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux.

Required action

CISA KEV

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected products and versions

CVE record · Linux

  • Linux · Linux

    • affected: from 773ba4fe9104a64a54d1c00f0fb6ffb95def2b03 before 14200d435af9a9eeb444f529fc2f689a236b7962
    • affected: from 773ba4fe9104a64a54d1c00f0fb6ffb95def2b03 before 65fb14cbebb0cd0eff903a22d33537ddc8b95769
    • affected: from 773ba4fe9104a64a54d1c00f0fb6ffb95def2b03 before 46f201f8b4c39633a1fa3dc12459f506d470993d
    • affected: from 773ba4fe9104a64a54d1c00f0fb6ffb95def2b03 before 6374fb9edf72c67a118a2c214a0dddd04c921e0a
    • affected: from 773ba4fe9104a64a54d1c00f0fb6ffb95def2b03 before e9eacf19281ea2498b36291b56c9606118c2d74e
    • affected: from 773ba4fe9104a64a54d1c00f0fb6ffb95def2b03 before 736b380e28d0480c7bc3e022f1950f31fe53a7c5
  • Linux · Linux

    • affected: 6.0
    • unaffected: before 6.0
    • unaffected: from 6.1.177 through 6.1.*
    • unaffected: from 6.6.144 through 6.6.*
    • unaffected: from 6.12.95 through 6.12.*
    • unaffected: from 6.18.38 through 6.18.*
    • unaffected: from 7.1.3 through 7.1.*
    • unaffected: from 7.2 through *

Status words (affected, unaffected, unknown) and version bounds are copied from the record. An upper bound such as “before 7.1.0” usually marks the first fixed version; confirm in the vendor advisory before planning an upgrade.

References

CISA KEV notes and CVE record

EPSS over the last 30 days

See also: all Linux entries in KEV · the full KEV catalog

Questions about CVE-2026-53362

Is CVE-2026-53362 being exploited?

Yes, according to CISA. CVE-2026-53362 was added to the Known Exploited Vulnerabilities catalog on 27 Aug 2026, which CISA does only with reliable evidence of exploitation in the wild. The catalog field for ransomware campaign use says "Unknown".

What is the deadline to remediate CVE-2026-53362?

CISA set 30 Aug 2026 as the due date for US Federal Civilian Executive Branch agencies. The date is binding only for those agencies; other organisations can read it as a measure of urgency.

What is the EPSS score of CVE-2026-53362?

0.71%, in the 52th percentile, in the FIRST EPSS model of 2 Oct 2026. It estimates the probability of exploitation activity in the following 30 days. For a CVE already in KEV the score is secondary: exploitation has been observed.

How severe is CVE-2026-53362?

416baaa9-dc9f-4396-8d5f-8c081fb06d67 rates it 7.8 HIGH (CVSS 3.1). These are the published assessments as of 3 Oct 2026; this site does not rescore.

Which product does CVE-2026-53362 affect?

Linux Kernel, as named in the CISA catalog. The affected versions listed in the CVE record are on this page; the vendor advisory in the references is the authority on fixed versions.

Related sections