DIRAS TAKE
Urgent: CISA added CVE-2026-53266 to its Known Exploited Vulnerabilities catalog with a short federal remediation deadline, so prioritize installing the kernel fixes or mitigations immediately.
What is CVE-2026-53266?
Local low-privileged users can cause an out-of-bounds write in the Linux Kernel's ebtables SNAT target, allowing modification of memory when rewriting the ARP sender hardware address. CVE-2026-53266 affects multiple maintained kernel branches where commits begin at 63137bc... and fixes appear before the listed branch-specific commits; some older branches (for example 2.x and 51.x) show no fixed commit. An attacker needs local access with low privileges (no user interaction required) to trigger this flaw. The weakness is classified as CWE-787 (Out-of-bounds Write).
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Which versions of Linux Kernel are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Linux | 63137bc5882a1882c553d389fdeeeace86ee1741 – before bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87 | bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87 |
| 76280.x | 63137bc5882a1882c553d389fdeeeace86ee1741 – before 76280b78cc9f23bdc6438e10ad6dff148ef8375b | 76280b78cc9f23bdc6438e10ad6dff148ef8375b |
| Linux | 63137bc5882a1882c553d389fdeeeace86ee1741 – before b7e91939ba9be805a62a257fa4e227dffbb88fa0 | b7e91939ba9be805a62a257fa4e227dffbb88fa0 |
| Linux | 63137bc5882a1882c553d389fdeeeace86ee1741 – before afd64b59c3de9bbbdd3759e834fdc55cda716e0b | afd64b59c3de9bbbdd3759e834fdc55cda716e0b |
| 153.x | 63137bc5882a1882c553d389fdeeeace86ee1741 – before 153ea96c806aea395daba907a4f88480b6ad5093 | 153ea96c806aea395daba907a4f88480b6ad5093 |
| Linux | 63137bc5882a1882c553d389fdeeeace86ee1741 – before b18675263db1147c8e1cab625400c13a0d87bd2d | b18675263db1147c8e1cab625400c13a0d87bd2d |
| Linux | 63137bc5882a1882c553d389fdeeeace86ee1741 – before c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5 | c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5 |
| 67.x | 63137bc5882a1882c553d389fdeeeace86ee1741 – before 67ba971ae02514d85818fe0c32549ab4bfa3bf49 | 67ba971ae02514d85818fe0c32549ab4bfa3bf49 |
| 2.x | 2f3839075a5f8dcf116c1abe35b36b018ac62445 | |
| 51.x | 51ba2945a8ef65ae437c8f9ba05f0343aa82ae5b |
Is CVE-2026-53266 being exploited?
CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-09-18 and directed remediation by 2026-09-21 (US federal agencies must comply). Public exploit code is available.
How to fix CVE-2026-53266
- Install vendor or distribution kernel updates that include the fixes (see fixed commits such as bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87 and the other branch fixes listed).
- If a fixed kernel is not available for your branch, restrict local access to affected systems and disable or restrict ebtables SNAT/ARP rewrite functionality where possible.
- Monitor for suspicious local activity and apply host-based detection for abnormal ARP or skb operations.
- Follow your vendor's published guidance and apply recommended mitigations until you can upgrade to a fixed kernel.
Frequently asked questions
Is CVE-2026-53266 being actively exploited?
Yes. CISA added CVE-2026-53266 to the Known Exploited Vulnerabilities catalog on 2026-09-18 and public exploit code is available.
Which Linux Kernel versions are affected by CVE-2026-53266?
Multiple kernel branches are affected where history starts at commit 63137bc5882a... and are fixed before the branch-specific commits listed; some older branches such as 2.x and 51.x show no fixed commit in the provided data.
Is there a patch for CVE-2026-53266?
Yes. Fixed commits are provided for several branches (for example bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87 and other branch-specific commits); apply distribution or vendor kernel updates that include those commits.
Does CVE-2026-53266 require authentication?
No interactive authentication is required; the vulnerability is exploitable by a local low-privileged user on affected Linux Kernel builds.
References
- nvd.nist.gov/vuln/detail/CVE-2026-53266
- cve.org/CVERecord?id=CVE-2026-53266
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-53266
- git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87
- git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b
- git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0
- git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b
- git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093
- git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d
- git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5
- git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49
- All Linux CVEs on CVE Radar
- CVEs published in September 2026