CISA has added three critical Linux kernel vulnerabilities with active exploit evidence to its Known Exploited Vulnerabilities catalog, including a severe TLS receive path flaw scored 9.8.
A critical use-after-free flaw in Linux's KVM hypervisor allows guest VMs on Intel and AMD systems to corrupt host kernel memory, potentially escaping the virtual environment. The vulnerability, known as Januscape (CVE-2026-53359), includes a public PoC that crashes hosts with a more impactful exploit reportedly in development.