Daily Signal — 2026-09-19
This is FLLC's automated morning scan of named public sources. It is intentionally concise: what changed, why it may matter, what to verify next, and where the claim came from. 4/5 sources were live for this edition.
At a glance
- CVE-2025-39964 leads the latest CISA exploited-vulnerability entries.
- CISA advisory watch: CISA Adds Two Known Exploited Vulnerabilities to Catalog.
- M5.5 was the strongest M4.5+ event in the USGS 24-hour feed.
Exploited vulnerabilities
- CVE-2025-39964 — Linux Kernel. Added 2026-09-18; remediation due 2026-09-21. Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- CVE-2026-53266 — Linux Kernel. Added 2026-09-18; remediation due 2026-09-21. Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- CVE-2025-39682 — Linux Kernel. Added 2026-09-18; remediation due 2026-09-21. Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
KEV priority queue
- CVE-2025-39964 · Linux Kernel · added 2026-09-18 · due 2026-09-21
- CVE-2026-53266 · Linux Kernel · added 2026-09-18 · due 2026-09-21
- CVE-2025-39682 · Linux Kernel · added 2026-09-18 · due 2026-09-21
- CVE-2026-58704 · Google Pixel · added 2026-09-16 · due 2026-09-19
- CVE-2026-76460 · Cisco Identity Services Engine · added 2026-09-16 · due 2026-09-19
- CVE-2026-87886 · Acronis Backup · added 2026-09-16 · due 2026-09-19
- CVE-2026-76461 · Cisco Secure Email Gateway · added 2026-09-14 · due 2026-09-17
- CVE-2026-84869 · ConnectWise ScreenConnect · added 2026-09-11 · due 2026-09-14
Defensive move: match the cited products against your actual inventory, follow the vendor remediation, and prioritize internet-facing or privileged systems. A catalog entry is evidence of exploitation in the wild—not proof that your environment is compromised.
Threat-actor and campaign watch
- The current CISA advisory window contains no title or summary that explicitly names a threat actor, campaign, or ransomware operation.
Trace responsibly: preserve the source and timestamp, map only explicitly reported infrastructure and MITRE ATT&CK behaviors, separate observed facts from assessment, and record confidence. A vendor, geography, malware family, or IP address alone is not actor attribution.
Earth systems
-
M5.5 — Kermadec Islands region, 2026-09-18 23:18 UTC. The M4.5+ day feed contained 13 events when retrieved. Open the USGS event.
-
NOAA space-weather data was unavailable or malformed during this run.
Interpretation boundary: earthquake magnitude does not establish local impact, and Kp is planetary-scale context. Follow the issuing agency and local authorities for decisions.
Orbital watch
- The public launch manifest was unavailable or returned no upcoming mission during this run.
Launch times and status can move. Confirm with the launch provider before travel, viewing, or operational decisions.
Source health
- CISA: live
- ADVISORIES: live
- USGS: live
- NOAA: live
- LAUNCHES: unavailable
Primary sources
- CISA Known Exploited Vulnerabilities
- CISA Cybersecurity Advisories
- USGS M4.5+ earthquakes, past day
- NOAA SWPC planetary K-index
- Launch Library 2 upcoming manifest
Retrieved 2026-09-19 15:15 UTC. Automated, source-linked, and reviewed by machine rules for completeness. It is not emergency, navigational, investment, or legal advice.