Daily Signal — 2026-09-21
This is FLLC's automated morning scan of named public sources. It is intentionally concise: what changed, why it may matter, what to verify next, and where the claim came from. 5/5 sources were live for this edition.
At a glance
- CVE-2025-39964 leads the latest CISA exploited-vulnerability entries.
- CISA advisory watch: CISA Adds Two Known Exploited Vulnerabilities to Catalog.
- M5.7 was the strongest M4.5+ event in the USGS 24-hour feed.
- Long March 8A | Unknown Payload is next on the public launch manifest.
Exploited vulnerabilities
- CVE-2025-39964 — Linux Kernel. Added 2026-09-18; remediation due 2026-09-21. Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- CVE-2026-53266 — Linux Kernel. Added 2026-09-18; remediation due 2026-09-21. Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- CVE-2025-39682 — Linux Kernel. Added 2026-09-18; remediation due 2026-09-21. Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
KEV priority queue
- CVE-2025-39964 · Linux Kernel · added 2026-09-18 · due 2026-09-21
- CVE-2026-53266 · Linux Kernel · added 2026-09-18 · due 2026-09-21
- CVE-2025-39682 · Linux Kernel · added 2026-09-18 · due 2026-09-21
- CVE-2026-58704 · Google Pixel · added 2026-09-16 · due 2026-09-19
- CVE-2026-76460 · Cisco Identity Services Engine · added 2026-09-16 · due 2026-09-19
- CVE-2026-87886 · Acronis Backup · added 2026-09-16 · due 2026-09-19
- CVE-2026-76461 · Cisco Secure Email Gateway · added 2026-09-14 · due 2026-09-17
- CVE-2026-84869 · ConnectWise ScreenConnect · added 2026-09-11 · due 2026-09-14
Defensive move: match the cited products against your actual inventory, follow the vendor remediation, and prioritize internet-facing or privileged systems. A catalog entry is evidence of exploitation in the wild—not proof that your environment is compromised.
Threat-actor and campaign watch
- The current CISA advisory window contains no title or summary that explicitly names a threat actor, campaign, or ransomware operation.
Trace responsibly: preserve the source and timestamp, map only explicitly reported infrastructure and MITRE ATT&CK behaviors, separate observed facts from assessment, and record confidence. A vendor, geography, malware family, or IP address alone is not actor attribution.
Earth systems
-
M5.7 — south of Africa, 2026-09-20 20:54 UTC. The M4.5+ day feed contained 15 events when retrieved. Open the USGS event.
-
NOAA space-weather data was unavailable or malformed during this run.
Interpretation boundary: earthquake magnitude does not establish local impact, and Kp is planetary-scale context. Follow the issuing agency and local authorities for decisions.
Orbital watch
- Long March 8A | Unknown Payload — China Aerospace Science and Technology Corporation; Go for Launch; no-earlier-than 2026-09-23 13:30 UTC. Pad: Commercial LC-1 · Wenchang Space Launch Site, People's Republic of China.
Launch times and status can move. Confirm with the launch provider before travel, viewing, or operational decisions.
Source health
- CISA: live
- ADVISORIES: live
- USGS: live
- NOAA: live
- LAUNCHES: live
Primary sources
- CISA Known Exploited Vulnerabilities
- CISA Cybersecurity Advisories
- USGS M4.5+ earthquakes, past day
- NOAA SWPC planetary K-index
- Launch Library 2 upcoming manifest
Retrieved 2026-09-21 15:15 UTC. Automated, source-linked, and reviewed by machine rules for completeness. It is not emergency, navigational, investment, or legal advice.