SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

Three Linux kernel vulnerabilities entered CISA’s KEV catalog on September 18, 2026, although their Linux 6.12 fixes were available 91–386 days earlier. This analysis separates patch availability, CVE publication, and known-exploitation status without treating KEV dates as first-attack dates.

Oct 1, 2026By Emandi Srinivas

Patch Analysis & Exploitation Timeline: Linux 6.12 Fixes Preceded Three KEV Listings by 91–386 Days

Dataset Summary

FieldValueInterpretation
Reporting PeriodSeptember 18, 2026 KEV additionsThe selected timelines extend from August 28, 2025 to September 18, 2026. Catalog due dates are September 21, 2026; source review was completed September 28, 2026.
Data SourcesSupplied CVE list; CISA KEV; CVE Program and NVD records; official Linux release historyThe supplied list defines the scope. Public primary sources establish the additional publication, release, and technical details.
Total CVEs AnalyzedThreeCVE-2025-39964, CVE-2026-53266, and CVE-2025-39682, all affecting the Linux kernel.
Reference Patch BranchUpstream Linux 6.12.xOne common branch keeps the release comparison consistent. These dates are not the earliest fixes across every branch or distribution.
Average CVE-Publication-to-Reference-Patch Gap−10.67 calendar daysThe selected fixed releases preceded formal CVE publication. This is not a measurement from the earliest public disclosure.
Average / Median Reference-Patch-to-KEV Gap278.33 days / 358 daysCalculated from 91, 358, and 386 calendar days. These intervals measure release-to-catalog timing, not attacker activity.
Shortest / Longest Reference-Patch-to-KEV Gap91 days / 386 daysCVE-2026-53266 has the shortest interval; CVE-2025-39682 has the longest.
Average Patch-to-First-Exploitation GapUnavailableNo exact first-exploitation date is established for any of the three CVEs in the reviewed sources.
KEV-to-Due-Date IntervalThree calendar days for all threeSeptember 18 to September 21, 2026. A catalog deadline is not an attacker-free period.

Sourcing and Methodology Note

The supplied three-entry list sets the scope. The CISA Known Exploited Vulnerabilities Catalog, snapshot 2026.09.27, corroborates the addition dates, due dates, weakness classifications, and triage fields. The CVE Program records for CVE-2025-39964, CVE-2026-53266, and CVE-2025-39682, together with their corresponding NVD records (39964, 53266, 39682), provide the publication, CVSS, and technical context.

Patch dates come from the official Linux release history and ChangeLog-6.12.44 (August 28, 2025), ChangeLog-6.12.49 (September 25, 2025), and ChangeLog-6.12.94 (June 19, 2026). Each changelog contains the correction linked by its CVE record. The calculations below are this article’s analytical layer, not statistics published by CISA.

Operational context is drawn from BOD 26-04, Prioritizing Security Updates Based on Risk, its implementation guidance, the Linux Kernel TLS documentation, and the published Red Hat explanation What is backporting and how does it affect Red Hat Enterprise Linux? Product capabilities in the closing section follow the official Saner Patch Management page. Unconfirmed dates remain unavailable.

Introduction

The Linux 6.12 fixes for these three vulnerabilities were available 91 to 386 days before their September 18, 2026 KEV listings. The mean interval is 278.33 days, while the median is 358 days. Two of the selected fixes were released in 2025; the third followed in June 2026.

The finding is a separation between patch availability and catalog inclusion, not a reconstruction of when attackers first acted. For defenders, it illustrates why a newly added KEV may require a fresh assessment of an older vulnerability and its already-published fix.

Background and Context

The cohort spans three different kernel paths: concurrent writing through AF_ALG, an ARP address rewrite in the ebtables SNAT target, and record handling in the kernel TLS receive path. Their common catalog date does not establish a common attack chain, identical prerequisites, or a shared campaign.

Linux fixes can appear in several maintained branches, and distributions can backport corrections into packages with older upstream version numbers. The analysis therefore uses the first fixed upstream 6.12.x release named in each CVE record as a consistent reference. It does not treat that release date as the date every downstream product received an update.

Formal CVE publication also differs from public code availability. Here, all three reference fixes predate their CVE publications. Calling those publication dates the first disclosure of every technical detail would erase information already present in the release history.

Gap Calculation Methodology

D is the calendar date in the CVE record’s datePublished field. P is the release date of the selected fixed Linux 6.12.x version. K is CISA’s dateAdded, E is the actual first-exploitation date, and R is the catalog due date.

CVE-publication-to-reference-patch gap = P − D

Reference-patch-to-KEV gap = K − P

Reference-patch-to-first-exploitation gap = E − P

Catalog remediation interval = R − K

Differences use calendar days without inclusive counting. A patch author’s timestamp is not substituted for the release date. Negative P − D values mean the fixed release preceded formal CVE publication; they do not describe negative remediation time.

KEV inclusion is used only as a dated catalog milestone confirming known exploitation. It is not substituted for E, and it does not quantify “mass exploitation.” The reviewed records do not establish a common measure of attack scale or exact first-attack dates. All three CVEs remain in the release-to-KEV calculation; none supports an exact E-based interval.

Patch Timeline & Exploitation Gap Analysis

The reference-patch-to-KEV distribution is [91, 358, 386] calendar days. Its mean is 278.33 days and its median is 358 days. The 91-day observation pulls the mean below the median, so reporting the mean alone would obscure the two longer intervals.

MetricMeanMedianCoverage and Meaning
CVE publication → reference patch−10.67 days−8 daysThree observations: −18, −6, and −8 days. All selected releases predate formal CVE publication.
Reference patch → KEV addition278.33 days358 daysAll three CVEs; this is the article’s primary timing measure.
Reference patch → actual first exploitationUnavailableUnavailableNo exact first-exploitation dates are established.
KEV addition → catalog due date3 days3 daysAll three entries share the same catalog dates.

CVSS severity-band comparison. To keep the scoring source consistent, this comparison uses the Linux CNA’s CVSS v3.1 values in the CVE Program records: CVE-2025-39964 is 7.8 High, CVE-2026-53266 is 8.8 High, and CVE-2025-39682 is 9.8 Critical.

CVSS Severity BandCVEsReference-Patch-to-KEV GapsMean / MedianInterpretation
HighCVE-2025-39964 (7.8); CVE-2026-53266 (8.8)358 days; 91 days224.5 / 224.5 daysTwo observations with a 267-day spread; they do not form a consistent severity-specific timing pattern.
CriticalCVE-2025-39682 (9.8)386 days386 / 386 daysOne observation only; it cannot establish a Critical-band trend.

The single Critical-severity case has a longer reference-patch-to-KEV interval than either High-severity case, but the cohort is too small to conclude that CVSS severity meaningfully explains the gap. The severity comparison is therefore descriptive, not a severity-to-timing correlation.

These figures do not measure enterprise patch deployment or the time CISA took to act after receiving evidence. Neither installation records nor CISA’s evidence-receipt dates are part of the dataset. They also cannot establish whether exploitation began before or after the reference patches.

CVE Timeline Data

“Patch available” below means the selected upstream Linux 6.12.x release. The signed publication-to-patch column retains the actual sequence instead of forcing negative values to zero.

CVE IDCVE Published (D)Reference Patch Available (P)KEV Added (K)Days: D → PDays: P → K
CVE-2025-39964October 13, 20256.12.49
September 25, 2025
September 18, 2026−18358
CVE-2026-53266June 25, 20266.12.94
June 19, 2026
September 18, 2026−691
CVE-2025-39682September 5, 20256.12.44
August 28, 2025
September 18, 2026−8386

The actual first-exploitation date is unavailable for each row. All three catalog due dates are September 21, 2026.

Selected historical fixed releases across upstream branches

CVE IDLinux 6.1.xLinux 6.6.xLinux 6.12.x
CVE-2025-399646.1.1546.6.1086.12.49
CVE-2026-532666.1.1766.6.1436.12.94
CVE-2025-396826.1.1496.6.1036.12.44

The branch values above were cross-checked against the Linux CNA CVE records and the matching kernel.org changelogs. These are selected fixed releases explicitly named in the CVE records, not a complete affected-product matrix or a recommendation to install those historical builds today. The 6.1.x and 6.6.x releases are not included in the timing calculations. Distribution-specific package and backport status require separate validation.

Statistical Distribution and Outliers

The shortest and longest reference-patch-to-KEV intervals differ by 295 days. The two longer observations, 358 and 386 days, are only 28 days apart; the third is 91 days. This describes a small, uneven sample rather than a stable industry distribution.

CVE-2026-53266 is the low-end observation and CVE-2025-39682 the high-end observation. With only three entries, neither is presented as a formally established statistical outlier. Their differences follow from their release dates relative to one shared KEV date; they do not prove that one weakness class was exploited faster.

Vulnerability Class Breakdown

CVE IDAffected PathCatalog Weakness ClassReference-Patch-to-KEV Gap
CVE-2025-39964AF_ALG socket writesCWE-362 — Race condition358 days
CVE-2026-53266ebtables SNAT ARP address rewriteCWE-787 — Out-of-bounds write91 days
CVE-2025-39682Kernel TLS receive-record handlingCWE-754 — Improper check for unusual or exceptional conditions386 days

Each class has one observation. The table supports identification, not a class-level conclusion about typical patch or exploitation timing. A shared kernel product label also does not make every Linux installation reachable through each affected path.

Notable Case Highlights

CVE-2025-39964: concurrent writes and an 18-day publication difference

The flaw permits concurrent writes to the same AF_ALG socket to interleave and leave inconsistent internal state. The correction prevents concurrent writers in af_alg_sendmsg. Linux 6.12.49 included it on September 25, 2025, while the CVE record was published October 13. Its KEV addition followed 358 days after the reference release.

CVE-2026-53266: a writable-buffer correction with the shortest catalog interval

The ebtables SNAT issue concerns the optional ARP sender hardware address rewrite. The correction makes the relevant buffer range writable before updating it; safely reading a header alone does not establish that the destination is writable. Linux 6.12.94 included the fix on June 19, 2026, six days before CVE publication and 91 days before KEV addition. “Shortest” here refers only to that catalog interval.

CVE-2025-39682: a zero-length TLS record and the longest interval

A zero-length record retrieved from rx_list can bypass the expected record-type handling in recvmsg(), disrupting assumptions about later records. The correction appeared in Linux 6.12.44 on August 28, 2025. Formal CVE publication followed September 5; KEV inclusion came 386 days after the release. The affected receive path is kernel TLS, not a blanket description of every userspace TLS implementation.

Historical Trend Comparison

No comparable earlier cohort using the same upstream branch, publication convention, and KEV endpoint is available in the reviewed material. The result therefore cannot be described as a widening, narrowing, or stable historical trend.

A meaningful series comparison would hold those date definitions constant and account for branch selection and sample size. This article establishes one three-CVE observation, not a trend in exploitation speed.

MITRE ATT&CK Mapping

Technique-level mapping is unavailable for the observed exploitation in this dataset. The reviewed catalog and technical records describe vulnerable behavior and confirm known exploitation, but do not establish the attributable sequence of attacker actions needed for a campaign-specific mapping.

No initial-access, persistence, privilege-escalation, or command-and-control technique is assigned solely from a CWE, a possible impact, or the fact that a kernel component is affected.

Risk Context for Organizations

The operational concern is the status of affected systems when an established vulnerability gains a KEV designation. A long reference-patch-to-KEV interval is not evidence that an organization already deployed the fix, nor that a still-vulnerable system was safe during the interval.

CVE IDCatalog Due DateForensic-Triage FlagKnown Ransomware Campaign Use
CVE-2025-39964September 21, 2026YesUnknown
CVE-2026-53266September 21, 2026YesUnknown
CVE-2025-39682September 21, 2026YesUnknown

These due dates had passed by the September 28 source review. “Unknown” ransomware use is not confirmation that ransomware activity is absent. The latter two entries also warn that impacted products could be end-of-life or end-of-service; that conditional warning does not classify every Linux product as unsupported.

The entries reference BOD 26-04 and its forensic-triage guidance. The directive addresses Federal Civilian Executive Branch agencies; the catalog dates should not be presented as universal legal deadlines for every organization. Elsewhere, the same information can inform an organization’s own risk and response requirements.

Detection and Patch Prioritization Considerations

Assess the deployed package, not just an upstream version string. Match the distribution, package revision, and applicable advisory to its backport status. The historical 6.12 releases explain the analysis; they are not a universal vulnerability-detection rule for vendor-maintained kernels.

Keep exposure assessment specific to the component. AF_ALG writes, ebtables SNAT rewriting, and kernel TLS receive processing are different paths. Kernel TLS receive support is configured separately through TLS_RX; ordinary use of HTTPS alone does not establish this particular receive-path exposure. Do not infer a shared remote attack surface from the kernel label.

Combine update validation with compromise assessment. The triage flags support treating evidence preservation and investigation as distinct response work, alongside mitigation. Confirm that corrected code is active through the platform-supported update or activation process. Record the deployed state, applicable exposure, and unresolved exceptions rather than equating an available patch with completed remediation.

Key Takeaways

  • The three selected Linux kernel CVEs entered KEV on September 18, 2026; their reference Linux 6.12 fixes preceded inclusion by 91, 358, and 386 days.
  • The reference-patch-to-KEV mean is 278.33 days and the median is 358 days; neither value is an observed attacker waiting period.
  • All three selected fixed releases preceded formal CVE publication, showing why publication and public patch availability must remain separate events.
  • No exact first-exploitation dates are established, so a patch-to-first-exploitation average or zero-day classification is unsupported by this analysis.
  • Distribution backport status, active corrected code, component exposure, and compromise assessment require separate checks.

Conclusion

This cohort shows how a new KEV designation can concern vulnerabilities with substantially older fixes. On the common Linux 6.12 reference branch, the releases preceded catalog inclusion by 91 to 386 days, while the actual first-exploitation dates remain unresolved.

For patch and compliance monitoring, preserve the distinction between a published correction, a formal CVE record, evidence of known exploitation, and a verified deployed fix. Those separate milestones support an auditable response without inventing an attack timeline.

Constantly Fix Risks with Saner Patch Management

Saner Patch Management supports patch workflows across Windows, Linux, macOS, and more than 550 third-party applications. Its published capabilities include policy-driven automation, risk-based prioritization, patch-compliance tracking, and rollback.

Evaluate supported products and applicable updates for your environment, and connect patch deployment with verification and compliance reporting. Schedule a demonstration here.

Featured Posts

Open WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels
WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

CVE Research

WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

Oct 1, 2026

Open OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure
OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

CVE Research

OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

Two critical vulnerabilities added to CISA KEV on September 24, 2026 reveal sharply different exploitation timelines. CVE-2026-71362 saw publicly documented exploitation roughly one day after Adobe's patch release, while CVE-2026-5430 had a 133-day vendor-remediation-to-observed-exploitation interval.

Oct 1, 2026

Open Citrix Sounds the Alarm: Two Critical NetScaler Zero-Days Actively Exploited
Citrix Sounds the Alarm: Two Critical NetScaler Zero-Days Actively Exploited

CVE Research

Citrix Sounds the Alarm: Two Critical NetScaler Zero-Days Actively Exploited

Citrix has released security updates for NetScaler ADC and NetScaler Gateway addressing CVE-2026-88771 and CVE-2026-88772, two critical remote code execution vulnerabilities. Exploits against unmitigated deployments have been observed. CVE-2026-88771 affects all deployments, including default configurations; CVE-2026-88772 applies when DTLS is enabled, including the default state on VPN virtual servers. This article covers impact, affected and fixed versions, how to confirm exposure, and recommended remediation.

Sep 28, 2026