Linux accounts for half of CISA’s latest actively exploited flaws
Legacy Linux is under fire.

Image by Cybernews.
- CISA added six actively exploited flaws, and three affect Linux-related software.
- The Linux flaws are older issues from 2015 and 2022, despite available patches.
- Their exploitation suggests some legacy Linux systems remain exposed in production environments.
- Recent malware, ransomware, and kernel flaws show attackers are expanding attacks against Linux infrastructure.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Linux vulnerabilities account for half of the 6 security flaws added to CISA's actively exploited catalog this week, reflecting a growing trend of attackers targeting the operating system for malware and ransomware campaigns.
The US Cybersecurity and Infrastructure Security Agency (CISA) added 6 vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on August 26th, based on evidence that attackers are exploiting them in the wild. Three of them affect Linux-related software, although they involve relatively old code.
One of them, CVE-2015-3246, affects the libuser library found in Red Hat Enterprise Linux 5, where the flaw was first discovered back in 2015. The second, CVE-2015-5287, affects the Automatic Bug Reporting Tool before version 2.7.1, which again dates back to 2015.
The third, CVE-2022-0995, is a Linux kernel vulnerability that impacts certain 5.x series of kernels that were released back in 2022.
The age of these vulnerabilities is notable. Despite patches being available for several years, their addition to the active exploit list confirms that these legacy, end-of-life systems remain operational and exposed in production environments.
The other 3 CISA additions affect Microsoft SQL Server, Ajax.NET Professional, and Citrix NetScaler ADC and Gateway. CISA's KEV catalog is specifically intended to track vulnerabilities that attackers are already exploiting, to help organizations prioritize these flaws over vulnerabilities that have not yet been exploited.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Linux is becoming a bigger target
The CISA update comes against a backdrop of increasingly varied attacks against Linux systems.
In February, researchers found a new Linux variant of the SystemBC remote-access trojan infecting more than 10,000 IP addresses. The new variant completely evaded detection across all 62 antivirus providers on VirusTotal.
Ransomware operators are also expanding their reach. The Gunra ransomware operation added a Linux variant in mid-2025 as it moved beyond its original focus on Windows systems.
Linux's dominant role in powering cloud infrastructure also makes it a lucrative target. In July, researchers disclosed a Linux KVM vulnerability dubbed Januscape that could be abused by attackers to take over the host. Although the vulnerability has since been patched, it impacts kernel releases going back 16 years.
Another recent example shows how a kernel flaw can become a cross-distribution problem. Copy Fail affects Linux kernels dating back to 2017, and researchers tested it successfully against popular Linux distributions, including Ubuntu, RHEL, and SUSE, with others also considered vulnerable.
With AI unearthing Linux bugs that have gone unnoticed for several years, CISA’s latest additions to the KEV database paint a worrying picture. Recent attacks show that Linux is already a target, while the age of the vulnerabilities added this week suggests there are older, unpatched Linux installations and that attackers are going after them actively.