CISA BOD 26-04 Timelines for Three Linux Kernel CVEs
From the source: Qualys BlogExecutive Summary CISA added three actively exploited Linux kernel vulnerabilities: CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 to its KEV Catalog on September 18, 2026, triggering a 3-day remediation deadline that passed on September 21. Under CISA BOD 26-04, a 3-day window applies to CVE-2025-39682 across all assets, and for the other two, the deadline is 3 days […]
Read the full story on Qualys BlogHave you worked with this?
The story is what was announced. Nobody has discussed it yet, so if it touches your team, a short post about what you’ve seen helps the next reader.
More from Qualys
Recent updates from Qualys, so you can tell whether this is a one-off or part of a pattern.
The End of Point-in-Time Compliance: Why Continuous Audit Readiness Matters to You in the AI Era
AI-driven threats are outpacing traditional audits. Discover how continuous monitoring, automated evidence collection, and risk-based remediation help security teams close compliance gaps and maintain audit readiness as environments change daily.
The Autonomous Engine Behind Remediation, and What Finally Makes It Safe
Executive Summary Vulnerability exploitation now happens at a speed that manual, ticket-based remediation can’t match. Qualys’s Enterprise TruRisk Management Platform closes that gap with autonomous remediation: exposures are prioritized by threat, business, and environmental context, then validated by TruConfirm and Agent Val before any resource is committed, eliminating over 90% of remediation…
Oracle Critical Security Patch Update, September 2026 Review
Oracle released its September edition of Critical Security Patch Update. The update received patches for 673 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products. Out of the 673 security updates published, a total of 104 […]
More in Security
What other companies in Security are doing. The category page shows who’s active, side by side.
Threat Actors Use Google Ads To Target Ledger Users
In August 2026, Zscaler ThreatLabz analyzed a phishing campaign that used fraudulent Google ads to target Ledger hardware wallet users. The ads redirected users through Google Cloud Storage and Vercel to a Google Sites page containing a phishing page impersonating Ledger in an iframe. During our analysis, the Vercel redirect appeared to change every 15-20 minutes. There, a fake…
Metasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites?
Two Things Every Cyber Asset Attack Surface Management (CAASM) Tool Needs to Get Right
Cyber Asset Attack Surface Management (CAASM) solved a significant problem. Security teams can now say with confidence what they own. But, two things separate a CAASM tool that stops there from one that actually moves the needle on risk. The first is what the inventory itself carries. The second is what it connects to. 1. An inventory needs to do more than list what exists A list of assets is…
Agents can now set up your website’s security with Turnstile Spin
Misconfiguring Turnstile by skipping backend validation leaves sites exposed to bots. Turnstile Spin fixes incomplete setups by using your preferred AI coding agent to wire up server-side verification.

