News
CAPACITY TEST:

CISA Android and Linux Warnings Put Patch Timing Back on the Security Agenda

Newsroom brief

CISA added exploited Android and Linux vulnerabilities to its Known Exploited Vulnerabilities catalog. The Android flaw affects Android 14 through 16, while the Linux issue centers on older kernel branches and cgroups v1 container environments. The immediate test is whether agencies and infrastructure operators apply vendor updates or mitigations by CISA's June 5 deadline.

Verified against source materialEdited by SendTech Times Cybersecurity Desk
CISA Android and Linux Warnings Put Patch Timing Back on the Security Agenda
Image source: BleepingComputer

CISA Adds Two Exploited Bugs to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, putting Android and Linux patch timing back in focus for agencies and large infrastructure operators.

The Android entry, CVE-2025-48595, is a high-severity integer overflow vulnerability in the Android Framework.

Google's security bulletin says the issue affects Android 14 through 16 and requires no user interaction to exploit.

Google said the flaw may be under limited targeted exploitation in the wild, but did not provide incident details or technical information about the activity.

Google addressed the Android issue in the June 2026 security patch levels dated 2026-06-01 and 2026-06-05.

For security teams, the practical risk is privilege escalation without user interaction, which raises the value of timely device patching and fleet-level update checks.

Linux Container Risk Centers on Privilege Escalation

The second KEV addition, CVE-2022-0492, is a high-severity privilege escalation flaw in older Linux kernel branches.

The vulnerable path sits in the cgroupreleaseagent_write() function of the cgroups v1 subsystem.

Cgroups, or control groups, are a Linux mechanism for limiting and organizing process resources; the flaw can let a local attacker cross namespace boundaries, gain higher privileges and move from a container toward root-level control of the host system.

Aqua Security and Palo Alto Networks previously linked the issue primarily to containerized environments using cgroups v1, especially when containers are granted elevated capabilities.

That makes the patch decision more than a server-maintenance item for organizations running container workloads.

The reader-risk control is straightforward: apply vendor-provided updates or mitigations, and review container privilege settings where cgroups v1 remains in use.

Deadline Creates the Operational Signal

CISA's KEV listing requires federal agencies covered by the BOD 22-01 directive to apply vendor-provided security updates and mitigations, or stop using the affected software.

CISA set the deadline for June 5.

The catalog also functions as a warning board for critical infrastructure entities and large organizations outside the federal mandate.

Neither vulnerability is marked as exploited by ransomware groups in CISA's entries, but the active-exploitation status is enough to move these bugs from routine vulnerability tracking into near-term remediation planning.

The next signal is whether device and Linux-container operators can close the patch gap before the vulnerabilities become broader operational risk.

Share this article
inXf

Related articles

More
CISA WebLogic Warning Turns Oracle Patch Lag Into an Exposure Test
Cybersecurity

CISA WebLogic Warning Turns Oracle Patch Lag Into an Exposure Test

CISA ordered U.S. federal agencies to patch Oracle WebLogic Server systems affected by CVE-2024-21182 after active exploitation was observed. Shodan tracks more than 1,592 exposed WebLogic servers vulnerable to the flaw, including 961 on version 12.2.1.4.0 and 631 on version 14.1.1.0.0. The immediate test is whether public- and private-sector defenders apply Oracle fixes or remove exposed systems where mitigations are unavailable.

IPA Translation Turns CISA Security Goals Into A Japan Infrastructure Baseline
Cybersecurity

IPA Translation Turns CISA Security Goals Into A Japan Infrastructure Baseline

Japan’s Information-technology Promotion Agency published a Japanese translation of CISA’s Cross-Sector Cybersecurity Performance Goals Version 2.0 for domestic critical infrastructure operators. The guidance covers IT and operational technology, maps goals to NIST CSF 2.0, and frames the controls as minimum practices rather than a full cybersecurity program. The practical question is whether asset owners use the worksheet to rank gaps by cost, complexity and impact, then review progress after 12 months.

Palo Alto Sell-Off Shows AI Cybersecurity Demand Still Has a Timing Problem
Cybersecurity

Palo Alto Sell-Off Shows AI Cybersecurity Demand Still Has a Timing Problem

Palo Alto Networks shares fell more than 4% after stronger quarterly results and current-quarter guidance failed to satisfy investors looking for faster AI-linked earnings upside. CEO Nikesh Arora reiterated a fiscal 2030 target of more than 4,000 platformizations and a USD 20 billion NGS ARR goal. The practical question is whether AI-related security demand turns into NGS ARR progress as data center infrastructure is ordered, installed and brought online.

Bad Epoll Linux Flaw Reaches Android Without A Public Patch Timetable
Cybersecurity

Bad Epoll Linux Flaw Reaches Android Without A Public Patch Timetable

A newly disclosed Linux kernel flaw tracked as CVE-2026-46242 can let an unprivileged local user gain root access on Linux systems and may be reachable from Android or Chrome sandbox contexts, but public material did not give a distribution-by-distribution patch timetable.

NFSP Ransomware Attack Turns Supplier Email Pause Into a Security-Control Test
Cybersecurity

NFSP Ransomware Attack Turns Supplier Email Pause Into a Security-Control Test

The National Federation of Subpostmasters was hit by ransomware after a cPanel-related hosting software bug was exploited. The NFSP was targeted on 30 April, and the Post Office paused some email interactions with the federation while saying branch operations were not affected. The immediate test is whether trusted communications can resume without pushing subpostmasters toward insecure workaround channels.

Cisco Unified CM Flaw Puts WebDialer Exposure Under Patch Pressure
Cybersecurity

Cisco Unified CM Flaw Puts WebDialer Exposure Under Patch Pressure

Cisco disclosed fixed-release guidance for a critical Unified Communications Manager flaw that can let attackers gain root privileges when WebDialer is enabled. Cisco PSIRT is aware of public proof-of-concept exploit code for CVE-2026-20230, though it has not found active exploitation or targeting. The immediate test is whether administrators patch Unified CM or disable WebDialer before proof-of-concept code turns into wider exposure.

Keep Reading

More Stories

Latest
Coratia Gets Rs 66 Crore Navy Order For Underwater RobotsCapital & PolicyJul 21, 2026Coratia Gets Rs 66 Crore Navy Order For Underwater RobotsYourStory reported that Coratia Technologies has a Rs 66 crore Indian Navy contract for indigenous underwater ROVs, moving the Odisha startup from inspection prototypes toward defence delivery.Finland Data Centre Growth Faces Grid And Heat-Reuse TestsCloud & Data CentersJul 20, 2026Finland Data Centre Growth Faces Grid And Heat-Reuse TestsFinland is attracting AI data centre projects because of low-carbon power, cool weather and land, Data Center Knowledge reported, but grid connections, permitting and waste-heat rules now determine how much capacity becomes operational.Bank Of Korea Expands CBDC Pilot To Nine Banks In SeptemberFintech & Digital PaymentsJul 20, 2026Bank Of Korea Expands CBDC Pilot To Nine Banks In SeptemberCoinDesk reported that the Bank of Korea will move its CBDC programme into September real-transaction testing with nine participating banks, using BOK infrastructure while lenders issue and manage deposit tokens.SAP Closes Prior Labs Deal For Tabular AI ModelsAIJul 20, 2026SAP Closes Prior Labs Deal For Tabular AI ModelsSAP has closed its Prior Labs acquisition and committed more than EUR1 billion over four years to a Freiburg AI lab whose models work on structured business data rather than general chatbot content.Google DeepMind Sets AI Bioresilience Work Around 15-Plus PartnershipsAIJul 20, 2026Google DeepMind Sets AI Bioresilience Work Around 15-Plus PartnershipsGoogle DeepMind and Isomorphic Labs have outlined an AI bioresilience programme with more than 15 partners, framing biological AI safety around prevention, outbreak detection and medical response.Sateliot Seeks €150 Million For Satellite-To-Phone 5G By 2028Telco & ConnectivityJul 20, 2026Sateliot Seeks €150 Million For Satellite-To-Phone 5G By 2028Sateliot is seeking up to EUR150 million to expand from satellite IoT links toward direct-to-smartphone 5G service, with 16 more low-Earth orbit satellites planned before larger spacecraft in 2028.Raidium Launches AI Radiology Viewer At Moffitt Before FDA ClearanceAIJul 20, 2026Raidium Launches AI Radiology Viewer At Moffitt Before FDA ClearanceRaidium Read is being used at Moffitt Cancer Center for research and clinical trials before FDA 510(k) clearance, making the US launch a workflow test rather than a fully cleared commercial rollout.Denmark Grid Plan Gives Hospitals Priority Over DatacentresCapital & PolicyJul 20, 2026Denmark Grid Plan Gives Hospitals Priority Over DatacentresDenmark's emergency grid proposal would move hospitals, defence and emergency services ahead of most datacentre projects in the electricity-connection queue as applications rise far beyond peak national load.Fake GitHub Repositories Turned Developer Trust Into BoryptGrab Delivery ChainCybersecurityJul 20, 2026Fake GitHub Repositories Turned Developer Trust Into BoryptGrab Delivery ChainDeveloperTech's article on Arctic Wolf Labs research describes a fake-repository campaign that used polished GitHub project pages as a delivery route for BoryptGrab malware. The case makes artifact provenance and workstation controls more important than visual trust in repository pages.IBM Research Tests Agent Routing On Cost, Latency And AccuracyAIJul 20, 2026IBM Research Tests Agent Routing On Cost, Latency And AccuracyA Hugging Face post from IBM Research said model routing for enterprise AI agents should optimise cost, quality and latency together after AppWorld tests reversed a simple token-price comparison.IBM Study Finds UAE AI Vendor Switching RiskCapital & PolicyJul 20, 2026IBM Study Finds UAE AI Vendor Switching RiskMiddle East AI News, citing IBM Institute for Business Value data, said 88 per cent of surveyed UAE executives would struggle to switch their primary AI vendor or model, while 96 per cent did not fully understand dependencies across vendors, models and infrastructure.Regions Bank Digital Transactions Reach 80% After Mobile UpgradeFintech & Digital PaymentsJul 19, 2026Regions Bank Digital Transactions Reach 80% After Mobile UpgradePYMNTS reported that Regions Bank’s second-quarter materials listed digital transactions at 80% of customer activity, with mobile users, logins, Zelle usage and chat volume rising as core modernisation continues.