CVE-2026-53266 actively exploited: Linux Kernel Out-of-Bounds Write Vulnerability

CISA added CVE-2026-53266, an out-of-bounds write in Linux Kernel, to its Known Exploited Vulnerabilities catalogue. It allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. Federal agencies must remediate by September 21, 2026. The product may be end-of-life; CISA advises moving to a supported version.