All KEV additions

CISA KEV digest

CISA KEV 02 Jun 2026: 2 exploited flaws in Linux and Android

2 vulnerabilities
Conceptual illustration: A workstation motherboard, floating abstract operating-system window and lime patch tile. Headline: OPERATING SYSTEMS.

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.

On 2 June 2026, CISA added 2 actively exploited vulnerabilities affecting Linux, Android to its Known Exploited Vulnerabilities catalog. If you run any of these products, patch or mitigate now — exploitation is already happening.

CVE-2022-0492Federal deadline

In this section

Linux Kernel Improper Authentication Vulnerability

Linux / Kernel / CWE-287, CWE-862

Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-48595Federal deadline

Android Framework Integer Overflow Vulnerability

Android / Framework / CWE-190

Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.