Our automated tracking framework flagged that CISA added CVE-2022-0995 (Linux Kernel) to the Known Exploited Vulnerabilities (KEV) catalog on August 31, 2026. A KEV listing is CISA’s official confirmation that the flaw is being exploited in the wild — U.S. federal agencies must patch it by a fixed deadline. Here is what our data shows.
What CISA Reported
CISA describes the flaw as follows: “Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system.”
Under Binding Operational Directive rules, U.S. federal agencies must remediate CVE-2022-0995 by September 9, 2026 — a 14-day window. Private organizations are not bound by the deadline, but CISA treats it as the benchmark for how urgently a confirmed-exploited flaw should be patched.
The Details
| CVE | CVE-2022-0995 |
| Vendor / product | Linux Kernel |
| Vulnerability | Linux Kernel Out-of-Bounds Write Vulnerability |
| CVSS base score | 7.8 |
| Added to KEV | August 26, 2026 |
| Days public before listing (NVD → KEV lag) | 1615 |
| Federal patch deadline | September 9, 2026 |
| Known ransomware use | No |
How This Compares to Linux’s Track Record
This one was public for 1615 days before CISA confirmed exploitation — longer than Linux’s 848-day median, a vulnerability that sat exploitable in the open. Linux currently ranks #14 on our KEV Lag leaderboard.
| Linux in the CISA KEV catalog | Value |
|---|---|
| Tracked KEV entries | 28 |
| Median lag (public → KEV listing) | 848 days |
| 0-day rate (exploited at or before disclosure) | 0% |
| Entries tied to known ransomware campaigns | 2 |
For perspective, the median across all 1684 tracked KEV entries is 267 days — Linux’s exploited vulnerabilities are flagged slower than the catalog average.
Other Recent Linux KEV Additions
The most recent Linux vulnerabilities CISA has confirmed as actively exploited, from our tracker:
| CVE | Product | Added to KEV | Lag (days) | Ransomware |
|---|---|---|---|---|
| CVE-2026-53362 | Kernel | August 27, 2026 | 54 | No |
| CVE-2022-0492 | Kernel | June 2, 2026 | 1552 | No |
| CVE-2026-31431 | Kernel | May 1, 2026 | 9 | No |
| CVE-2018-14634 | Kernel | January 26, 2026 | 2680 | No |
| CVE-2021-22555 | Kernel | October 6, 2025 | 1552 | No |
Defense guide: How to Detect DDoS Attack: Warning Signs & Defense Playbook — detection signals, attack chain and response steps for this class of attack.
What This Means for Defenders
CISA has added CVE-2022-0995, a Linux Kernel Out-of-Bounds Write Vulnerability, to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies patch by September 9, 2026. With a CVSS base score of 7.8, this vulnerability presents a significant risk, particularly for organizations heavily reliant on Linux-based infrastructure. The critical nature of a kernel-level flaw means successful exploitation could lead to arbitrary code execution or denial of service, making immediate patching a high priority for systems directly exposed to potential attackers.
The listing of CVE-2022-0995 comes 1615 days after its public disclosure, a considerable delay compared to the historical median lag of 848 days for Linux vulnerabilities added to the KEV catalog. This extended lag suggests that exploitation may have been ongoing for a significant period before CISA’s official recognition, narrowing the detection window for many organizations. While there is no known ransomware use associated with this CVE, its inclusion in the KEV catalog confirms active exploitation in the wild, underscoring the urgency for all security teams.
Organizations with Linux Kernel deployments should prioritize patching CVE-2022-0995 immediately to mitigate risk. For systems where the patch cannot be applied before the federal deadline, implementing compensating controls is crucial. This may include isolating affected systems, applying strict network segmentation, monitoring for unusual activity on Linux hosts, and ensuring robust endpoint detection and response (EDR) solutions are in place to detect potential exploitation attempts. Regular vulnerability scanning and threat hunting can also help identify and address any pre-existing compromise.
Related Coverage
- Linux’s CVE-2026-53362 Was Exploited in 54 Days — Faster Than Its 848-Day Median (August 2026)
- Critical Microsoft SharePoint Flaw CVE-2026-50522 (CVSS 9.8) Added to CISA KEV (July 2026)
How We Track This
This report was generated from our CISA KEV Lag Tracker, which syncs the official CISA KEV catalog daily and records the date each CVE is added. For every entry we retrieve the original NVD publication date and compute the lag in calendar days. No dates or figures on this page are estimated or taken from third-party sources — they come directly from CISA and NVD records.