Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    K
    The Goat's Weekly

    Medical Device Cybersecurity News: Week of Monday, August 31, 2026

    CISA has added two high-severity Linux kernel vulnerabilities, CVE-2026-53362 and CVE-2022-0995, to the Known Exploited Vulnerabilities catalog.

    Hero image for Medical Device Cybersecurity News: Week of Monday, August 31, 2026
    Week of August 31, 2026 · The Goat's Weekly
    On this page

    In this issue

    • FDA & US regulatory

      Letters, guidance, enforcement

    • CISA KEV & CVEs

      Vulnerabilities in your SBOM

    • Standards & international

      AAMI, ISO, IEC, EU MDCG

    • What to do this week

      Concrete actions for security leads

    4 min read810 words

    Key Takeaways

    • CISA added CVE-2026-53362 to the KEV catalog, involving a Linux kernel networking function bug.
    • CVE-2022-0995, an out-of-bounds write vulnerability, is also confirmed to be under active exploitation.
    • Both vulnerabilities carry a CVSS 3.1 score of 7.8 (High).
    • The FDA expects immediate patching or mitigation for vulnerabilities listed in the CISA KEV.
    • Class II and III connected devices using Linux for data transmission are at the highest risk.
    Direct Answer

    CISA has added two high-severity Linux kernel vulnerabilities, CVE-2026-53362 and CVE-2022-0995, to the Known Exploited Vulnerabilities catalog. Manufacturers must immediately audit their software bills of materials to identify these flaws in Linux-based Class II and III medical devices to meet the FDA expectations for postmarket risk management.

    The cybersecurity landscape for medical device manufacturers has shifted this week with a specific focus on the Linux kernel. CISA identified two distinct vulnerabilities currently under active exploitation. These flaws involve memory corruption and out-of-bounds write capabilities, which present direct risks to device integrity and patient safety.

    Manufacturers using Linux distributions for data transmission, diagnostic imaging, or surgical robotics must take notice. Because these vulnerabilities are now part of the CISA Known Exploited Vulnerabilities (KEV) catalog, the FDA considers them high-priority items that require a formal response plan and potential patching to maintain compliance with postmarket cybersecurity requirements.

    In this brief

    Why This Matters

    For medical device manufacturers, a KEV listing serves as a regulatory trigger. The FDA views active exploitation as a significant increase in the "likelihood of occurrence" for a cyberattack. If your device uses an unpatched Linux kernel, you may be out of compliance with the FD&C Act Section 524B, which requires manufacturers to provide a plan to monitor, identify, and address postmarket vulnerabilities.

    Linux Kernel CVE-2026-53362 Added to CISA KEV

    Critical

    CISA has officially listed CVE-2026-53362 in the KEV catalog.

    Active Exploitation of Linux Kernel Out-of-Bounds Write CVE-2022-0995

    Critical

    CISA also added CVE-2022-0995 to the KEV catalog, noting that this memory corruption flaw is being used to bypass standard system permissions.

    ## What to do this week * Run an automated scan of your current SBOMs to identify any Linux kernel versions affected by CVE-2026-53362 or CVE-2022-0995. * Cross-reference your vulnerability disclosure policy (VDP) to ensure you have a mechanism to report these specific KEV findings to your end users. * Draft a technical bulletin for hospital IT staff if your devices require a manual firmware update to resolve these kernel flaws.

    How Blue Goat Cyber Helps

    Blue Goat Cyber assists medical device manufacturers in navigating complex regulatory requirements through detailed penetration testing and SBOM analysis. Our team, led by experts like Christian Espinosa, helps you identify KEV vulnerabilities and develop the documentation the FDA requires for postmarket submissions. Find more details on our services page.

    FAQ

    Get the next issue

    Stay informed on the latest regulatory updates and security threats by subscribing to Goat's Weekly.

    Ready when you are

    Get FDA cleared without the cybersecurity headaches.

    30-minute strategy session. No cost, no commitment - just answers from people who've shipped 250+ FDA submissions.