On this page
In this issue
-
FDA & US regulatory
Letters, guidance, enforcement
-
CISA KEV & CVEs
Vulnerabilities in your SBOM
-
Standards & international
AAMI, ISO, IEC, EU MDCG
-
What to do this week
Concrete actions for security leads
Key Takeaways
- CISA added CVE-2026-53362 to the KEV catalog, involving a Linux kernel networking function bug.
- CVE-2022-0995, an out-of-bounds write vulnerability, is also confirmed to be under active exploitation.
- Both vulnerabilities carry a CVSS 3.1 score of 7.8 (High).
- The FDA expects immediate patching or mitigation for vulnerabilities listed in the CISA KEV.
- Class II and III connected devices using Linux for data transmission are at the highest risk.
CISA has added two high-severity Linux kernel vulnerabilities, CVE-2026-53362 and CVE-2022-0995, to the Known Exploited Vulnerabilities catalog. Manufacturers must immediately audit their software bills of materials to identify these flaws in Linux-based Class II and III medical devices to meet the FDA expectations for postmarket risk management.
The cybersecurity landscape for medical device manufacturers has shifted this week with a specific focus on the Linux kernel. CISA identified two distinct vulnerabilities currently under active exploitation. These flaws involve memory corruption and out-of-bounds write capabilities, which present direct risks to device integrity and patient safety.
Manufacturers using Linux distributions for data transmission, diagnostic imaging, or surgical robotics must take notice. Because these vulnerabilities are now part of the CISA Known Exploited Vulnerabilities (KEV) catalog, the FDA considers them high-priority items that require a formal response plan and potential patching to maintain compliance with postmarket cybersecurity requirements.
In this brief
- Why This Matters
- Linux Kernel CVE-2026-53362 Added to CISA KEV
- Active Exploitation of Linux Kernel Out-of-Bounds Write CVE-2022-0995
- What to do this week
- How Blue Goat Cyber Helps
- FAQ
Why This Matters
For medical device manufacturers, a KEV listing serves as a regulatory trigger. The FDA views active exploitation as a significant increase in the "likelihood of occurrence" for a cyberattack. If your device uses an unpatched Linux kernel, you may be out of compliance with the FD&C Act Section 524B, which requires manufacturers to provide a plan to monitor, identify, and address postmarket vulnerabilities.
Linux Kernel CVE-2026-53362 Added to CISA KEV
CISA has officially listed CVE-2026-53362 in the KEV catalog.
Active Exploitation of Linux Kernel Out-of-Bounds Write CVE-2022-0995
CISA also added CVE-2022-0995 to the KEV catalog, noting that this memory corruption flaw is being used to bypass standard system permissions.
How Blue Goat Cyber Helps
Blue Goat Cyber assists medical device manufacturers in navigating complex regulatory requirements through detailed penetration testing and SBOM analysis. Our team, led by experts like Christian Espinosa, helps you identify KEV vulnerabilities and develop the documentation the FDA requires for postmarket submissions. Find more details on our services page.
FAQ
Get the next issue
Stay informed on the latest regulatory updates and security threats by subscribing to Goat's Weekly.
