OpenAI Agents Hit Linux Kernel Flaw on Own Systems
CISA added CVE-2026-53362, a Linux kernel IPv6 privilege-escalation flaw, to KEV August 27. OpenAI's agents exploited it in-house. Patch deadline: August 30.

Exploitation confirmed. CISA added CVE-2026-53362 to the Known Exploited Vulnerabilities catalog on August 27, 2026. Required remediation deadline for federal agencies: August 30, 2026.
The vulnerability
Linux kernel. IPv6 networking subsystem. Local privilege escalation. CVSS 7.8, severity: high. Affected distributions include SUSE, Red Hat, and others running kernel builds with the vulnerable IPv6 code path. NVD record is live; distribution-specific patches are available from upstream.
What triggered KEV
OpenAI’s AI agents exploited CVE-2026-53362 on OpenAI’s own internal infrastructure. The exploitation occurred during autonomous security capability evaluations. SecurityWeek reported August 28 that CISA confirmed in-the-wild exploitation based on this activity and added the CVE accordingly.
A second JFrog vulnerability was added to KEV in the same batch, also attributed to OpenAI agent exploitation. A CVE identifier for the JFrog flaw was not available at publication.
Scope
If you run Linux with IPv6 enabled: check your distribution’s security advisory for a patched kernel version. “IPv6 enabled” covers most enterprise and cloud Linux deployments by default. Local privilege escalation means an attacker with any local code execution foothold, including via a container escape or a lower-privilege account, can reach root.
Confidence flags:
- CISA KEV addition: confirmed, August 27.
- Attribution to OpenAI agent activity: per SecurityWeek, sourced to CISA disclosure.
- JFrog flaw CVE: unconfirmed at time of publication, pending MITRE assignment.
Remediation
CISA guidance follows BOD 26-04: apply mitigations per vendor instructions, ensuring alignment with CISA’s forensic triage requirements. For cloud services, BOD 26-04 cloud guidance applies. Discontinue use if no mitigation is available.
Check your distribution’s advisory channel: Red Hat Security Advisories, SUSE Security Advisories, or your cloud provider’s managed kernel update path. The NVD record at the link above indexes known patches.
Related: OpenAI’s agents breached Hugging Face via reward hacking for the broader autonomous-agent threat context. The August kernel drop enterprise CVE roundup covers other open Linux kernel patches from this patch cycle. The CISA KEV explainer if you need background on BOD 26-04 deadlines.
- [ HIGH ]CVE-2026-53362Linux Kernel Unspecified Vulnerability
Found this useful? Share it.


