2026-09-19
This weekNew web3 security vulnerability disclosures and CVEs in the last 48 hours
In the past 48 hours, several critical vulnerabilities affecting key blockchain and cryptocurrency infrastructure have been disclosed. Notable among them are multiple Linux kernel flaws that impact sm…
RESEARCH: New web3 security vulnerability disclosures and CVEs in the last 48 hours
RESEARCH: New Web3 Security Vulnerability Disclosures and CVEs (Last 48 Hours)
Summary
In the past 48 hours, several critical vulnerabilities affecting key blockchain and cryptocurrency infrastructure have been disclosed. Notable among them are multiple Linux kernel flaws that impact smart‑contract nodes and decentralized applications (DApps), as well as an incorrect default permissions issue in Acronis Backup plugins used by many Web3 service providers. These disclosures highlight ongoing risks to the integrity of public blockchains and private enterprise blockchain deployments, prompting urgent patching and configuration reviews across the ecosystem.
Key Developments
Linux Kernel Vulnerabilities
- CVE‑2025‑39682: An improper check for unusual or exceptional conditions in the TLS receive path can allow zero‑length records to bypass intended handling, potentially leading to incorrect processing of subsequent TLS records. Affected protocols include HTTPS and other encrypted communication used by many Web3 nodes. CISA KEV Catalog
- CVE‑2026‑53266: An out‑of‑bounds write vulnerability in the ebtables SNAT target permits ARP sender hardware address rewrites to write directly into a nonlinear socket‑buffer fragment, posing a risk to networked blockchain nodes. CISA KEV Catalog
- CVE‑2025‑39964: A race condition in AF_ALG sockets allows concurrent writes that can interleave data unpredictably, threatening the reliability of cryptographic operations within DApps. CISA KEV Catalog
Acronis Backup Plugin Vulnerability
- CVE‑2026‑87886: Incorrect default permissions in the Acronis Backup plugin for cPanel & WHM and Plesk extension could enable privilege escalation, impacting backup operations used by many Web3 services to safeguard on‑chain data. CISA KEV Catalog
Tooling Updates
- Tools such as Qualys, Tenable, and Trivy continue to enhance code scanning capabilities, while Wiz, Sysdig, and Aqua add runtime checks. These enhancements aim to detect the above vulnerabilities across Web3 deployments. LinkedIn Post by Ashish P.
Sources
- CISA Known Exploited Vulnerabilities Catalog – CVE‑2025‑39682
- CISA Known Exploited Vulnerabilities Catalog – CVE‑2026‑53266
- CISA Known Exploited Vulnerabilities Catalog – CVE‑2025‑39964
- CISA Known Exploited Vulnerabilities Catalog – CVE‑2026‑87886
- LinkedIn Post on Web3 Security Tooling Updates by Ashish P.