Executive Summary
On June 2, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2022-0492, a Linux Kernel Improper Authentication Vulnerability, and CVE-2025-48595, an Android Framework Integer Overflow Vulnerability. Both vulnerabilities are actively exploited, posing significant risks to federal enterprises. CVE-2022-0492 allows unauthorized access to Linux systems, while CVE-2025-48595 enables local privilege escalation on Android devices without user interaction. (nvd.nist.gov)
The inclusion of these vulnerabilities in the KEV Catalog underscores the critical need for organizations to promptly address known security flaws. With active exploitation in the wild, timely remediation is essential to mitigate potential threats and protect sensitive information.
Why This Matters Now
The active exploitation of CVE-2022-0492 and CVE-2025-48595 highlights the urgency for organizations to patch these vulnerabilities immediately. Delayed remediation increases the risk of unauthorized access and data breaches, emphasizing the importance of proactive vulnerability management.
Attack Path Analysis
An attacker exploits CVE-2022-0492 to gain unauthorized access to a Linux system. They escalate privileges by leveraging the cgroups v1 release_agent feature, allowing them to execute arbitrary code with elevated permissions. The attacker moves laterally within the network by exploiting the compromised system to access other connected devices. They establish command and control by setting up a persistent backdoor for remote access. Sensitive data is exfiltrated from the compromised systems to an external server. Finally, the attacker deploys ransomware to encrypt critical files, demanding payment for decryption.
Kill Chain Progression
Initial Compromise
Description
The attacker exploits CVE-2022-0492, a vulnerability in the Linux kernel's cgroup_release_agent_write function, to gain unauthorized access to the system.
Related CVEs
CVE-2022-0492
CVSS 7.8A vulnerability in the Linux kernel's cgroup_release_agent_write function allows privilege escalation and bypassing namespace isolation.
Affected Products:
Red Hat Enterprise Linux – 8.0
Red Hat Enterprise Linux EUS – 8.2
Red Hat Virtualization Host – 4.0
Exploit Status:
exploited in the wildCVE-2025-48595
CVSS 8.4An integer overflow in multiple locations of the Android Framework allows local escalation of privilege without user interaction.
Affected Products:
Google Android – 14.0, 15.0, 16.0
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploitation for Privilege Escalation
Hardware Additions
Valid Accounts
Exploitation of Remote Services
Hijack Execution Flow
Abuse Elevation Control Mechanism
Process Injection
Endpoint Denial of Service
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Asset Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Federal agencies face mandatory remediation under BOD 22-01 for Linux kernel and Android vulnerabilities enabling privilege escalation and lateral movement attacks.
Information Technology/IT
Critical exposure through widespread Linux infrastructure and Android device management, requiring immediate patching of authentication bypass and integer overflow vulnerabilities.
Telecommunications
High risk from Linux-based network infrastructure and Android devices, vulnerable to exploitation enabling encrypted traffic interception and command control establishment.
Financial Services
Severe compliance implications under PCI DSS and regulatory frameworks, with Android banking apps and Linux servers vulnerable to data exfiltration attacks.
Sources
- CISA Adds Two Known Exploited Vulnerabilities to Cataloghttps://www.cisa.gov/news-events/alerts/2026/06/02/cisa-adds-two-known-exploited-vulnerabilities-catalogVerified
- NVD - CVE-2022-0492https://nvd.nist.gov/vuln/detail/CVE-2022-0492Verified
- NVD - CVE-2025-48595https://nvd.nist.gov/vuln/detail/CVE-2025-48595Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it embeds security directly into the cloud fabric, potentially limiting the attacker's ability to move laterally and exfiltrate data.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF may not prevent the initial exploitation, it could limit the attacker's ability to leverage the compromised system to access other network segments.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation could limit the attacker's ability to exploit elevated privileges to access other workloads or sensitive data.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security could constrain the attacker's ability to move laterally by enforcing strict controls on internal traffic flows.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control could detect and potentially disrupt unauthorized command and control communications.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement could limit the attacker's ability to exfiltrate data by controlling outbound traffic.
While Aviatrix CNSF may not prevent the deployment of ransomware, its segmentation and traffic controls could limit the spread and impact of such attacks.
Impact at a Glance
Affected Business Functions
- System Administration
- User Access Management
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of sensitive system configurations and user credentials.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within the network.
- • Deploy Inline IPS (Suricata) to detect and prevent exploitation attempts of known vulnerabilities.
- • Utilize Threat Detection & Anomaly Response systems to identify and respond to unusual activities promptly.
- • Enforce Egress Security & Policy Enforcement to control outbound traffic and prevent data exfiltration.
- • Regularly update and patch systems to mitigate known vulnerabilities like CVE-2022-0492.



