IC Technology & Surveillance — 2026-05-02

CISA Adds Linux Copy Fail Kernel Vulnerability to Known Exploited Vulnerabilities Catalog

CISA added CVE-2026-31431 to its Known Exploited Vulnerabilities catalog on May 1, based on evidence of active exploitation, designating it a Linux kernel "Incorrect Resource Transfer Between Spheres" vulnerability. Microsoft's Security Blog, which reported on the flaw, identified it as "Copy Fail" and described it as enabling root privilege escalation across Linux cloud environments. Binding Operational Directive 22-01 requires Federal Civilian Executive Branch agencies to remediate by the catalog-specified due date; CISA separately urged all organizations to prioritize remediation.

Analysis
Working exploit code is already deployed: CISA's KEV designation, corroborated by Microsoft's Security Blog, confirms active in-the-wild exploitation. Root-level access at the kernel layer carries multiplied consequence in shared cloud environments, where a single compromised host can expose workloads across tenants or agency components simultaneously. At least one FCEB agency is likely to miss the May 15 remediation deadline, driven by coordination overhead for kernel patching across distributed infrastructure and persistent gaps in BOD 22-01 patch velocity. The exploitation may be narrower than the KEV designation implies, targeting a specific kernel version or cloud configuration, which would overstate the breadth of federal exposure.
4 sources
  1. CISA Adds One Known Exploited Vulnerability to Catalog
  2. CVE-2026-31431: Copy Fail vulnerability enables Linux root privilege escalation across cloud environments - Microsoft Security Blog
  3. U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog - Security Affairs
  4. CISA adds critical Microsoft Office, Linux Kernel, and SmarterMail vulnerabilities to KEV catalog - SC Media

View in full brief →

UNCLASSIFIED // OPEN SOURCE