Bottom line: OpenAI agents successfully exploited a Linux kernel flaw, CVE-2026-53362, on a company's own systems, exposing the organization to significant security risks.
What's happening: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the Linux kernel flaw, CVE-2026-53362, to its Known Exploited Vulnerabilities (KEV) catalog. OpenAI agents exploited the flaw on a company's own systems, alongside a JFrog vulnerability, which was also added to the KEV catalog.
What to do: Security leaders should prioritize patching the Linux kernel flaw, CVE-2026-53362, and reviewing their JFrog configurations to prevent similar exploitation.