Treasury
3-MO 4.14% +2bp 6-MO 4.24% +4bp 1-YR 4.44% +4bp 2-YR 4.76% +9bp 3-YR 4.83% +8bp 5-YR 4.86% +8bp 7-YR 4.93% +7bp 10-YR 5.01% +7bp 20-YR 5.38% +6bp 30-YR 5.34% +5bp 3-MO 4.14% +2bp 6-MO 4.24% +4bp 1-YR 4.44% +4bp 2-YR 4.76% +9bp 3-YR 4.83% +8bp 5-YR 4.86% +8bp 7-YR 4.93% +7bp 10-YR 5.01% +7bp 20-YR 5.38% +6bp 30-YR 5.34% +5bp 3-MO 4.14% +2bp 6-MO 4.24% +4bp 1-YR 4.44% +4bp 2-YR 4.76% +9bp 3-YR 4.83% +8bp 5-YR 4.86% +8bp 7-YR 4.93% +7bp 10-YR 5.01% +7bp 20-YR 5.38% +6bp 30-YR 5.34% +5bp 3-MO 4.14% +2bp 6-MO 4.24% +4bp 1-YR 4.44% +4bp 2-YR 4.76% +9bp 3-YR 4.83% +8bp 5-YR 4.86% +8bp 7-YR 4.93% +7bp 10-YR 5.01% +7bp 20-YR 5.38% +6bp 30-YR 5.34% +5bp 3-MO 4.14% +2bp 6-MO 4.24% +4bp 1-YR 4.44% +4bp 2-YR 4.76% +9bp 3-YR 4.83% +8bp 5-YR 4.86% +8bp 7-YR 4.93% +7bp 10-YR 5.01% +7bp 20-YR 5.38% +6bp 30-YR 5.34% +5bp 3-MO 4.14% +2bp 6-MO 4.24% +4bp 1-YR 4.44% +4bp 2-YR 4.76% +9bp 3-YR 4.83% +8bp 5-YR 4.86% +8bp 7-YR 4.93% +7bp 10-YR 5.01% +7bp 20-YR 5.38% +6bp 30-YR 5.34% +5bp
US Treasury par yield curve · Sep 18 · Source: U.S. Treasury
Saturday, September 19, 2026
U.S. Edition
Federal cybersecurity

CISA gives agencies until Monday to address three exploited Linux kernel flaws

The Department of Homeland Security headquarters at the St. Elizabeths campus in Washington.
Photo: Tia Duffour / Wikimedia Commons (Public domain)

Three Linux kernel flaws entered CISA's Known Exploited Vulnerabilities Catalog Friday, with a federal remediation deadline of Monday, September 21.

The entries are CVE-2025-39682 in the kernel's TLS receive path, CVE-2026-53266 in the ebtables SNAT target and CVE-2025-39964 in AF_ALG sockets.

That deadline is close.

Under Binding Operational Directive 26-04, civilian executive branch agencies must apply vendor mitigations to affected systems. If mitigations are unavailable, the catalog says to discontinue use of the product.

CISA requires forensic triage for all three vulnerabilities. It lists known ransomware campaign use as unknown for each one.