Our Blog

Cybersecurity SOC dashboard comparing CVSS vulnerability severity with EPSS and CISA KEV exploitation signals, highlighting flawed vulnerability prioritisation models

Weekly CISA KEV Updates: 28 September 2026 - Twelve New Known Exploited Vulnerabilities Added

 

Audience: Vulnerability Managers, Security Operations, CISOs, DevSecOps Teams
Reading Time: Approximately 10 minutes

 

This Week's KEV Additions

CVE ID Vendor / Product CVSS Date Added CISA Due Date Exploitation Type EPSS Score Reachability
CVE-2026-88772 Citrix NetScaler ADC and NetScaler Gateway 9.8 (Critical) 2026-09-27 2026-10-18 Improper restriction of operations within the bounds of a memory buffer

Pending

N (Network)
CVE-2026-88771 Citrix NetScaler ADC and NetScaler Gateway 9.8 (Critical) 2026-09-27 2026-10-18 Improper input validation

Pending

N (Network)
CVE-2026-67279 MikroTik RouterOS 6.5 (Medium) 2026-09-25 2026-10-16 Improper enforcement of behavioral workflow

1.027%

N (Network)
CVE-2026-65660 Microsoft SharePoint 8.8 (High) 2026-09-25 2026-10-16 Code injection

2.101%

N (Network)
CVE-2026-87902 WordPress Core 8.6 (High) 2026-09-25 2026-10-16 Remote file inclusion

18.166%

N (Network)
CVE-2026-5430 WSO2 API Control Plane, Manager, Traffic Manager & Universal Gateway 9.8 (Critical) 2026-09-24 2026-10-15 Path traversal / Unrestricted file upload

0.588%

N (Network)
CVE-2026-71362 Adobe Commerce and Magento 9.8 (Critical) 2026-09-24 2026-10-15 Incorrect authorization

87.507%

N (Network)
CVE-2026-93952 Arista VeloCloud Orchestrator (VCO) 9.8 (Critical) 2026-09-22 2026-10-13 Improper input validation

1.062%

N (Network)
CVE-2026-94127 F5 BIG-IP APM 9.8 (Critical) 2026-09-22 2026-10-13 Heap-based buffer overflow

2.226%

N (Network)
CVE-2026-93616 Check Point Security Management Server 9.8 (Critical) 2026-09-22 2026-10-13 Path traversal

19.654%

N (Network)
CVE-2026-85102 Check Point Security Gateway 9.8 (Critical) 2026-09-22 2026-10-13 Improper certificate validation

0.988%

N (Network)
CVE-2026-7273 Zyxel GS1900 Series Switches 8.8 (High) 2026-09-21 2026-10-12 Stack-based buffer overflow

2.501%

A (Adjacent)

Note: EPSS scores are as published by FIRST.org at time of writing and are not updated after publication; scores change daily.

 

hackerstorm Dynamic Intelligence

Need live data on specific KEVs from this roundup?

Lookup scores, news, poc's, threat intel, vendor advisory status, and exploit vectors in real time.

 

Analysis

 

CVE-2026-88772 — Citrix NetScaler ADC and NetScaler Gateway

  • What it is: An improper restriction of operations within memory buffer bounds vulnerability in Citrix NetScaler ADC and NetScaler Gateway that can allow remote code execution or denial of service.

  • Affected versions: Refer to Citrix security advisory for specific vulnerable builds.

  • Exploitation status: Confirmed exploitation added to CISA KEV catalog.

  • Patch available: Yes, consult vendor advisory for remediation builds.

  • CISA due date: 2026-10-18

  • Operational risk: Compromise of perimeter edge infrastructure, allowing attackers to execute arbitrary code or disrupt critical gateway access.

 

CVE-2026-88771 — Citrix NetScaler ADC and NetScaler Gateway

  • What it is: An improper input validation vulnerability in Citrix NetScaler ADC and NetScaler Gateway permitting unauthenticated attackers to execute arbitrary commands.

  • Affected versions: Refer to Citrix security advisory.

  • Exploitation status: Confirmed exploitation added to CISA KEV catalog.

  • Patch available: Yes, refer to vendor advisory.

  • CISA due date: 2026-10-18

  • Operational risk: Unauthenticated remote code execution on internet-facing edge appliances, leading to full network compromise.

 

CVE-2026-67279 — MikroTik RouterOS

  • What it is: An improper enforcement of behavioral workflow vulnerability in MikroTik RouterOS enabling unauthenticated clients to open a session channel and send execution requests.

  • Affected versions: Refer to MikroTik advisory.

  • Exploitation status: Confirmed exploitation added to CISA KEV catalog.

  • Patch available: Yes, upgrade RouterOS to a patched version.

  • CISA due date: 2026-10-16

  • Operational risk: Unauthorized session establishment and command execution on networking infrastructure.

 

CVE-2026-65660 — Microsoft SharePoint

  • What it is: A code injection vulnerability in Microsoft SharePoint that allows authorized attackers to execute code over a network.

  • Affected versions: Refer to Microsoft security updates.

  • Exploitation status: Confirmed exploitation added to CISA KEV catalog.

  • Patch available: Yes, apply appropriate Microsoft security update.

  • CISA due date: 2026-10-16

  • Operational risk: Compromise of collaboration platforms and internal document repositories.

 

CVE-2026-87902 — WordPress Core

  • What it is: A remote file inclusion vulnerability in WordPress Core allowing unauthenticated attackers to manipulate page-template resolution and include arbitrary local readable .php files.

  • Affected versions: Refer to WordPress security advisories.

  • Exploitation status: Confirmed exploitation added to CISA KEV catalog.

  • Patch available: Yes, update WordPress Core.

  • CISA due date: 2026-10-16

  • Operational risk: Potential code execution and compromise of web application environments.

 

CVE-2026-5430 — WSO2 API Control Plane, Manager, Traffic Manager & Universal Gateway

  • What it is: A path traversal vulnerability in WSO2 API products enabling unrestricted file upload and leading to remote code execution.

  • Affected versions: Refer to WSO2 advisory.

  • Exploitation status: Confirmed exploitation added to CISA KEV catalog.

  • Patch available: Yes, apply fixes from WSO2.

  • CISA due date: 2026-10-15

  • Operational risk: Full compromise of API management infrastructure.

 

CVE-2026-71362 — Adobe Commerce and Magento

  • What it is: An incorrect authorization vulnerability in Adobe Commerce and Magento allowing unauthorized actors to gain elevated access to sensitive resources.

  • Affected versions: Refer to Adobe security bulletin.

  • Exploitation status: Confirmed exploitation added to CISA KEV catalog.

  • Patch available: Yes, apply updates provided by Adobe.

  • CISA due date: 2026-10-15

  • Operational risk: Unauthorized data access and privilege escalation in e-commerce environments.

 

CVE-2026-93952 — Arista VeloCloud Orchestrator (VCO)

  • What it is: An improper input validation vulnerability in Arista VeloCloud Orchestrator on-prem allowing remote attackers to access privileged internal functionality and impact the VCO host.

  • Affected versions: Refer to Arista advisory.

  • Exploitation status: Confirmed exploitation added to CISA KEV catalog.

  • Patch available: Yes, apply vendor patch.

  • CISA due date: 2026-10-13

  • Operational risk: Compromise of SD-WAN management orchestration and control planes.

 

CVE-2026-94127 — F5 BIG-IP APM

  • What it is: A heap-based buffer overflow vulnerability in F5 BIG-IP APM when access policy and OAuth profile are configured.

  • Affected versions: Refer to F5 advisory.

  • Exploitation status: Confirmed exploitation added to CISA KEV catalog.

  • Patch available: Yes, install fixes from F5.

  • CISA due date: 2026-10-13

  • Operational risk: Denial of service or remote code execution on authentication and access gateways.

 

CVE-2026-93616 — Check Point Security Management Server

  • What it is: A path traversal vulnerability in Check Point management and log servers allowing unauthenticated file access.

  • Affected versions: Refer to Check Point advisory.

  • Exploitation status: Confirmed exploitation added to CISA KEV catalog.

  • Patch available: Yes, apply vendor hotfixes.

  • CISA due date: 2026-10-13

  • Operational risk: Compromise of central security management infrastructure.

 

CVE-2026-85102 — Check Point Security Gateway

  • What it is: An improper certificate validation vulnerability in Check Point Security Gateway and Spark Firewall using VPN features.

  • Affected versions: Refer to Check Point advisory.

  • Exploitation status: Confirmed exploitation added to CISA KEV catalog.

  • Patch available: Yes, apply vendor remediation.

  • CISA due date: 2026-10-13

  • Operational risk: Compromise of encrypted VPN tunnels and boundary defenses.

 

CVE-2026-7273 — Zyxel GS1900 Series Switches

  • What it is: A stack-based buffer overflow vulnerability in CGI programs of Zyxel GS1900 switches permitting LAN-based unauthenticated execution.

  • Affected versions: Refer to Zyxel security advisory.

  • Exploitation status: Confirmed exploitation added to CISA KEV catalog.

  • Patch available: Yes, update switch firmware.

  • CISA due date: 2026-10-12

  • Operational risk: Compromise of network switches and localized layer-2 infrastructure.

 

Exploitation Context

This week’s additions to the CISA Known Exploited Vulnerabilities (KEV) catalog highlight an aggressive focus by threat actors on internet-facing network edge devices, remote access gateways, and enterprise security management platforms. Critical infrastructure and perimeter controls—including Citrix NetScaler, Check Point gateways, F5 BIG-IP, and Arista orchestration tools—represent primary targets designed to achieve initial access and persistence within corporate networks.

 

Additionally, enterprise collaboration platforms and e-commerce applications such as Microsoft SharePoint and Adobe Commerce continue to attract active exploitation due to the high density of sensitive data they process. Security teams should prioritize patching based on public exposure and the severe implications of remote code execution across these administrative and boundary components.

 

 

Remediation Priorities

 

Priority CVE ID Recommended Action Timeline
1 CVE-2026-88772 Apply vendor patches immediately to secure Citrix NetScaler ADC and Gateway against RCE. Immediate
2 CVE-2026-88771 Update Citrix NetScaler appliances to remediate unauthenticated command execution risks. Immediate
3 CVE-2026-71362 Apply Adobe Commerce and Magento updates to prevent unauthorized access. Within 24 hours
4 CVE-2026-93616 Apply Check Point security management server patches to block path traversal. Within 24 hours
5 CVE-2026-85102 Update Check Point Security Gateways for proper certificate validation. Within 24 hours
6 CVE-2026-94127 Patch F5 BIG-IP APM to mitigate buffer overflow exposure. Within 24 hours
7 CVE-2026-93952 Update Arista VeloCloud Orchestrator to resolve input validation flaws. Within 24 hours
8 CVE-2026-5430 Apply WSO2 product updates to prevent path traversal and file upload exploitation. Within 72 hours
9 CVE-2026-65660 Apply Microsoft SharePoint security updates to remediate code injection risks. Within 72 hours
10 CVE-2026-87902 Update WordPress Core to patch remote file inclusion vulnerabilities. Within 72 hours
11 CVE-2026-67279 Update MikroTik RouterOS firmware to address workflow enforcement flaws. Within 72 hours
12 CVE-2026-7273 Upgrade Zyxel GS1900 series switch firmware to patch buffer overflow vulnerabilities. By CISA due date

 

 

Detection and Monitoring Guidance

 

  • CVE-2026-88772 (Citrix):

    • Log Sources: Citrix ADC/Gateway HTTP access logs, system error logs, core dump monitors.

    • Behavioral Indicators: Abnormal memory usage patterns, unexpected process terminations, or unexpected child processes spawned by gateway services.

    • Monitoring Gap / Detection Artifacts: Encrypted HTTPS traffic requires SSL offloading or inspection at the proxy layer to spot malformed payload structures.

 

  • CVE-2026-88771 (Citrix):

    • Log Sources: Web server access logs, audit logs, command execution logs on NetScaler appliances.

    • Behavioral Indicators: Unauthenticated HTTP requests containing anomalous parameters or shell invocation syntax targeting management endpoints.

    • Monitoring Gap / Detection Artifacts: Lack of strict input validation logging can obscure the exact payload vector without detailed WAF telemetry.

 

  • CVE-2026-67279 (MikroTik):

    • Log Sources: MikroTik RouterOS system logs, remote API access logs, firewall connection logs.

    • Behavioral Indicators: Unauthorized or unauthenticated session establishment attempts followed by command execution prompts.

    • Monitoring Gap / Detection Artifacts: Devices exposed directly to the internet without restricted management IP whitelisting increase blind spots.

 

  • CVE-2026-65660 (Microsoft):

    • Log Sources: IIS W3C logs, SharePoint ULS logs, Windows Security event logs.

    • Behavioral Indicators: Suspicious requests by authorized accounts executing unexpected web parts or injecting code into application pools.

    • Monitoring Gap / Detection Artifacts: Requires parsing verbose ULS logs to distinguish administrative actions from malicious code injection.

 

  • CVE-2026-87902 (WordPress):

    • Log Sources: Web server access logs (Apache/Nginx), PHP error logs, file integrity monitoring (FIM) alerts.

    • Behavioral Indicators: HTTP requests attempting to traverse template directories or include local `.php` files from unexpected paths.

    • Monitoring Gap / Detection Artifacts: Standard web server logs may blend legitimate template rendering with traversal probes unless query string inspection is enabled.

 

  • CVE-2026-5430 (WSO2):

    • Log Sources: WSO2 carbon server logs, application access logs, system file creation monitors.

    • Behavioral Indicators: Path traversal patterns (`../`) in upload parameters coupled with the creation of executable files in web-accessible directories.

    • Monitoring Gap / Detection Artifacts: Endpoint monitoring is required to catch unauthorized file writes outside designated upload repositories.

 

  • CVE-2026-71362 (Adobe):

    • Log Sources: Adobe Commerce application logs, web server access logs, authentication audit trails.

    • Behavioral Indicators: Access attempts to sensitive administrative endpoints or resources by low-privileged or unauthenticated sessions.

    • Monitoring Gap / Detection Artifacts: Granular application-level auditing is necessary to detect authorization bypasses that do not trigger HTTP error codes.

 

  • CVE-2026-93952 (Arista):

    • Log Sources: VeloCloud Orchestrator audit logs, system daemon logs, API gateway logs.

    • Behavioral Indicators: Unauthorized API calls or malformed input payloads directed at internal orchestrator functions.

    • Monitoring Gap / Detection Artifacts: Requires centralized collection of internal orchestrator microservice logs to trace privilege boundary violations.

 

  • CVE-2026-94127 (F5):

    • Log Sources: F5 BIG-IP system logs (`/var/log/ltm`), access policy logs, kernel crash logs.

    • Behavioral Indicators: Sudden daemon restarts, memory corruption alerts, or malformed OAuth/APM requests causing service crashes.

    • Monitoring Gap / Detection Artifacts: Heap overflows often manifest as silent service crashes rather than explicit intrusion alerts without crash dump analysis.

 

  • CVE-2026-93616 (Check Point):

    • Log Sources: Check Point management server logs, HTTP/API service access logs, audit trails.

    • Behavioral Indicators: Path traversal strings (`../`) present in requests destined for management server components.

    • Monitoring Gap / Detection Artifacts: Encrypted management traffic requires internal gateway logging or host-level IDS to capture traversal signatures.

 

  • CVE-2026-85102 (Check Point):

    • Log Sources: VPN gateway daemon logs, certificate verification logs, connection establishment records.

    • Behavioral Indicators: Anomalous VPN handshake behaviors or successful authentication sessions utilizing invalid or untrusted certificate chains.

    • Monitoring Gap / Detection Artifacts: Requires deep inspection of VPN handshake logging to identify bypassed validation checks.

 

  • CVE-2026-7273 (Zyxel):

    • Log Sources: Switch system logs, CGI execution error logs, local network traffic monitors.

    • Behavioral Indicators: Overly long input strings or malformed HTTP requests sent to switch CGI binaries from local network segments.

    • Monitoring Gap / Detection Artifacts: Layer-2 switch management interfaces typically lack deep packet inspection, requiring host-based switch log export to a SIEM.

 

 

Hackerstorm Analysis

The clustering of critical vulnerabilities across perimeter gateways and remote access solutions this week underscores the critical need for robust asset discovery and rapid patch management cycles. Attackers continue to weaponize memory corruption, input validation, and path traversal flaws to bypass security controls before defenders can implement mitigations. Organizations must enforce strict network segmentation, restrict administrative access to trusted internal hosts, and treat CISA KEV deadlines as hard operational SLAs.

 

 

    •  

 

 

Subscribe to get these articles directly to your inbox when published

 

 

 

 

What you should do next

Ensure you understand the latest KEV additions to cover off any potential gaps in your remediation activities.  View all weekly reports here

 

 

 

 

Further Reading

The following resources offer technical analysis to help integrate CISA KEV data into operational triage workflows and stay aligned with updated mitigation guidance.

 

 

hackerstorm Dynamic Intelligence

Need live data on specific KEVs from this roundup?

Lookup scores, news, poc's, threat intel, vendor advisory status, and exploit vectors in real time.

 

 

 

 


About This Report

 

Attribution Note

This analysis is based on publicly available reporting and security research summaries. Some technical details may change as additional information becomes available. 

 

Author Information

Timur Mehmet | Founder & Lead Editor

Timur is a veteran Information Security professional with a career spanning over three decades. Since the 1990s, he has led security initiatives across high-stakes sectors, including Finance, Telecommunications, Media, and Energy. Professional qualifications over the years have included CISSP, ISO27000 Auditor, ITIL and technologies such as Networking, Operating Systems, PKI, Firewalls. For more information including independent citations and credentials, visit our About page.

Contact: This email address is being protected from spambots. You need JavaScript enabled to view it.

 

Editorial Standards

This article adheres to Hackerstorm.com's commitment to accuracy, independence, and transparency:

  • Fact-Checking: All statistics and claims are verified against primary sources and authoritative reports
  • Source Transparency: Original research sources and citations are provided in the References section below
  • No Conflicts of Interest: This analysis is independent and not sponsored by any vendor or organization
  • Corrections Policy: We correct errors promptly and transparently. Report inaccuracies to This email address is being protected from spambots. You need JavaScript enabled to view it.

Editorial Policy: Ethics, Non-Bias, Fact Checking and Corrections


Learn More: About Hackerstorm.com | FAQs

 

Source Transparency

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 


 

Analyst Notes

  • No ransomware attribution was publicly associated with this week's KEV additions at the time of publication.
  • No confirmed threat actor attribution was available beyond CISA's confirmation of active exploitation for the majority of entries.
  • Where vendor advisory details or EPSS values were unavailable at publication time, placeholders were retained pending analyst validation and vendor updates prior to final publication.

 

 

 

 

 

By using this site, you agree to our Terms & Conditions.

COOKIE / PRIVACY POLICY: This website uses essential cookies required for basic site functionality. We also use analytics cookies to understand how the website is used. We do not use cookies for marketing or personalization, and we do not sell or share any personal data with third parties.

Terms & Privacy Policy