- Details
- 2026-09-20 10:26:04
Audience: Vulnerability Managers, Security Operations, CISOs, DevSecOps Teams
Reading Time: Approximately 10 minutes
| CVE ID | Vendor / Product | CVSS | Date Added | CISA Due Date | Exploitation Type | EPSS Score | Reachability |
| CVE-2026-88772 | Citrix NetScaler ADC and NetScaler Gateway | 9.8 (Critical) | 2026-09-27 | 2026-10-18 | Improper restriction of operations within the bounds of a memory buffer |
Pending |
N (Network) |
| CVE-2026-88771 | Citrix NetScaler ADC and NetScaler Gateway | 9.8 (Critical) | 2026-09-27 | 2026-10-18 | Improper input validation |
Pending |
N (Network) |
| CVE-2026-67279 | MikroTik RouterOS | 6.5 (Medium) | 2026-09-25 | 2026-10-16 | Improper enforcement of behavioral workflow |
1.027% |
N (Network) |
| CVE-2026-65660 | Microsoft SharePoint | 8.8 (High) | 2026-09-25 | 2026-10-16 | Code injection |
2.101% |
N (Network) |
| CVE-2026-87902 | WordPress Core | 8.6 (High) | 2026-09-25 | 2026-10-16 | Remote file inclusion |
18.166% |
N (Network) |
| CVE-2026-5430 | WSO2 API Control Plane, Manager, Traffic Manager & Universal Gateway | 9.8 (Critical) | 2026-09-24 | 2026-10-15 | Path traversal / Unrestricted file upload |
0.588% |
N (Network) |
| CVE-2026-71362 | Adobe Commerce and Magento | 9.8 (Critical) | 2026-09-24 | 2026-10-15 | Incorrect authorization |
87.507% |
N (Network) |
| CVE-2026-93952 | Arista VeloCloud Orchestrator (VCO) | 9.8 (Critical) | 2026-09-22 | 2026-10-13 | Improper input validation |
1.062% |
N (Network) |
| CVE-2026-94127 | F5 BIG-IP APM | 9.8 (Critical) | 2026-09-22 | 2026-10-13 | Heap-based buffer overflow |
2.226% |
N (Network) |
| CVE-2026-93616 | Check Point Security Management Server | 9.8 (Critical) | 2026-09-22 | 2026-10-13 | Path traversal |
19.654% |
N (Network) |
| CVE-2026-85102 | Check Point Security Gateway | 9.8 (Critical) | 2026-09-22 | 2026-10-13 | Improper certificate validation |
0.988% |
N (Network) |
| CVE-2026-7273 | Zyxel GS1900 Series Switches | 8.8 (High) | 2026-09-21 | 2026-10-12 | Stack-based buffer overflow |
2.501% |
A (Adjacent) |
Note: EPSS scores are as published by FIRST.org at time of writing and are not updated after publication; scores change daily.
Lookup scores, news, poc's, threat intel, vendor advisory status, and exploit vectors in real time.Need live data on specific KEVs from this roundup?
What it is: An improper restriction of operations within memory buffer bounds vulnerability in Citrix NetScaler ADC and NetScaler Gateway that can allow remote code execution or denial of service.
Affected versions: Refer to Citrix security advisory for specific vulnerable builds.
Exploitation status: Confirmed exploitation added to CISA KEV catalog.
Patch available: Yes, consult vendor advisory for remediation builds.
CISA due date: 2026-10-18
Operational risk: Compromise of perimeter edge infrastructure, allowing attackers to execute arbitrary code or disrupt critical gateway access.
What it is: An improper input validation vulnerability in Citrix NetScaler ADC and NetScaler Gateway permitting unauthenticated attackers to execute arbitrary commands.
Affected versions: Refer to Citrix security advisory.
Exploitation status: Confirmed exploitation added to CISA KEV catalog.
Patch available: Yes, refer to vendor advisory.
CISA due date: 2026-10-18
Operational risk: Unauthenticated remote code execution on internet-facing edge appliances, leading to full network compromise.
What it is: An improper enforcement of behavioral workflow vulnerability in MikroTik RouterOS enabling unauthenticated clients to open a session channel and send execution requests.
Affected versions: Refer to MikroTik advisory.
Exploitation status: Confirmed exploitation added to CISA KEV catalog.
Patch available: Yes, upgrade RouterOS to a patched version.
CISA due date: 2026-10-16
Operational risk: Unauthorized session establishment and command execution on networking infrastructure.
What it is: A code injection vulnerability in Microsoft SharePoint that allows authorized attackers to execute code over a network.
Affected versions: Refer to Microsoft security updates.
Exploitation status: Confirmed exploitation added to CISA KEV catalog.
Patch available: Yes, apply appropriate Microsoft security update.
CISA due date: 2026-10-16
Operational risk: Compromise of collaboration platforms and internal document repositories.
What it is: A remote file inclusion vulnerability in WordPress Core allowing unauthenticated attackers to manipulate page-template resolution and include arbitrary local readable .php files.
Affected versions: Refer to WordPress security advisories.
Exploitation status: Confirmed exploitation added to CISA KEV catalog.
Patch available: Yes, update WordPress Core.
CISA due date: 2026-10-16
Operational risk: Potential code execution and compromise of web application environments.
What it is: A path traversal vulnerability in WSO2 API products enabling unrestricted file upload and leading to remote code execution.
Affected versions: Refer to WSO2 advisory.
Exploitation status: Confirmed exploitation added to CISA KEV catalog.
Patch available: Yes, apply fixes from WSO2.
CISA due date: 2026-10-15
Operational risk: Full compromise of API management infrastructure.
What it is: An incorrect authorization vulnerability in Adobe Commerce and Magento allowing unauthorized actors to gain elevated access to sensitive resources.
Affected versions: Refer to Adobe security bulletin.
Exploitation status: Confirmed exploitation added to CISA KEV catalog.
Patch available: Yes, apply updates provided by Adobe.
CISA due date: 2026-10-15
Operational risk: Unauthorized data access and privilege escalation in e-commerce environments.
What it is: An improper input validation vulnerability in Arista VeloCloud Orchestrator on-prem allowing remote attackers to access privileged internal functionality and impact the VCO host.
Affected versions: Refer to Arista advisory.
Exploitation status: Confirmed exploitation added to CISA KEV catalog.
Patch available: Yes, apply vendor patch.
CISA due date: 2026-10-13
Operational risk: Compromise of SD-WAN management orchestration and control planes.
What it is: A heap-based buffer overflow vulnerability in F5 BIG-IP APM when access policy and OAuth profile are configured.
Affected versions: Refer to F5 advisory.
Exploitation status: Confirmed exploitation added to CISA KEV catalog.
Patch available: Yes, install fixes from F5.
CISA due date: 2026-10-13
Operational risk: Denial of service or remote code execution on authentication and access gateways.
What it is: A path traversal vulnerability in Check Point management and log servers allowing unauthenticated file access.
Affected versions: Refer to Check Point advisory.
Exploitation status: Confirmed exploitation added to CISA KEV catalog.
Patch available: Yes, apply vendor hotfixes.
CISA due date: 2026-10-13
Operational risk: Compromise of central security management infrastructure.
What it is: An improper certificate validation vulnerability in Check Point Security Gateway and Spark Firewall using VPN features.
Affected versions: Refer to Check Point advisory.
Exploitation status: Confirmed exploitation added to CISA KEV catalog.
Patch available: Yes, apply vendor remediation.
CISA due date: 2026-10-13
Operational risk: Compromise of encrypted VPN tunnels and boundary defenses.
What it is: A stack-based buffer overflow vulnerability in CGI programs of Zyxel GS1900 switches permitting LAN-based unauthenticated execution.
Affected versions: Refer to Zyxel security advisory.
Exploitation status: Confirmed exploitation added to CISA KEV catalog.
Patch available: Yes, update switch firmware.
CISA due date: 2026-10-12
Operational risk: Compromise of network switches and localized layer-2 infrastructure.
This week’s additions to the CISA Known Exploited Vulnerabilities (KEV) catalog highlight an aggressive focus by threat actors on internet-facing network edge devices, remote access gateways, and enterprise security management platforms. Critical infrastructure and perimeter controls—including Citrix NetScaler, Check Point gateways, F5 BIG-IP, and Arista orchestration tools—represent primary targets designed to achieve initial access and persistence within corporate networks.
Additionally, enterprise collaboration platforms and e-commerce applications such as Microsoft SharePoint and Adobe Commerce continue to attract active exploitation due to the high density of sensitive data they process. Security teams should prioritize patching based on public exposure and the severe implications of remote code execution across these administrative and boundary components.
| Priority | CVE ID | Recommended Action | Timeline |
| 1 | CVE-2026-88772 | Apply vendor patches immediately to secure Citrix NetScaler ADC and Gateway against RCE. | Immediate |
| 2 | CVE-2026-88771 | Update Citrix NetScaler appliances to remediate unauthenticated command execution risks. | Immediate |
| 3 | CVE-2026-71362 | Apply Adobe Commerce and Magento updates to prevent unauthorized access. | Within 24 hours |
| 4 | CVE-2026-93616 | Apply Check Point security management server patches to block path traversal. | Within 24 hours |
| 5 | CVE-2026-85102 | Update Check Point Security Gateways for proper certificate validation. | Within 24 hours |
| 6 | CVE-2026-94127 | Patch F5 BIG-IP APM to mitigate buffer overflow exposure. | Within 24 hours |
| 7 | CVE-2026-93952 | Update Arista VeloCloud Orchestrator to resolve input validation flaws. | Within 24 hours |
| 8 | CVE-2026-5430 | Apply WSO2 product updates to prevent path traversal and file upload exploitation. | Within 72 hours |
| 9 | CVE-2026-65660 | Apply Microsoft SharePoint security updates to remediate code injection risks. | Within 72 hours |
| 10 | CVE-2026-87902 | Update WordPress Core to patch remote file inclusion vulnerabilities. | Within 72 hours |
| 11 | CVE-2026-67279 | Update MikroTik RouterOS firmware to address workflow enforcement flaws. | Within 72 hours |
| 12 | CVE-2026-7273 | Upgrade Zyxel GS1900 series switch firmware to patch buffer overflow vulnerabilities. | By CISA due date |
CVE-2026-88772 (Citrix):
Log Sources: Citrix ADC/Gateway HTTP access logs, system error logs, core dump monitors.
Behavioral Indicators: Abnormal memory usage patterns, unexpected process terminations, or unexpected child processes spawned by gateway services.
Monitoring Gap / Detection Artifacts: Encrypted HTTPS traffic requires SSL offloading or inspection at the proxy layer to spot malformed payload structures.
CVE-2026-88771 (Citrix):
Log Sources: Web server access logs, audit logs, command execution logs on NetScaler appliances.
Behavioral Indicators: Unauthenticated HTTP requests containing anomalous parameters or shell invocation syntax targeting management endpoints.
Monitoring Gap / Detection Artifacts: Lack of strict input validation logging can obscure the exact payload vector without detailed WAF telemetry.
CVE-2026-67279 (MikroTik):
Log Sources: MikroTik RouterOS system logs, remote API access logs, firewall connection logs.
Behavioral Indicators: Unauthorized or unauthenticated session establishment attempts followed by command execution prompts.
Monitoring Gap / Detection Artifacts: Devices exposed directly to the internet without restricted management IP whitelisting increase blind spots.
CVE-2026-65660 (Microsoft):
Log Sources: IIS W3C logs, SharePoint ULS logs, Windows Security event logs.
Behavioral Indicators: Suspicious requests by authorized accounts executing unexpected web parts or injecting code into application pools.
Monitoring Gap / Detection Artifacts: Requires parsing verbose ULS logs to distinguish administrative actions from malicious code injection.
CVE-2026-87902 (WordPress):
Log Sources: Web server access logs (Apache/Nginx), PHP error logs, file integrity monitoring (FIM) alerts.
Behavioral Indicators: HTTP requests attempting to traverse template directories or include local `.php` files from unexpected paths.
Monitoring Gap / Detection Artifacts: Standard web server logs may blend legitimate template rendering with traversal probes unless query string inspection is enabled.
CVE-2026-5430 (WSO2):
Log Sources: WSO2 carbon server logs, application access logs, system file creation monitors.
Behavioral Indicators: Path traversal patterns (`../`) in upload parameters coupled with the creation of executable files in web-accessible directories.
Monitoring Gap / Detection Artifacts: Endpoint monitoring is required to catch unauthorized file writes outside designated upload repositories.
CVE-2026-71362 (Adobe):
Log Sources: Adobe Commerce application logs, web server access logs, authentication audit trails.
Behavioral Indicators: Access attempts to sensitive administrative endpoints or resources by low-privileged or unauthenticated sessions.
Monitoring Gap / Detection Artifacts: Granular application-level auditing is necessary to detect authorization bypasses that do not trigger HTTP error codes.
CVE-2026-93952 (Arista):
Log Sources: VeloCloud Orchestrator audit logs, system daemon logs, API gateway logs.
Behavioral Indicators: Unauthorized API calls or malformed input payloads directed at internal orchestrator functions.
Monitoring Gap / Detection Artifacts: Requires centralized collection of internal orchestrator microservice logs to trace privilege boundary violations.
CVE-2026-94127 (F5):
Log Sources: F5 BIG-IP system logs (`/var/log/ltm`), access policy logs, kernel crash logs.
Behavioral Indicators: Sudden daemon restarts, memory corruption alerts, or malformed OAuth/APM requests causing service crashes.
Monitoring Gap / Detection Artifacts: Heap overflows often manifest as silent service crashes rather than explicit intrusion alerts without crash dump analysis.
CVE-2026-93616 (Check Point):
Log Sources: Check Point management server logs, HTTP/API service access logs, audit trails.
Behavioral Indicators: Path traversal strings (`../`) present in requests destined for management server components.
Monitoring Gap / Detection Artifacts: Encrypted management traffic requires internal gateway logging or host-level IDS to capture traversal signatures.
CVE-2026-85102 (Check Point):
Log Sources: VPN gateway daemon logs, certificate verification logs, connection establishment records.
Behavioral Indicators: Anomalous VPN handshake behaviors or successful authentication sessions utilizing invalid or untrusted certificate chains.
Monitoring Gap / Detection Artifacts: Requires deep inspection of VPN handshake logging to identify bypassed validation checks.
CVE-2026-7273 (Zyxel):
Log Sources: Switch system logs, CGI execution error logs, local network traffic monitors.
Behavioral Indicators: Overly long input strings or malformed HTTP requests sent to switch CGI binaries from local network segments.
Monitoring Gap / Detection Artifacts: Layer-2 switch management interfaces typically lack deep packet inspection, requiring host-based switch log export to a SIEM.
The clustering of critical vulnerabilities across perimeter gateways and remote access solutions this week underscores the critical need for robust asset discovery and rapid patch management cycles. Attackers continue to weaponize memory corruption, input validation, and path traversal flaws to bypass security controls before defenders can implement mitigations. Organizations must enforce strict network segmentation, restrict administrative access to trusted internal hosts, and treat CISA KEV deadlines as hard operational SLAs.
Subscribe to get these articles directly to your inbox when published
Ensure you understand the latest KEV additions to cover off any potential gaps in your remediation activities. View all weekly reports here
The following resources offer technical analysis to help integrate CISA KEV data into operational triage workflows and stay aligned with updated mitigation guidance.
Lookup scores, news, poc's, threat intel, vendor advisory status, and exploit vectors in real time.Need live data on specific KEVs from this roundup?
This analysis is based on publicly available reporting and security research summaries. Some technical details may change as additional information becomes available.
Timur Mehmet | Founder & Lead Editor
Timur is a veteran Information Security professional with a career spanning over three decades. Since the 1990s, he has led security initiatives across high-stakes sectors, including Finance, Telecommunications, Media, and Energy. Professional qualifications over the years have included CISSP, ISO27000 Auditor, ITIL and technologies such as Networking, Operating Systems, PKI, Firewalls. For more information including independent citations and credentials, visit our About page.
Contact:
This article adheres to Hackerstorm.com's commitment to accuracy, independence, and transparency:
Editorial Policy: Ethics, Non-Bias, Fact Checking and Corrections
Learn More: About Hackerstorm.com | FAQs
CVE-2026-88772:
CISA (CISA KEV catalog) — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
NVD (NVD Record) — https://nvd.nist.gov/vuln/detail/CVE-2026-88772
CVE-2026-88771:
CISA (CISA KEV catalog) — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
NVD (NVD Record) — https://nvd.nist.gov/vuln/detail/CVE-2026-88771
CVE-2026-67279:
CISA (CISA KEV catalog) — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
NVD (NVD Record) — https://nvd.nist.gov/vuln/detail/CVE-2026-67279
FIRST.org (EPSS) — https://www.first.org/epss/
CVE-2026-65660:
CISA (CISA KEV catalog) — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
NVD (NVD Record) — https://nvd.nist.gov/vuln/detail/CVE-2026-65660
FIRST.org (EPSS) — https://www.first.org/epss/
CVE-2026-87902:
CISA (CISA KEV catalog) — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
NVD (NVD Record) — https://nvd.nist.gov/vuln/detail/CVE-2026-87902
FIRST.org (EPSS) — https://www.first.org/epss/
CVE-2026-5430:
CISA (CISA KEV catalog) — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
NVD (NVD Record) — https://nvd.nist.gov/vuln/detail/CVE-2026-5430
FIRST.org (EPSS) — https://www.first.org/epss/
CVE-2026-71362:
CISA (CISA KEV catalog) — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
NVD (NVD Record) — https://nvd.nist.gov/vuln/detail/CVE-2026-71362
FIRST.org (EPSS) — https://www.first.org/epss/
CVE-2026-93952:
CISA (CISA KEV catalog) — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
NVD (NVD Record) — https://nvd.nist.gov/vuln/detail/CVE-2026-93952
FIRST.org (EPSS) — https://www.first.org/epss/
CVE-2026-94127:
CISA (CISA KEV catalog) — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
NVD (NVD Record) — https://nvd.nist.gov/vuln/detail/CVE-2026-94127
FIRST.org (EPSS) — https://www.first.org/epss/
CVE-2026-93616:
CISA (CISA KEV catalog) — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
NVD (NVD Record) — https://nvd.nist.gov/vuln/detail/CVE-2026-93616
FIRST.org (EPSS) — https://www.first.org/epss/
CVE-2026-85102:
CISA (CISA KEV catalog) — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
NVD (NVD Record) — https://nvd.nist.gov/vuln/detail/CVE-2026-85102
FIRST.org (EPSS) — https://www.first.org/epss/
CVE-2026-7273:
CISA (CISA KEV catalog) — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
NVD (NVD Record) — https://nvd.nist.gov/vuln/detail/CVE-2026-7273
FIRST.org (EPSS) — https://www.first.org/epss/
COOKIE / PRIVACY POLICY: This website uses essential cookies required for basic site functionality. We also use analytics cookies to understand how the website is used. We do not use cookies for marketing or personalization, and we do not sell or share any personal data with third parties.