- Details
- 2026-10-05 10:26:04
Audience: Vulnerability Managers, Security Operations, CISOs, DevSecOps Teams
Reading Time: Approximately 10 minutes
Subscribe to get these articles directly to your inbox when published
43 KEV additions. 28 critical CVEs.
September 2026 saw a massive surge of 43 critical additions to CISA's Known Exploited Vulnerabilities (KEV) catalog, heavily dominated by enterprise networking equipment, core operating system kernels, perimeter gateways, and management consoles. Threat actor activity this month heavily targeted unauthenticated remote code execution and path traversal vectors, proving an aggressive, sustained campaign against edge appliances and infrastructure management servers. This monthly rollup provides security leaders and defense teams with cumulative intelligence, operational risk analysis, and prioritized remediation paths to safeguard enterprise assets.
| Metric | Value |
| Total new KEV additions this month | 43 |
| CVSS Critical entries (9.0–10.0) | 28 |
| CVSS High entries (7.0–8.9) | 15 |
| Entries with confirmed active exploitation | 43 |
| Entries with public PoC or exploit code | 43 |
| Most affected vendor | Linux Kernel / Check Point / Citrix / Cisco |
| Most common exploitation type | Remote Code Execution / Path Traversal / Buffer Overflow |
| Sectors most targeted | Government (FCEB), Critical Infrastructure, Financial Services, Technology |
| CVE | Vendor / Product | CVSS | Type | EPSS Score | Why It's Priority |
| CVE-2026-93616 | Check Point Security Management | 9.8 (Critical) | Path Traversal | 19.65% | Allows unauthenticated remote attackers to upload and execute arbitrary scripts directly on centralized security management servers, threatening entire firewall infrastructures. |
| CVE-2026-71362 | Adobe Commerce / Magento | 9.8 (Critical) | Incorrect Authorization | 87.51% | Features an extremely high EPSS score indicating widespread exploitation scanning against e-commerce platforms, permitting unauthenticated access to sensitive database layers. |
| CVE-2026-87902 | WordPress Core | 8.8 (High) | Remote File Inclusion | 39.98% | Impacts massive volumes of web deployments globally via core template resolution flaws, leading directly to unauthenticated remote code execution. |
| CVE-2026-94127 | F5 BIG-IP APM | Critical (CVSS 4.0) | Heap Buffer Overflow | 2.23% | Targets edge authentication gateways configured with OAuth profiles, exposing corporate perimeters to unauthenticated pre-auth code execution. |
| CVE-2026-88771 | Citrix NetScaler ADC / Gateway | Critical (CVSS 4.0) | Improper Input Validation | 1.08% | Compromises core virtual private network entry points, granting remote actors command execution capabilities on public-facing Citrix appliances. |
| CVE-2026-76504 | Cisco Catalyst SD-WAN Manager | 9.8 (Critical) | Authentication Bypass | 1.82% | Enables unauthenticated remote actors to acquire administrator privileges via URI encoding manipulation, impacting wide-area software-defined networking. |
| CVE-2026-86950 | Apple Multiple Products | 8.8 (High) | Out-of-Bounds Write | 1.24% | CoreGraphics memory corruption affecting iOS, macOS, and iPadOS, enabling arbitrary code execution through crafted user interaction vectors. |
| CVE-2026-88772 | Citrix NetScaler ADC / Gateway | Critical (CVSS 4.0) | Buffer Bounds Restriction | 1.30% | Secondary Citrix gateway flaw allowing remote code execution and service disruption via memory buffer manipulation. |
| CVE-2026-67279 | MikroTik RouterOS | Medium (CVSS 4.0) | Workflow Enforcement | 1.03% | Unauthenticated session channel opening that chains with subsequent execution flaws to compromise edge routers. |
| CVE-2026-65660 | Microsoft SharePoint | 8.8 (High) | Code Injection | 2.10% | Enables authorized network actors to inject code into enterprise collaboration systems, posing severe internal compromise risks. |
| CVE-2026-5430 | WSO2 Multiple Products | 9.8 (Critical) | Path Traversal | 0.59% | Path traversal allowing unrestricted file uploads and subsequent remote code execution across API management servers. |
| CVE-2026-93952 | Arista VeloCloud Orchestrator | Critical (CVSS 4.0) | Improper Input Validation | 1.06% | Grants remote attackers access to privileged internal orchestrator functionalities, compromising managed SD-WAN fabrics. |
| CVE-2026-85102 | Check Point Multiple Products | 9.8 (Critical) | Improper Certificate Validation | 7.55% | Enables unauthenticated remote execution on security gateways leveraging flawed site-to-site or remote access VPN validation routines. |
| CVE-2026-7273 | Zyxel GS1900 Switches | 8.8 (High) | Stack-Based Buffer Overflow | 2.50% | LAN-based unauthenticated actors can exploit switch CGI programs to execute arbitrary operating system commands. |
| CVE-2025-39964 | Linux Kernel | 7.8 (High) | Race Condition | 1.28% | Concurrent socket writes cause unpredictable data interleaving in AF_ALG sockets, creating internal state inconsistencies. |
| CVE-2026-53266 | Linux Kernel | 7.8 (High) | Out-of-Bounds Write | 1.15% | Ebtables SNAT target memory corruption vulnerability allowing arbitrary writes into file page-backed buffers. |
Ensure you understand the latest KEV additions to cover off any potential gaps in your remediation activities. View all weekly reports here
The following resources offer technical analysis to help integrate CISA KEV data into operational triage workflows and stay aligned with updated mitigation guidance.
Lookup scores, news, poc's, threat intel, vendor advisory status, and exploit vectors in real time.Need live data on specific KEVs from this roundup?
September's heavy influx of 43 KEV additions highlights a major tactical shift toward foundational infrastructure components, including deep Linux kernel memory weaknesses, network management plane vulnerabilities (Check Point, Arista, Cisco), and edge routing platforms. Rather than isolated desktop applications, threat actors are systematically exploiting architectural primitives that permit root-level persistence and unauthenticated command execution across large networks. The inclusion of critical kernel race conditions and out-of-bounds writes signifies that sophisticated adversaries are weaponizing low-level system flaws to bypass traditional endpoint detection and response layers.
| Sector | Exposure Level | Key CVEs This Month | Recommended Focus |
| Government / FCEB | High | CVE-2026-76504, CVE-2026-93616 | Enforce strict BOD 26-04 timelines and execute mandatory forensic triage on edge management consoles. |
| Healthcare | Medium | CVE-2026-88771, CVE-2026-94127 | Audit remote access portals and apply vendor iRules or immediate patches for NetScaler and BIG-IP. |
| Financial Services | High | CVE-2026-71362, CVE-2026-5430 | Restrict unauthorized API access channels and patch e-commerce payment gateways immediately. |
| Critical Infrastructure | High | CVE-2026-67279, CVE-2026-93952 | Isolate operational routers and SD-WAN orchestrators from direct external internet access. |
| Technology / SaaS | High | CVE-2026-87902, CVE-2025-39964 | Upgrade core content management and host kernels to eliminate low-level escalation vectors. |
Analyzing all 43 KEV entries from September reveals a concerning convergence: adversaries are coupling low-level OS kernel flaws (such as Linux socket race conditions and out-of-bounds writes) with high-level edge management bypasses. This dual-pronged volume suggests that attackers are preparing pre-positioned exploitation frameworks capable of establishing persistent footholds across heterogeneous enterprise stacks. Security teams must recognize that high monthly volumes of KEV additions cannot be mitigated by standard patch cycles alone; organizations require automated asset discovery and runtime behavioral telemetry to catch anomalous kernel and gateway activity.
This analysis is based on publicly available reporting and security research summaries. Some technical details may change as additional information becomes available.
Timur Mehmet | Founder & Lead Editor
Timur is a veteran Information Security professional with a career spanning over three decades. Since the 1990s, he has led security initiatives across high-stakes sectors, including Finance, Telecommunications, Media, and Energy. Professional qualifications over the years have included CISSP, ISO27000 Auditor, ITIL and technologies such as Networking, Operating Systems, PKI, Firewalls. For more information including independent citations and credentials, visit our About page.
Contact:
This article adheres to Hackerstorm.com's commitment to accuracy, independence, and transparency:
Editorial Policy: Ethics, Non-Bias, Fact Checking and Corrections
Learn More: About Hackerstorm.com | FAQs
CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
National Vulnerability Database (NVD): https://nvd.nist.gov/
HackerStorm Threat Intelligence Field Notes (September 2026)
Vendor Advisories:
Cisco Security Advisory — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU
Apple Security Updates — https://support.apple.com/en-us/149226
Citrix Security Bulletin — https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
MikroTik RouterOS Advisory — https://mikrotik.com/supportsec/september-2026-vulnerability/
Microsoft Security Update Guide — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660
WordPress Security Advisory — https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp
WSO2 Security Advisory — https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5328/
Adobe Commerce Advisory — https://helpx.adobe.com/security/products/magento/apsb26-92.html
Arista Security Advisory — https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183
F5 Security Advisory — https://my.f5.com/manage/s/article/K000162605
Check Point Security Advisory — https://support.checkpoint.com/results/sk/sk1000171/
Zyxel Security Advisory — https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026
Linux Kernel Git Repository — https://git.kernel.org/
COOKIE / PRIVACY POLICY: This website uses essential cookies required for basic site functionality. We also use analytics cookies to understand how the website is used. We do not use cookies for marketing or personalization, and we do not sell or share any personal data with third parties.