Our Blog

Hackerstorm monthly KEV vulnerability report

Vulnerability Priority Report – September 2026 | HackerStorm

 

Audience: Vulnerability Managers, Security Operations, CISOs, DevSecOps Teams
Reading Time: Approximately 10 minutes

 

 

Subscribe to get these articles directly to your inbox when published

 

43 KEV additions. 28 critical CVEs. 

 

September 2026 saw a massive surge of 43 critical additions to CISA's Known Exploited Vulnerabilities (KEV) catalog, heavily dominated by enterprise networking equipment, core operating system kernels, perimeter gateways, and management consoles. Threat actor activity this month heavily targeted unauthenticated remote code execution and path traversal vectors, proving an aggressive, sustained campaign against edge appliances and infrastructure management servers. This monthly rollup provides security leaders and defense teams with cumulative intelligence, operational risk analysis, and prioritized remediation paths to safeguard enterprise assets.

 

The Month in Numbers

Metric Value
Total new KEV additions this month 43
CVSS Critical entries (9.0–10.0) 28
CVSS High entries (7.0–8.9) 15
Entries with confirmed active exploitation 43
Entries with public PoC or exploit code 43
Most affected vendor Linux Kernel / Check Point / Citrix / Cisco
Most common exploitation type Remote Code Execution / Path Traversal / Buffer Overflow
Sectors most targeted Government (FCEB), Critical Infrastructure, Financial Services, Technology

 

Priority Vulnerabilities This Month

CVE Vendor / Product CVSS Type EPSS Score Why It's Priority
CVE-2026-93616 Check Point Security Management 9.8 (Critical) Path Traversal 19.65% Allows unauthenticated remote attackers to upload and execute arbitrary scripts directly on centralized security management servers, threatening entire firewall infrastructures.
CVE-2026-71362 Adobe Commerce / Magento 9.8 (Critical) Incorrect Authorization 87.51% Features an extremely high EPSS score indicating widespread exploitation scanning against e-commerce platforms, permitting unauthenticated access to sensitive database layers.
CVE-2026-87902 WordPress Core 8.8 (High) Remote File Inclusion 39.98% Impacts massive volumes of web deployments globally via core template resolution flaws, leading directly to unauthenticated remote code execution.
CVE-2026-94127 F5 BIG-IP APM Critical (CVSS 4.0) Heap Buffer Overflow 2.23% Targets edge authentication gateways configured with OAuth profiles, exposing corporate perimeters to unauthenticated pre-auth code execution.
CVE-2026-88771 Citrix NetScaler ADC / Gateway Critical (CVSS 4.0) Improper Input Validation 1.08% Compromises core virtual private network entry points, granting remote actors command execution capabilities on public-facing Citrix appliances.
CVE-2026-76504 Cisco Catalyst SD-WAN Manager 9.8 (Critical) Authentication Bypass 1.82% Enables unauthenticated remote actors to acquire administrator privileges via URI encoding manipulation, impacting wide-area software-defined networking.
CVE-2026-86950 Apple Multiple Products 8.8 (High) Out-of-Bounds Write 1.24% CoreGraphics memory corruption affecting iOS, macOS, and iPadOS, enabling arbitrary code execution through crafted user interaction vectors.
CVE-2026-88772 Citrix NetScaler ADC / Gateway Critical (CVSS 4.0) Buffer Bounds Restriction 1.30% Secondary Citrix gateway flaw allowing remote code execution and service disruption via memory buffer manipulation.
CVE-2026-67279 MikroTik RouterOS Medium (CVSS 4.0) Workflow Enforcement 1.03% Unauthenticated session channel opening that chains with subsequent execution flaws to compromise edge routers.
CVE-2026-65660 Microsoft SharePoint 8.8 (High) Code Injection 2.10% Enables authorized network actors to inject code into enterprise collaboration systems, posing severe internal compromise risks.
CVE-2026-5430 WSO2 Multiple Products 9.8 (Critical) Path Traversal 0.59% Path traversal allowing unrestricted file uploads and subsequent remote code execution across API management servers.
CVE-2026-93952 Arista VeloCloud Orchestrator Critical (CVSS 4.0) Improper Input Validation 1.06% Grants remote attackers access to privileged internal orchestrator functionalities, compromising managed SD-WAN fabrics.
CVE-2026-85102 Check Point Multiple Products 9.8 (Critical) Improper Certificate Validation 7.55% Enables unauthenticated remote execution on security gateways leveraging flawed site-to-site or remote access VPN validation routines.
CVE-2026-7273 Zyxel GS1900 Switches 8.8 (High) Stack-Based Buffer Overflow 2.50% LAN-based unauthenticated actors can exploit switch CGI programs to execute arbitrary operating system commands.
CVE-2025-39964 Linux Kernel 7.8 (High) Race Condition 1.28% Concurrent socket writes cause unpredictable data interleaving in AF_ALG sockets, creating internal state inconsistencies.
CVE-2026-53266 Linux Kernel 7.8 (High) Out-of-Bounds Write 1.15% Ebtables SNAT target memory corruption vulnerability allowing arbitrary writes into file page-backed buffers.

 

What you should do next

Ensure you understand the latest KEV additions to cover off any potential gaps in your remediation activities.  View all weekly reports here

 

 

 

 

Further Reading

The following resources offer technical analysis to help integrate CISA KEV data into operational triage workflows and stay aligned with updated mitigation guidance.

 

 

hackerstorm Dynamic Intelligence

Need live data on specific KEVs from this roundup?

Lookup scores, news, poc's, threat intel, vendor advisory status, and exploit vectors in real time.

 

 

Threat Landscape Context

September's heavy influx of 43 KEV additions highlights a major tactical shift toward foundational infrastructure components, including deep Linux kernel memory weaknesses, network management plane vulnerabilities (Check Point, Arista, Cisco), and edge routing platforms. Rather than isolated desktop applications, threat actors are systematically exploiting architectural primitives that permit root-level persistence and unauthenticated command execution across large networks. The inclusion of critical kernel race conditions and out-of-bounds writes signifies that sophisticated adversaries are weaponizing low-level system flaws to bypass traditional endpoint detection and response layers.

 

Sector Exposure Summary

Sector Exposure Level Key CVEs This Month Recommended Focus
Government / FCEB High CVE-2026-76504, CVE-2026-93616 Enforce strict BOD 26-04 timelines and execute mandatory forensic triage on edge management consoles.
Healthcare Medium CVE-2026-88771, CVE-2026-94127 Audit remote access portals and apply vendor iRules or immediate patches for NetScaler and BIG-IP.
Financial Services High CVE-2026-71362, CVE-2026-5430 Restrict unauthorized API access channels and patch e-commerce payment gateways immediately.
Critical Infrastructure High CVE-2026-67279, CVE-2026-93952 Isolate operational routers and SD-WAN orchestrators from direct external internet access.
Technology / SaaS High CVE-2026-87902, CVE-2025-39964 Upgrade core content management and host kernels to eliminate low-level escalation vectors.

 

Hackerstorm Analysis

Analyzing all 43 KEV entries from September reveals a concerning convergence: adversaries are coupling low-level OS kernel flaws (such as Linux socket race conditions and out-of-bounds writes) with high-level edge management bypasses. This dual-pronged volume suggests that attackers are preparing pre-positioned exploitation frameworks capable of establishing persistent footholds across heterogeneous enterprise stacks. Security teams must recognize that high monthly volumes of KEV additions cannot be mitigated by standard patch cycles alone; organizations require automated asset discovery and runtime behavioral telemetry to catch anomalous kernel and gateway activity.

 

 


 

About This Report

 

Attribution Note

This analysis is based on publicly available reporting and security research summaries. Some technical details may change as additional information becomes available. 

 

Author Information

Timur Mehmet | Founder & Lead Editor

Timur is a veteran Information Security professional with a career spanning over three decades. Since the 1990s, he has led security initiatives across high-stakes sectors, including Finance, Telecommunications, Media, and Energy. Professional qualifications over the years have included CISSP, ISO27000 Auditor, ITIL and technologies such as Networking, Operating Systems, PKI, Firewalls. For more information including independent citations and credentials, visit our About page.

Contact: This email address is being protected from spambots. You need JavaScript enabled to view it.

 

Editorial Standards

This article adheres to Hackerstorm.com's commitment to accuracy, independence, and transparency:

  • Fact-Checking: All statistics and claims are verified against primary sources and authoritative reports
  • Source Transparency: Original research sources and citations are provided in the References section below
  • No Conflicts of Interest: This analysis is independent and not sponsored by any vendor or organization
  • Corrections Policy: We correct errors promptly and transparently. Report inaccuracies to This email address is being protected from spambots. You need JavaScript enabled to view it.

Editorial Policy: Ethics, Non-Bias, Fact Checking and Corrections


Learn More: About Hackerstorm.com | FAQs

 

Source Transparency

 

 

 

 

By using this site, you agree to our Terms & Conditions.

COOKIE / PRIVACY POLICY: This website uses essential cookies required for basic site functionality. We also use analytics cookies to understand how the website is used. We do not use cookies for marketing or personalization, and we do not sell or share any personal data with third parties.

Terms & Privacy Policy