This month: 23 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2026-76461
Cisco · Secure Email Gateway
Cisco Secure Email Gateway SQL Injection Vulnerability
Detected Sep 14 · 3-day patch deadline
CVE-2026-84869
ConnectWise · ScreenConnect
ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
Detected Sep 11 · 3-day patch deadline
CVE-2026-85706
GitLab · Community Edition and Enterprise Edition
GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
Detected Sep 11 · 3-day patch deadline

KEV Intelligence Brief — September 15, 2026

Classification: TLP:CLEAR | Audience: Federal Contractors, DevOps, SecOps Leadership Prepared: Tuesday, September 15, 2026 | Authority: CISA BOD 26-04

Deadline Watch: Overdue and Expiring Within 72 Hours

Four of the eight newly cataloged vulnerabilities carry patch deadlines that have already passed or expire before this brief's publication date, demanding immediate retrospective compliance review alongside active remediation.

MikroTik RouterOS drew two entries simultaneously (CVE-2026-67277 and CVE-2026-86060), both added September 10 with a September 13 deadline that is now overdue. Taken together, they represent a dangerous chain: CVE-2026-67277 exposes kernel memory and enables denial-of-service through an unauthenticated call to the btest service, while CVE-2026-86060 allows an attacker to manipulate the RouterOS policy trust mask via improper argument delimiter neutralization — a privilege escalation primitive. Organizations that have not patched should assume these devices are already being actively probed. Because MikroTik routers frequently sit at network perimeters or inside segmented OT/IT environments with minimal monitoring, forensic triage per BOD 26-04 requirements is non-negotiable before returning any patched device to production. Disable the btest service if it is not operationally required, and audit all RouterOS policy assignments for unauthorized changes.

Fortinet FortiOS, FortiSwitchManager, and FortiSASE (CVE-2025-25249) share a heap-based buffer overflow exploitable via specially crafted packets, carrying a September 12 deadline — also overdue. This is a remote code execution class vulnerability with no authentication prerequisite implied by the packet-based delivery mechanism. Fortinet perimeter products are consistently among the highest-value targets for state-sponsored actors seeking persistent network access. Any organization still running unpatched Fortinet appliances should treat them as potentially compromised, isolate them from internal routing, rotate all service accounts and VPN credentials that traversed those systems, and conduct log review for anomalous session establishment prior to applying patches.

ConnectWise ScreenConnect (CVE-2026-84869) and GitLab CE/EE (CVE-2026-85706) both carried a September 14 deadline — expired yesterday. The ScreenConnect vulnerability combines improper privilege management with missing authorization, permitting an attacker to conduct file transfer and execution through an active remote session without host confirmation. In managed service provider environments, a single compromised ScreenConnect instance translates directly into downstream client exposure — a supply-chain multiplier that significantly elevates organizational risk. GitLab's path traversal flaw (CVE-2026-85706) is equally severe in context: an unauthenticated caller can read arbitrary files via the repository commits API due to broken path confinement. Source code, CI/CD secrets, API keys embedded in repositories, and pipeline configurations are all in scope for exfiltration. Self-hosted GitLab instances exposed to the internet should be placed behind authenticated reverse proxies or VPNs immediately if patching is delayed even temporarily.

Developer Toolchain and DevSecOps Infrastructure Under Siege

Three entries this cycle target the software supply chain directly — the repositories, artifact managers, and source control systems that sit at the center of modern software delivery pipelines.

JFrog Artifactory appears twice: CVE-2026-42016 and CVE-2026-42018, both added September 11 with a September 25 deadline, offering a slightly longer runway but warranting no complacency given active exploitation. CVE-2026-42016 is an incorrect authorization flaw where token validation checks the signature and issuer but fails to enforce token scope — meaning a legitimately issued, narrowly scoped token can be weaponized for privilege escalation to broader artifact access. CVE-2026-42018 compounds this: when anonymous access is configured as disabled, Artifactory can nevertheless return an internal anonymous-user token to an unauthenticated caller, effectively nullifying the access control policy. Together, these vulnerabilities mean that an adversary needs no valid credentials to begin escalating privileges within your artifact repository. For organizations using Artifactory as part of CI/CD pipelines, the blast radius extends to package signing keys, build secrets, and dependency integrity. Audit all active tokens immediately, revoke any of unknown provenance, and verify that anonymous access is genuinely disabled at the application layer — not merely assumed to be based on configuration intent.

The GitLab path traversal (CVE-2026-85706, noted above) reinforces this theme. When source control and artifact management are simultaneously under active exploitation, the integrity of the entire build pipeline must be questioned. Teams should perform artifact provenance checks and verify the integrity of any packages built or published during the relevant exposure windows.

Internet-Facing Email Infrastructure: Critical Priority Before Week's End

Cisco Secure Email Gateway (CVE-2026-76461) was added September 14 with a September 17 deadline — three days from today. This SQL injection vulnerability in Cisco AsyncOS is particularly alarming because it is exploitable by an unauthenticated remote attacker and yields root-level command execution on the underlying operating system. Email gateways are definitionally internet-facing, process sensitive communications, and frequently hold credentials for downstream mail infrastructure. A root shell on an SEG provides an attacker with a persistent, high-trust network vantage point. Organizations must apply Cisco's patch before the deadline without exception. If patching cannot be completed by September 17, the system must be isolated or taken offline per BOD 26-04 guidance — operating an unpatched, internet-facing device with an unauthenticated RCE vulnerability after the federal deadline constitutes a compliance failure with potential reporting obligations. Review mail flow logs for anomalous relay behavior and unexpected process execution from the SEG host going back at least 30 days.

Analyst Note

This cycle's KEV additions are unusually dense with authentication bypass and privilege escalation pairs — MikroTik, JFrog, and ConnectWise each contribute vulnerabilities that chain naturally. Defenders should evaluate these not as isolated patch tickets but as compound attack paths. Prioritization should reflect internet exposure, supply-chain position, and whether the affected system holds credentials or secrets that grant lateral movement opportunity.

Sources: CISA KEV Catalog · CISA BOD 26-04 · Cisco Security Advisory — AsyncOS SEG · JFrog Security Advisories · ConnectWise Security Bulletins · GitLab Security Releases · MikroTik Security Advisories · Fortinet PSIRT Advisories

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


Hacking Editorial Brief — September 15, 2026

Revolut Social Engineering Attack Exposes Nearly 700 Customer Records

Fintech platform Revolut disclosed that attackers successfully social engineered company personnel into handing over private customer data for nearly 700 users. The threat actors impersonated government officials to deceive Revolut staff into providing customer IDs, addresses, and other personal details. The incident occurred over the weekend and represents a targeted social engineering campaign exploiting human rather than technical vulnerabilities. Revolut has contacted affected customers, though the full scope of data misuse and whether additional financial fraud has occurred remains under investigation. The breach highlights persistent risks in customer service and compliance workflows where impersonation tactics can bypass technical security controls.

Canadian National Pleads Guilty to Breaching 165 Companies, Exposing 100 Million Records

A 26-year-old Canadian hacker has pleaded guilty to compromising 165 companies in a campaign that began in early 2024 and exposed data linked to approximately 100 million individuals. The operation extended beyond directly targeted organizations, suggesting supply chain or third-party data aggregation as part of the broader exposure. Investigative work eventually led to identification and prosecution, though the guilty plea represents one of the larger-scale breach admissions in recent years by individual count and exposure volume. Details on the attack methodology, targeted sectors, and whether data was monetized or distributed remain limited in public reporting.

Sources: City AM · Financial Times · Times of India

📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://thehackernews.comSep 15

Russian-Linked Threat Actors Using AI to Exploit PaperCut NG/MF Vulnerabilities

A suspected Russian-speaking cyber actor has used artificial intelligence to devise exploits targeting recently disclosed security flaws in PaperCut N...

https://gbhackers.comSep 1

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campa...

https://www.bleepingcomputer.comJul 15

CISA Confirms Ransomware Gangs Abusing Microsoft SharePoint RCE Vulnerability

CISA confirmed that ransomware gangs have begun actively exploiting a high-severity Microsoft SharePoint remote code execution vulnerability since ear...

https://thehackernews.comSep 15

China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and ...

https://www.securityweek.comSep 14

Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

Chinese threat actors linked to UNC3569 are actively exploiting CVE-2026-51990 in Tencent's Sogou Input Method to deploy the GrayRabbit backdoor for c...

https://thehackernews.comSep 15

New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing

Intel takes the same position on physical attacks against server memory. Cybersecurity. Intel has separately said that physical interposer attacks of ...

https://cisoseries.comSep 14

Passkey phishing attack, Anthropic's report, airline cyber loophole - CISO Series

Airlines compliance with new cybersecurity regulations means fewer passenger conveniences. Starting next month, airlines whose flights are canceled or...

https://uk.finance.yahoo.comSep 14

Cybersecurity stocks get a jolt on gloomy AI warnings from CEOs of Anthropic and OpenAI

Shares of top cybersecurity names popped in pre-market trading amid fresh warnings from the biggest names in AI within the past two days. Okta (OKTA) ...


Updated daily