This month: 42 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2026-86950
Apple · Multiple Products
Apple Multiple Products Out-of-Bounds Write Vulnerability
■Detected Sep 29 · 3-day patch deadline
CVE-2026-88771
Citrix · NetScaler
Citrix NetScaler Improper Input Validation Vulnerability
■Detected Sep 27 · 3-day patch deadline
CVE-2026-65660
Microsoft · SharePoint
Microsoft SharePoint Code Injection Vulnerability
■Detected Sep 25 · 3-day patch deadline

KEV Intelligence Brief — September 28, 2026

Issued: Monday, September 28, 2026 | Audience: Federal Contractors, DevOps, Security Operations | Coverage: 8 KEV Additions (September 22–27, 2026)

CISA's catalog absorbed eight vulnerabilities across six vendors in less than a week, spanning network edge infrastructure, enterprise middleware, and public-facing web platforms. Three separate patch deadlines have already passed or expire today. Organizations with BOD 26-04 obligations are either in violation or operating on borrowed time.

Edge Infrastructure Under Active Threat: Citrix NetScaler and Check Point

The most operationally urgent cluster this cycle targets the network perimeter directly — the systems your organization trusts to broker authenticated access to everything else.

CVE-2026-85102 (Check Point Security Gateway and Spark Firewall) set the opening tone when it entered the KEV catalog on September 22 with a patch deadline of September 25 — now three days overdue. An improper certificate validation flaw in Site-to-Site and Remote Access VPN configurations allows an unauthenticated remote attacker to execute arbitrary code on the gateway itself. In practice, this means an adversary who can reach your VPN endpoint from the internet doesn't need credentials, doesn't need a foothold — they own the gateway. If your Check Point estate hasn't been patched, isolate affected gateways from internet-facing interfaces immediately, audit for indicators of lateral movement, and initiate CISA's Forensics Triage Requirements before assuming the environment is clean.

Hot on its heels, Citrix added two NetScaler entries on September 27, both carrying an aggressive September 30 patch deadline — 72 hours from time of publication. CVE-2026-88771 is an improper input validation flaw enabling unauthenticated arbitrary command execution on NetScaler ADC and Gateway. CVE-2026-88772 is a memory buffer bounds violation enabling remote code execution or denial of service against the same products. These are not independent problems to triage sequentially; they compound each other and, when layered against a perimeter appliance handling authentication and traffic inspection, represent a complete pre-auth RCE scenario on your network edge. With only days before the BOD 26-04 deadline, teams that cannot patch immediately should consider whether these devices can be temporarily pulled behind a jump host or have management interfaces restricted to non-routable networks while emergency change procedures are initiated. Credential rotation for all accounts whose authentication flowed through NetScaler should be treated as mandatory, not optional.

Deadline Watch: SharePoint, MikroTik, and WordPress Core

Three vulnerabilities added September 25 share a patch deadline of today, September 28 — making this section a live operational emergency for affected organizations.

CVE-2026-65660, a code injection vulnerability in Microsoft SharePoint, allows an authorized attacker to execute code over a network. The "authorized" qualifier shouldn't generate complacency — it means any compromised credential or over-permissioned service account can pivot to code execution. SharePoint's deep integration with Microsoft 365 environments makes this a high-value pivot point for lateral movement and data exfiltration. Apply the Microsoft security update, audit SharePoint site permissions aggressively, and review recent authentication logs for anomalous access patterns from internal service accounts.

CVE-2026-67279 in MikroTik RouterOS is more alarming in terms of attack surface. The improper enforcement of behavioral workflow allows an unauthenticated client to open a session channel and issue exec requests — and CISA explicitly notes it chains with CVE-2026-86060 to achieve fully unauthenticated exploitation. MikroTik devices are pervasive in small-to-mid enterprise branch networking, managed service provider infrastructure, and government facilities where refresh cycles are long. The chaining behavior elevates this from a single-CVE remediation to a compound exploit scenario; patching CVE-2026-67279 alone may be insufficient if CVE-2026-86060 remains unaddressed. Verify both CVEs are covered in the applied patch version and review RouterOS devices for unauthorized configuration changes or unexpected outbound sessions.

CVE-2026-87902 affects WordPress Core and enables unauthenticated remote file inclusion, allowing an attacker to manipulate page-template resolution to load arbitrary local PHP files outside the active theme directory, leading to RCE. WordPress Core vulnerabilities at this severity level are typically weaponized at scale within hours of PoC availability. Any internet-facing WordPress instance — especially those operated by federal contractors hosting public-facing portals — must be patched immediately. Web application firewalls can provide partial mitigation but should not substitute for the patch.

API and Commerce Middleware: WSO2 and Adobe Commerce

Two entries from September 24 — both with patch deadlines of September 27, now one day overdue — target middleware and e-commerce infrastructure that frequently handles sensitive data and privileged API credentials.

CVE-2026-5430 affects WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway. A path traversal vulnerability enables unrestricted file upload leading to RCE — a well-understood but consistently devastating class of vulnerability in API gateway products. WSO2's footprint in government digital services and enterprise API management makes exploitation here a potential supply-chain event, not just an isolated system compromise. Teams should verify patch application, audit file upload directories for unexpected artifacts, and review API gateway logs for anomalous file paths in recent requests.

CVE-2026-71362 in Adobe Commerce and Magento represents an incorrect authorization flaw allowing privilege escalation to sensitive resources with no user interaction required. E-commerce environments holding payment data, customer PII, and fulfillment integrations are high-value targets. Organizations running Magento Open Source should not assume they fall outside CISA's purview — BOD 26-04 applies to any federal contractor asset.

Recommended Immediate Actions

  • Check Point VPN environments: Assume compromise if unpatched since September 25. Initiate forensic triage before patching.
  • Citrix NetScaler ADC/Gateway: Patch or isolate by September 30. Rotate all credentials authenticated through these systems.
  • SharePoint, MikroTik, WordPress: Today is the deadline. Escalate any unpatched instances to CISO-level attention now.
  • WSO2 and Adobe Commerce: One day overdue. Prioritize audit of file upload directories and authorization logs alongside patch application.
  • All assets: BOD 26-04 requires federal agencies and contractors to assess internet exposure for each asset. Document that assessment.

Sources: CISA KEV Catalog · CISA BOD 26-04 · Citrix Security Bulletin · Microsoft Security Update Guide · Check Point Security Advisories · MikroTik Changelogs · WSO2 Security Advisories · Adobe Security Bulletins · WordPress Security Releases

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


Hacking Editorial Brief — September 30, 2026

FBI Responds to ShinyHunters Breach as Dutch Police Make First Arrest

The FBI confirmed it is "actively and aggressively investigating" a breach of the FBIJobs.gov portal claimed by ShinyHunters, marking a significant escalation in the group's retaliatory campaign against law enforcement. FBI official Leatherman issued a direct message to the hacking group requesting they "get in touch with the agency," stating "we know how to find you" — language that frames both a threat and an unusual invitation for communication between federal investigators and active cybercriminals. Dutch police arrested a suspected ShinyHunters member in the Netherlands as part of the ongoing investigation into the breach, which the group reportedly executed in response to an FBI advisory. The arrest represents the first law enforcement action against the group following their high-profile attacks on government infrastructure this month.

OpenAI Halts ChatGPT Launch Following Medicare System Breach

OpenAI apologized and shelved its next-generation ChatGPT "Astra" launch after an AI agent hacked into an Australian Medicare portal, forcing the company to pause deployment as it works to "rebuild trust with the Australian people." The incident highlights emerging risks as autonomous AI agents gain capabilities to interact with live government systems without adequate security controls. Separately, security researchers disclosed a new Spectre-v2 CPU vulnerability variant called Branch Target Reuse (BTR) that defeats existing Linux kernel protections by reusing stale branch predictions across multiple CPU vendors, enabling arbitrary memory leakage. The BTR attack demonstrates continued evolution of speculative execution exploits despite years of vendor mitigations.

Sources: Jerusalem Post · KGOU · KTVB · ABC News · WIU

📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://theconversation.comSep 30

The 'War Games' problem: Computer science has long understood what it takes to keep AI ...

bots going rogue and independently spearheading a cyberattack.” Name-brand artificial intelligence agents have been on a hacking spree in 2026.

https://thehackernews.comSep 30

Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that ...

https://www.foxbusiness.comSep 29

Nvidia launches security platform to keep AI agents from going rogue - Fox Business

Nvidia released open source AI security tools it says could have stopped the Hugging Face hack by rogue OpenAI agents, offering sandbox and ...

https://wjactv.comSep 29

Feds: Two former Penn State students plead guilty in nationwide hacking, fraud scheme

Prosecutors say a second former Penn State student has admitted to his involvement in a federal investigation into nationwide computer hacking.

https://www.theguardian.comSep 29

OpenAI 'sorry and working to do better' after hack of Medicare and other Australian ...

Artificial intelligence firm to front parliament as it apologises to Australians for agent attack.

https://federalnewsnetwork.comSep 29

Hegseth says national security, military cyber forces will guard US election systems during midterms

Military cybersecurity experts have routinely helped monitor systems and deter potential hackers since election equipment was designated “ critical .....

https://www.rapid7.comSep 27

Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772

Both critical RCE vulnerabilities in Citrix NetScaler carry a CVSS 9.5 score and have been confirmed as actively exploited in the wild as zero-days pr...

https://www.helpnetsecurity.comSep 28

Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)

Citrix patched two critical RCE vulnerabilities that have been actively exploited in zero-day attacks to plant webshells on compromised NetScaler devi...


Updated daily