This month: 18 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2026-67277
MikroTik · RouterOS
MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
Detected Sep 10 · 3-day patch deadline
CVE-2025-25249
Fortinet · Multiple Products
Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
Detected Sep 9 · 3-day patch deadline
CVE-2026-19490
Citrix · NetScaler
Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
Detected Sep 9 · 3-day patch deadline

KEV Intelligence Brief — September 11, 2026

Prepared by: Cybersecurity Intelligence Team Distribution: Federal Contractors · DevOps & Platform Engineering · Security Operations Leadership Classification: TLP:WHITE

Eight new entries hit CISA's Known Exploited Vulnerabilities catalog across the past three days, spanning network infrastructure, enterprise security platforms, e-commerce storefronts, and end-user browsers. Several deadlines have already passed or expire this weekend. Operators should treat this brief as an immediate action document, not background reading.

Critical Infrastructure on the Edge: Network and Security Platform Authentication Bypasses

The most operationally severe cluster in this update targets the security infrastructure that organizations trust to enforce access control — and this week, that infrastructure is the attack surface.

Citrix NetScaler (CVE-2026-19490) and Cisco Secure Firewall Management Center / Security Cloud Control (CVE-2026-20079) both carry authentication-bypass vulnerabilities exploitable by unauthenticated remote attackers, and both carry a patch deadline of September 12 — tomorrow. The Citrix flaw is particularly insidious: any NetScaler appliance operating as an AAA virtual server or Gateway — SSL VPN, ICA Proxy, CVPN, or RDP Proxy — is in scope. The Cisco FMC/SCC vulnerability goes further, enabling unauthenticated execution of script files with root access to the underlying OS. If your firewall management console is internet-reachable or accessible from a compromised network segment, assume adversaries have already enumerated it.

Compounding this, MikroTik RouterOS contributes two vulnerabilities added September 10 with a near-impossible September 13 patch deadline: CVE-2026-67277 (missing authentication on the btest service, enabling kernel memory disclosure and denial of service) and CVE-2026-86060 (argument delimiter injection enabling policy mask manipulation and privilege escalation). MikroTik devices are ubiquitous in SMB environments, ISP edge deployments, and — critically — inside federal contractor networks where they are frequently undermanaged. The combination of these two flaws is particularly dangerous: CVE-2026-67277 can expose kernel memory useful for defeating ASLR or harvesting credentials, while CVE-2026-86060 enables an attacker who gains initial access to escalate by rewriting trusted policy configurations.

Immediate actions for this cluster: Audit all internet-exposed NetScaler, Cisco FMC/SCC, and MikroTik devices now. For Cisco FMC, verify that management interfaces are not reachable from untrusted networks — there is no acceptable operational justification for public exposure of a firewall management console. For MikroTik, disable the btest service if it is not operationally required and apply firmware patches on an emergency change basis. Rotate credentials on all accounts associated with these platforms regardless of confirmed exploitation status. BOD 26-04 obligations for federal agencies are non-negotiable here given the sub-72-hour deadlines.

Deadline Already Expired: Fortinet Multi-Product RCE and Adobe Commerce Injection

Two entries demand immediate retrospective review because their CISA-mandated deadlines have already passed.

Fortinet (CVE-2025-25249) covers FortiOS, FortiSwitchManager, and FortiSASE — a broad swath of Fortinet's portfolio. The heap-based buffer overflow allows remote code execution via specially crafted packets, with a patch deadline of September 12 (passed as of today). Fortinet vulnerabilities have been a persistent favorite of nation-state actors, particularly those targeting government and critical infrastructure. If your Fortinet environment has not been patched, treat it as potentially compromised: conduct forensic triage per CISA's requirements under BOD 26-04, review authentication logs for anomalous API calls or configuration changes, and consider isolating affected appliances from management networks while patching proceeds.

Adobe Commerce and Magento Open Source (CVE-2026-75650) carried a September 11 deadline — today — and represents a template injection vulnerability enabling arbitrary code execution. E-commerce platforms running Adobe Commerce are high-value targets for skimming operations and supply-chain compromise. Any organization still unpatched at this moment should take storefronts offline or place them behind a WAF with emergency ruleset updates while patching is completed. Payment data environments adjacent to unpatched Magento instances should be treated as potentially exposed, and PCI-DSS incident response procedures should be evaluated.

Deadline Watch: Browser Attack Surface and Windows Privilege Escalation

Two additional entries carry later deadlines but warrant proactive action given their breadth of exposure.

Google Chromium V8 (CVE-2026-87491) is an out-of-bounds write vulnerability enabling arbitrary code execution inside the sandbox via a crafted HTML page. The September 23 deadline may feel distant, but this flaw affects every Chromium-based browser — Chrome, Edge, Opera, and derivatives — meaning virtually every knowledge worker endpoint in your environment is in scope. Browser vulnerabilities at the V8 engine level are regularly weaponized in watering-hole and spearphishing campaigns within days of public disclosure. Push this update through your endpoint management tooling now rather than waiting for the deadline.

Microsoft Windows Update Stack (CVE-2026-81963) is a link-following vulnerability enabling local privilege escalation to SYSTEM, with a September 22 deadline. While this requires local access — lowering the immediate remote threat — it is a critical second-stage capability. In environments where initial access via any of the above remote vulnerabilities is achieved, a local privilege escalation to SYSTEM on Windows endpoints dramatically accelerates attacker dwell time and persistence. Prioritize patch deployment through WSUS or Intune, and audit for suspicious scheduled tasks or service modifications in the interim.

Summary Deadline Table

| CVE | Vendor / Product | Deadline | Status | |---|---|---|---| | CVE-2026-75650 | Adobe Commerce / Magento | Sep 11 | Past due today | | CVE-2025-25249 | Fortinet (FortiOS, FortiSwitchManager, FortiSASE) | Sep 12 | Expires tomorrow | | CVE-2026-19490 | Citrix NetScaler | Sep 12 | Expires tomorrow | | CVE-2026-20079 | Cisco FMC / SCC | Sep 12 | Expires tomorrow | | CVE-2026-67277 | MikroTik RouterOS | Sep 13 | Expires Sunday | | CVE-2026-86060 | MikroTik RouterOS | Sep 13 | Expires Sunday | | CVE-2026-81963 | Microsoft Windows | Sep 22 | Monitor | | CVE-2026-87491 | Google Chromium V8 | Sep 23 | Monitor |

Sources: CISA KEV Catalog · CISA BOD 26-04 · Fortinet PSIRT Advisories · Citrix Security Bulletins · Cisco Security Advisories · MikroTik Security Announcements · Adobe Security Bulletins · Google Chrome Releases · Microsoft Security Update Guide

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


Hacking Editorial Brief — September 11, 2026

AI Agents Execute Coordinated Attack on PaperCut Infrastructure

Blackpoint Cyber and GreyNoise identified an active campaign deploying hundreds of AI agents to exploit zero-day vulnerabilities in PaperCut NG and PaperCut MF print management software. The attack represents a tactical shift from individual AI-assisted exploitation to coordinated swarm tactics, with researchers documenting automated reconnaissance, vulnerability scanning, and exploitation across multiple targets simultaneously. Anthropic separately confirmed that AI capabilities now enable lone operators to sustain attack campaigns previously requiring teams of skilled personnel, validating concerns that AI tools are fundamentally altering the economics and scale of offensive operations.

Florida Driver License Database Compromised, Internet Archive Breach Exposes 31 Million Records

Threat actors claimed access to Florida's driver license database, with stolen records appearing on multiple cybercrime monitoring platforms, though the full scope and legitimacy of the breach remain under investigation. Separately, the Internet Archive confirmed a September 2026 breach exposing over 31 million files including email addresses and usernames, with pro-Palestinian actors conducting concurrent DDoS attacks against the platform. The incidents underscore continued targeting of government identity systems and large-scale data repositories.

US Lawmakers Push Sanctions Against Indian Hack-for-Hire Firms

Three U.S. lawmakers formally called on the American government to blacklist multiple Indian IT firms over documented hack-for-hire operations, escalating legislative pressure on commercial surveillance vendors. The move follows broader efforts to disrupt the mercenary spyware ecosystem and comes as the industry faces increased scrutiny over targeting of journalists, activists, and political figures. Meanwhile, commercial AI tools failed to defend Hugging Face against OpenAI's sanctioned attack during testing, with researchers concluding that open-weight models offer more effective security than proprietary detection systems in adversarial scenarios.

Sources: Hackread · SiliconANGLE · WWSB · Cybersecurity News · KFGO · Financial Times

📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://www.pravda.com.uaSep 11

Russian hackers used Claude AI to target Ukrainian government and military – Anthropic

Anthropic says Russian hackers linked to Midnight Blizzard used Claude AI in a cyber-espionage campaign targeting Ukrainian government, ...

https://techcrunch.comSep 10

ID verification giant IDScan confirms data breach with more than 150 million driver's licenses stolen

IDScan confirmed a data breach involving theft of driver's licenses and other government-issued identification documents from its cloud storage.

https://www.bbc.comSep 10

AI is becoming harder to control – can humans stay in charge? - BBC

AI agents went on an uncontrolled hacking spree, leaving some in the industry worried.

https://www.aljazeera.comSep 10

Anthropic discloses 4th AI hacking incident as researcher quits over safety - Al Jazeera

Claude Opus 4.6 hacked third-party systems during testing, adding to Anthropic's mounting security breaches.

https://cybersecuritynews.comSep 10

Internet Archive Breach Exposes 31 Million Files

Attackers breached the Internet Archive's systems in September 2026, exposing over 31 million files including email addresses and usernames, with invo...

https://www.geekwire.comSep 10

Amazon's new board member is a cybersecurity founder who sold his last company to ...

Amazon added a cybersecurity specialist to its board in 2020, when it elected Alexander, who also led U.S. Cyber Command. Mandia comes from the other ...

https://media.defense.govAug 26

China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure

Defense Department document details that QTFY, attributed to Nanjing Xinjiuwei Network Technology Co., is an enabling company for PRC cyber operations...

https://shattered.ioSep 2

Iran-Linked Hackers Target U.S. Critical Infrastructure in Water, Telecom, and Energy Sectors

Iranian government-linked hackers are conducting widespread attempts to breach systems tied to water utilities, telecommunications networks, and energ...


Updated daily