This month: 30 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2026-7273
Zyxel · GS1900 Series Switches
Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
Detected Sep 21 · 3-day patch deadline
CVE-2025-39682
Linux · Kernel
Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
Detected Sep 18 · 3-day patch deadline
CVE-2026-58704
Google · Pixel
Google Pixel Improper Authorization Vulnerability
Detected Sep 16 · 3-day patch deadline

KEV Intelligence Brief — September 22, 2026

Issued by: Security Operations Intelligence | TLP: WHITE Reporting Period: September 14–21, 2026 | CVEs Covered: 8

Critical Infrastructure Under Active Siege: Cisco, Zyxel, and the Perimeter Collapse

The most operationally urgent entries in this week's KEV additions center on internet-facing infrastructure where unauthenticated attackers can achieve remote code execution or full administrative bypass — with little to no prerequisite access.

CVE-2026-76461 — Cisco Secure Email Gateway SQL Injection — carries the earliest expired deadline in this batch: September 17. If your organization runs Cisco AsyncOS on SEG appliances and has not patched, assume compromise is possible. This is not a theoretical escalation path; a SQL injection yielding unauthenticated root-level OS command execution on an email gateway places an attacker directly inside your mail flow, where credential harvesting, phishing infrastructure injection, and lateral movement are trivial next steps. Isolate any unpatched SEG instances from internal mail relays immediately, rotate service account credentials associated with the gateway, and conduct forensic triage per CISA's BOD 26-04 requirements before returning the appliance to production.

CVE-2026-76460 — Cisco Identity Services Engine Incorrect Use of Privileged APIs — shares the September 19 deadline and deserves equal alarm. ISE and ISE-PIC are authentication and policy enforcement backbones for many federal and enterprise networks. An unauthenticated remote attacker bypassing the web-based management interface effectively inherits the trust posture of your entire NAC infrastructure — network segmentation policies, device profiling, and RADIUS authentication all become adversary-controlled. If your ISE management interface is reachable from untrusted segments, firewall it off now. Patching is non-negotiable under BOD 26-04; organizations that cannot patch immediately must document compensating controls and escalate.

CVE-2026-7273 — Zyxel GS1900 Series Stack-Based Buffer Overflow — adds a hardware layer to the perimeter problem. Though the attack vector is LAN-based, the unauthenticated nature of this CGI exploit means any device already on the local network — a compromised endpoint, a rogue IoT device, or a contractor laptop — can pivot through a GS1900 switch to execute OS commands. These switches are broadly deployed in SMB and government branch environments precisely where network segmentation is least mature. The September 24 deadline is the only one in this batch that remains ahead of today's date, giving teams a narrow window to push firmware updates before CISA's compliance clock expires.

Linux Kernel: Three Exploited Flaws, One Overdue Deadline

Three separate Linux Kernel vulnerabilities added on September 18 share a September 21 deadline that is now past. This clustering is significant — it signals that threat actors are actively chaining or independently exploiting kernel-level primitives, and organizations running unpatched Linux distributions are already operating outside BOD 26-04 compliance.

CVE-2025-39682 targets the TLS receive path, where a zero-length record can bypass recvmsg() record-type handling, corrupting zero-copy and queuing assumptions for subsequent TLS records. In high-throughput environments — containerized microservices, Kubernetes ingress controllers, or TLS-terminating proxies — this could be leveraged to manipulate encrypted traffic processing at the kernel level. CVE-2025-39964 is a race condition on AF_ALG sockets, the kernel's cryptographic API interface. Concurrent writes cause unpredictable data interleaving, creating exploitable inconsistencies in socket state — a meaningful risk on multi-tenant systems where shared cryptographic operations are common. CVE-2026-53266 is the most structurally dangerous of the three: an out-of-bounds write in the ebtables SNAT target, where an ARP rewrite operation can corrupt a splice-imported file page in a nonlinear socket buffer. This type of memory corruption primitive is precisely what kernel exploit chains are built around.

CISA explicitly flags that affected kernel versions may be end-of-life. DevOps and platform engineering teams should audit their base images, container runtimes, and VM templates immediately. Transitioning to a supported, patched kernel is the only sustainable remediation — backporting is not viable on EoL branches. For teams operating under change-freeze conditions, runtime exploit mitigations such as seccomp profiles, SELinux/AppArmor enforcement, and network namespace isolation provide meaningful — though incomplete — compensating controls.

Privilege Escalation at the Edge: Mobile, Backup, and Identity Tooling

Three September 16 additions round out the week by targeting the supporting infrastructure that security teams often treat as lower-risk — and attackers do not.

CVE-2026-58704 — Google Pixel Improper Authorization in the cellular modem — represents the intersection of mobile device management and physical security risk. The vulnerability's logic error allows privilege escalation through the modem layer, outside the Android permission model. Organizations issuing Pixel devices to personnel with access to classified or sensitive systems should treat this as a high-priority MDM push. The September 19 deadline has passed; verify patch status through your EMM console today.

CVE-2026-87886 — Acronis Backup Incorrect Default Permissions for its cPanel/WHM and Plesk plugins — is a quiet but dangerous supply-chain pivot point. Backup agents operate with elevated system privileges by design, and misconfigured default permissions create a reliable local privilege escalation path. Hosting providers and managed service providers using these plugins should audit file system permissions against vendor hardening guidance immediately, as exploitation could grant an attacker root or SYSTEM access on backup infrastructure touching multiple client environments.

Taken together, this week's KEV additions form a coherent attack surface map: perimeter bypass via Cisco and Zyxel, kernel-level exploitation via Linux, and privilege escalation through mobile, backup, and identity tooling. No single patch resolves the exposure — security leaders should treat this batch as a coordinated remediation sprint, not a routine patch cycle.

Sources: CISA KEV Catalog · Cisco Security Advisories · Zyxel Security Advisories · Google Android Security Bulletins · Acronis Security Advisories · Linux Kernel CVE Tracker · CISA BOD 26-04

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


Hacking Editorial Brief — September 22, 2026

ShinyHunters Breaches Clop Ransomware Gang's Infrastructure

Threat actor ShinyHunters has successfully compromised the infrastructure of rival ransomware operation Clop, breaching the gang's leak site and threatening to expose victim payment data. The breach represents an unusual case of one cybercriminal group targeting another's operational infrastructure, creating secondary risks for organizations that may have previously paid ransoms to Clop. The incident raises concerns about the security of sensitive negotiation and payment records held by ransomware operations, which could be weaponized for further extortion or exposed publicly. ShinyHunters' ability to penetrate Clop's systems underscores vulnerabilities even within established criminal infrastructure.

Russian Actor Leverages AI to Exploit PaperCut Vulnerabilities at Scale

A suspected Russian-speaking threat actor has been observed using artificial intelligence to develop exploits targeting recently disclosed vulnerabilities in PaperCut NG/MF print management software, successfully compromising hundreds of instances. The campaign demonstrates operationalization of AI tools for exploit development and deployment at scale, representing a tactical evolution in how threat actors accelerate weaponization of disclosed vulnerabilities. The targeting of PaperCut, widely deployed in enterprise and education environments, suggests the actor is focused on broad access rather than specific vertical targeting. The incident follows broader industry concerns about AI-assisted offensive capabilities, now confirmed in active operations.

Supply Chain Attack Compromises Popular Python Face-Swapping Application

Attackers successfully injected a malicious dependency into Deep-Live-Cam, a Python-based face-swapping tool with 96,600 GitHub stars, in a supply chain attack targeting the project's dependency chain. The compromise demonstrates continued threat actor focus on open-source projects with large user bases as vectors for downstream attacks. The method of injecting malicious source dependencies rather than compromising the primary codebase reflects sophisticated understanding of software supply chain trust relationships and build processes.

Sources: Dark Reading · The Hacker News · Malware Patrol

📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://www.cybersecuritydive.comAug 26

Federal Authorities Disrupt China-Backed Hacking Operation Targeting US Critical Infrastructure

The FBI and Department of Justice seized domains linked to QTFY, a China-nexus hacking operation that targeted multiple federal agencies and critical ...

https://thehackernews.comSep 18

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

Microsoft released fixes for a maximum-severity CVSS 10.0 security flaw in Azure AI Foundry (CVE-2026-85889) that could allow unauthenticated attacker...

https://thehackernews.comSep 20

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

The Hacker News has contacted Hacktron with questions about how the forum code execution was achieved and about the scope of the account access. What ...

https://www.theregister.comSep 17

Cisco ISE Authentication Bypass Under Active Exploit - CVE-2026-76460

Cisco disclosed CVE-2026-76460, an authentication bypass affecting Identity Services Engine (ISE) that allows unauthenticated remote attackers to exec...

https://www.geo.tvSep 19

Google's Gemini goes rogue, hacks real company systems during key cybersecurity test

Google's Gemini model accessed the internet and hacked other companies during a test of its cybersecurity capabilities, the first known example of the...

https://www.wsj.comSep 18

Hackers Used Anthropic's Claude to Break Into OpenAI - WSJ

The hack demonstrates the complexity of defending corporate secrets in the age of AI hacking, said Joshua Saxe, the chief technology officer with ...

https://thehackernews.comSep 18

Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

"At this time, there is no indication that this vulnerability has been exploited in the wild," the notice said. The U.S. Cybersecurity and ...

https://www.wsj.comSep 17

What Companies Actually Need as Cybersecurity Risks Rise - WSJ

But according to one cybersecurity CEO, having the right technology for defense isn't necessarily the problem. It's the humans who need to step up— .....


Updated daily