CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief — September 14, 2026
Prepared by: Cybersecurity Intelligence Team Distribution: Federal Contractors · DevOps & Platform Engineering · Security Operations Leadership Reference Period: KEV Additions September 9–11, 2026
Eight vulnerabilities added to the KEV catalog in the past five days span your network perimeter, your remote access infrastructure, and your software supply chain simultaneously. Three patch deadlines have already passed as of today. This is not a backlog problem — it is an active exposure problem.
Deadline Overdue: Network and Remote Access Infrastructure Under Active Exploitation
Four vulnerabilities affecting perimeter and remote access products carry deadlines that have already expired or expire today, making immediate action the only acceptable posture.
CVE-2025-25249 (Fortinet FortiOS, FortiSwitchManager, FortiSASE — deadline September 12) is the most broadly impactful of the group. A heap-based buffer overflow triggered by specially crafted packets enables unauthenticated remote code execution across three distinct Fortinet product lines. Organizations running FortiOS as their primary firewall OS should treat any unpatched perimeter node as fully compromised until forensic triage confirms otherwise. CISA's BOD 26-04 forensic triage requirements are explicitly invoked here — log collection and integrity verification should precede patch application where operationally feasible.
CVE-2026-19490 (Citrix NetScaler ADC and NetScaler Gateway — deadline September 12) allows an unauthenticated remote actor to bypass authentication entirely via an alternate path or channel when the appliance is configured as an AAA virtual server, SSL VPN gateway, ICA Proxy, CVPN, or RDP Proxy. The attack surface here is enormous: NetScaler Gateway is one of the most widely deployed remote access solutions in federal and enterprise environments. Any organization still running an unpatched NetScaler in gateway mode is effectively operating with no authentication enforcement on their perimeter. Isolate, patch, rotate all session tokens and service account credentials associated with the gateway, and audit recent authentication logs for anomalous access patterns.
CVE-2026-67277 and CVE-2026-86060 (MikroTik RouterOS — deadline September 13, now past) form a two-vulnerability chain that should be evaluated together. The first allows kernel memory disclosure and denial of service via the unauthenticated btest service — a network performance testing function that has no business being exposed to untrusted networks. The second permits argument delimiter injection that alters the trusted RouterOS policy mask, enabling privilege escalation from an authenticated but low-privilege context. Chained, these bugs move an attacker from unauthenticated network access to elevated routing control. MikroTik devices are prevalent in distributed enterprise branch networks and OT-adjacent environments; exposure should be audited aggressively, and the btest service should be disabled on all internet-adjacent interfaces immediately regardless of patch status.
Developer Toolchain Under Siege: JFrog and GitLab Vulnerabilities Targeting the Pipeline
Three vulnerabilities added September 11 directly threaten software development infrastructure — the systems used to store, build, and version the code your organization ships or depends on.
CVE-2026-42016 and CVE-2026-42018 (JFrog Artifactory — deadline September 25) are functionally complementary. CVE-2026-42016 represents an incorrect authorization flaw where token validation checks the signature and issuer but not the token's scope, enabling privilege escalation by a user who can obtain or forge a token with an elevated scope claim. CVE-2026-42018 compounds this: even with anonymous access disabled, an unauthenticated caller can elicit an internal anonymous-user token from the API. Together, these bugs mean that an external attacker who can reach your Artifactory instance may be able to enumerate artifacts, inject malicious packages, or escalate to administrative access — a direct supply chain risk. Organizations using Artifactory as a self-hosted binary repository for CI/CD pipelines should treat this as a supply chain integrity event, not merely a software vulnerability. Audit repository access logs retroactively, rotate all API tokens, and review any packages published in the past 30 days for unauthorized modifications.
CVE-2026-85706 (GitLab CE/EE — deadline September 14, today) enables an unauthenticated user to read arbitrary files via path traversal in the repository commits API due to improper path confinement and missing authentication enforcement. An unauthenticated file read on a GitLab instance can expose source code, CI/CD pipeline secrets, .env files, SSH keys, and deployment credentials stored within repositories. For self-managed GitLab deployments, this is a critical-priority patch. If patching cannot be completed today, restrict the commits API endpoint at the network layer and audit web server access logs for traversal patterns (e.g., ../ sequences in API paths).
Remote Management Weaponized: ConnectWise ScreenConnect
CVE-2026-84869 (ConnectWise ScreenConnect — deadline September 14, today) enables an attacker to perform file transfer and arbitrary execution through an active remote session without authorization or host confirmation. Unlike typical RMM vulnerabilities that require credential theft, this flaw bypasses the host-side confirmation dialog entirely — the mechanism that gives endpoint operators visibility into what is being done on their machines. In managed service provider (MSP) environments, a single compromised or attacker-controlled ScreenConnect session could be weaponized laterally across an entire managed client base. MSPs and IT service providers should treat this as a critical operational risk. Patch immediately, review all active and recent session logs, and verify that no unauthorized file transfers or executions occurred in the past 72 hours.
Operational Summary
| CVE | Product | Deadline | Status | |---|---|---|---| | CVE-2025-25249 | Fortinet FortiOS/FortiSwitchManager/FortiSASE | Sep 12 | OVERDUE | | CVE-2026-19490 | Citrix NetScaler | Sep 12 | OVERDUE | | CVE-2026-67277 | MikroTik RouterOS | Sep 13 | OVERDUE | | CVE-2026-86060 | MikroTik RouterOS | Sep 13 | OVERDUE | | CVE-2026-84869 | ConnectWise ScreenConnect | Sep 14 | DUE TODAY | | CVE-2026-85706 | GitLab CE/EE | Sep 14 | DUE TODAY | | CVE-2026-42016 | JFrog Artifactory | Sep 25 | 11 days remaining | | CVE-2026-42018 | JFrog Artifactory | Sep 25 | 11 days remaining |
All eight vulnerabilities carry BOD 26-04 obligations for federal agencies and contractors. Internet-exposed instances of any affected product should be treated as highest priority regardless of internal patch scheduling cycles.
Sources: CISA KEV Catalog · CISA BOD 26-04 · Fortinet PSIRT Advisories · Citrix Security Bulletins · JFrog Security Advisories · GitLab Security Releases · ConnectWise Security Advisories · MikroTik Security
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
Hacking Editorial Brief — September 14, 2026
China-Aligned Actors Exploit Tencent Input Method Flaw to Deploy GrayRabbit Malware
A China-aligned espionage group is actively exploiting CVE-2026-51990, a critical vulnerability in Tencent's Sogou Input Method application, to deploy GrayRabbit malware on compromised systems. The campaign targets the widely deployed Chinese language input software, enabling attackers to establish persistent access on affected endpoints. Separately, APT31 has been observed deploying the previously undocumented BlueMoon exploit kit, which chains vulnerabilities in Microsoft Windows and Google Chrome to compromise targets. The toolkit represents a shift toward modular, multi-stage exploit chains by advanced persistent threat groups focused on espionage operations. A Russian-speaking threat actor has also been attributed to exploiting PaperCut NG/MF vulnerabilities using AI-assisted techniques to breach hundreds of instances of the print management software.
Malicious Twitch Extension Exfiltrates OAuth Tokens From 31,000 Users
A malicious browser extension distributed through Twitch, identified as JeetBot, successfully exfiltrated OAuth tokens from nearly 31,000 users by transmitting credentials to operator-controlled proxy infrastructure. The campaign targeted Twitch users seeking additional platform functionality, harvesting authentication tokens that could enable account takeover and unauthorized access to linked services. Firefox version 85.8.7 now blocks the malicious behavior, though the scope of compromised accounts and potential downstream impact remains under investigation. The incident highlights ongoing risks associated with third-party browser extensions in gaming and streaming ecosystems.
Microsoft September Patch Tuesday Addresses Record 974 Flaws Including Two Exploited Zero-Days
Microsoft's September 2026 Patch Tuesday addressed 974 vulnerabilities, a record-breaking figure that includes two actively exploited zero-day flaws: CVE-2026-81963 and CVE-2026-85880. The volume represents a substantial increase from the 966 vulnerabilities disclosed in initial reporting and underscores escalating complexity across Microsoft's product stack. Both zero-days were under active exploitation at the time of disclosure, though Microsoft has not publicly attributed the campaigns or detailed exploitation scope.
Sources: Bleeping Computer · The Hacker News · The Hacker News · The Hacker News · Bleeping Computer
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
Passkey phishing attack, Anthropic's report, airline cyber loophole - CISO Series
Airlines compliance with new cybersecurity regulations means fewer passenger conveniences. Starting next month, airlines whose flights are canceled or...
Cybersecurity stocks get a jolt on gloomy AI warnings from CEOs of Anthropic and OpenAI
Shares of top cybersecurity names popped in pre-market trading amid fresh warnings from the biggest names in AI within the past two days. Okta (OKTA) ...
Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
JeetBot's Twitch extension sent OAuth tokens from nearly 31000 users to operator-controlled proxies; Firefox 85.8.7 stops the behavior.
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
Volexity detected Chinese threat actors UTA0560 and JungleBamboo exploiting a Chrome zero-day (CVE-2026-85046) and Windows kernel vulnerability in coo...
North Korean Hackers Exploit Windows Zero-Day in Operation Dream Job
North Korean hackers have been actively exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies.
Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an ...
Ukrainian hacker gets four years in US prison over Conti ransomware attacks
A Ukrainian national was sentenced to four years in a U.S. prison for his role in the notorious Conti ransomware operation, which targeted more ...
Anthropic blocks 'malicious use' of AI that could develop biological weapons - BBC
The revelations in Anthropic's threat intelligence report come after a former top researcher at the company warned of the risks of AI to humanity.
Updated daily
