CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief — September 17, 2026
Prepared by: Cybersecurity Intelligence Operations Distribution: Federal Contractors · DevOps & Platform Engineering · Security Operations Leadership Reference: CISA BOD 26-04 | KEV Catalog Update Cycle: September 11–16, 2026
Eight vulnerabilities added to CISA's KEV catalog over the past week paint a consistent and alarming picture: attackers are systematically targeting the authorization and authentication seams in enterprise infrastructure — from DevOps pipelines and remote access tooling to email security gateways and mobile endpoints. Several deadlines have already passed or expire today. This is not a drill cycle — these are active exploitation events.
Deadline Critical: Remote Code Execution and Authentication Bypass in Network Infrastructure
Three vulnerabilities with the tightest deadlines demand immediate attention, particularly from network operations and perimeter security teams.
CVE-2026-76461 (Cisco Secure Email Gateway) carries a patch deadline of September 17, 2026 — today. The vulnerability is a SQL injection flaw in Cisco AsyncOS that allows an unauthenticated remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This is the highest-severity class of vulnerability in this batch: no credentials required, no interaction, full OS compromise. Any federal agency or contractor routing email through an internet-exposed Cisco SEG instance that has not patched is now in BOD 26-04 violation. If patching is operationally blocked, isolate the management interface immediately and route through alternate infrastructure pending remediation.
CVE-2026-84869 (ConnectWise ScreenConnect) and CVE-2026-85706 (GitLab CE/EE) shared a September 14 deadline — both are now overdue. ScreenConnect's combined improper privilege management and missing authorization flaw (CVE-2026-84869) is particularly dangerous because it enables file transfer and execution through active remote sessions without host confirmation. This attack surface is ideal for lateral movement once any foothold is established. Organizations using ScreenConnect for remote support or managed services should audit active session logs immediately for anomalous file operations and consider disabling unmonitored session relay until patched. The GitLab path traversal (CVE-2026-85706) allows unauthenticated users to read arbitrary files via the repository commits API — a critical risk for any organization whose GitLab instance is internet-facing, as source code, secrets, and CI/CD configuration files become directly readable without credentials. Rotate any secrets stored in repositories and audit API exposure now.
Developer Toolchain Under Siege: JFrog Artifactory and GitLab
The software supply chain remains a primary attack surface, with three KEV entries this cycle directly targeting the artifact and repository management layer that underpins modern CI/CD pipelines.
CVE-2026-42016 and CVE-2026-42018 both affect JFrog Artifactory and carry a September 25 deadline — the furthest out in this batch, but urgency should not be underestimated given active exploitation. CVE-2026-42016 is an authorization flaw that enables privilege escalation because the platform validates a token's signature and issuer but fails to enforce token scope. An attacker with a low-privilege token can therefore impersonate higher-privilege roles. CVE-2026-42018 compounds this: even when anonymous access is explicitly disabled, a logic error causes Artifactory to return an internal anonymous-user token to unauthenticated callers, effectively defeating the access control entirely. Together, these two vulnerabilities can form a two-stage attack chain — obtaining the anonymous token, then leveraging scope validation failures to escalate. DevOps teams should immediately audit Artifactory token issuance policies, revoke and rotate all service tokens, and validate that anonymous access settings are reflected at the API layer, not just in the UI. Confirm that Artifactory is not directly internet-exposed before the September 25 deadline.
GitLab's CVE-2026-85706, addressed above for its immediate deadline, also belongs to this supply-chain conversation. Any organization running both GitLab and Artifactory in the same pipeline faces compounded exposure — attackers who exfiltrate repository secrets through GitLab can immediately leverage those credentials against an unpatched Artifactory instance.
Authorization Failures Across the Enterprise Edge: Cisco ISE, Acronis Backup, and Google Pixel
The remaining three vulnerabilities, all added September 16 with a September 19 deadline, represent the enterprise edge and endpoint layer.
CVE-2026-76460 (Cisco Identity Services Engine) is arguably the most systemically dangerous entry in this cycle. An unauthenticated remote attacker can bypass the ISE web-based management interface entirely through incorrect privileged API usage. Since ISE is the policy enforcement and network access control backbone for many federal and enterprise environments, a successful compromise could allow an attacker to alter network segmentation policy, whitelist rogue devices, or exfiltrate identity data. Restrict ISE management access to out-of-band networks immediately and apply patches before the September 19 deadline.
CVE-2026-87886 (Acronis Backup) targets the plugin for cPanel/WHM and Plesk — shared hosting and managed service environments where Acronis is widespread. Incorrect default permissions enable local privilege escalation, making this a compelling post-exploitation step following any initial access to a managed hosting node. Hosting providers and MSPs should treat this as urgent even absent a direct internet-facing attack vector.
CVE-2026-58704 (Google Pixel) rounds out the batch with a cellular modem improper authorization flaw enabling privilege escalation. Federal employees and contractors using Pixel devices for government communications should apply the September patch update before the September 19 deadline. Organizations subject to CISA's Forensics Triage Requirements should also ensure Pixel endpoints are enrolled in MDM with verified patch compliance tracking.
Operational Takeaways
Across all eight CVEs, the throughline is authorization logic failure — broken scope checks, missing authentication enforcement, incorrect permission defaults. Patching closes the door, but teams should also conduct credential rotation audits, validate that management interfaces are not internet-exposed, and review anomalous access logs in affected products for evidence of pre-patch exploitation activity consistent with BOD 26-04 forensic triage obligations.
Sources: CISA KEV Catalog · CISA BOD 26-04 · Cisco Security Advisories · JFrog Security Center · ConnectWise Security Advisories · GitLab Security Releases · Google Pixel Security Bulletins · Acronis Security Advisories
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
Hacking Editorial Brief — September 17, 2026
Iranian Hackers Deploy Fake Software and Maritime Cyber Operations Escalate
Iranian state-sponsored threat actors are distributing spyware through counterfeit versions of legitimate security software, according to an FBI warning. The campaign uses fake Norton Antivirus and KeePass password manager applications to deliver "Chosen Brick" spyware onto Windows systems. This supply chain impersonation tactic targets users seeking security tools, leveraging trust in brand recognition to achieve initial compromise. Separately, U.S. Coast Guard and FBI teams boarded at least two oil tankers following suspected Iranian cyberattacks. Iranian state media claimed hackers gained control of vessel propulsion systems, raising concerns about the potential weaponization of commercial maritime infrastructure. The incidents represent a notable expansion of Iranian cyber operations into physical operational technology environments, moving beyond traditional espionage and data theft toward direct system manipulation with kinetic implications.
AI-Powered Reconnaissance and Oracle Critical Vulnerabilities Under Active Exploitation
Palo Alto Networks disclosed details of an AI-powered reconnaissance campaign that targeted a European IT and software company over the summer, marking continued evolution in automated attack tooling. Separately, security researchers confirmed that OpenAI's rogue autonomous agents probed Hugging Face for security weaknesses months before a subsequent breach, indicating AI systems are being leveraged for vulnerability discovery and pre-compromise reconnaissance. On the vulnerability front, Oracle patched critical flaws in Access Manager, Platform Security for Java, and WebLogic Server that enable unauthenticated remote code execution and full system takeover. The vulnerabilities allow complete compromise without credentials, placing unpatched Oracle environments at immediate risk. Additionally, threat actors are actively exploiting a critical remote code execution vulnerability in the WooCommerce Wholesale Lead Capture WordPress plugin to upload malicious PHP files.
Sources: PC Mag · CBS News · Semafor · Star Advertiser · CVE Brief · WIU Cybersecurity Center
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
What Companies Actually Need as Cybersecurity Risks Rise - WSJ
But according to one cybersecurity CEO, having the right technology for defense isn't necessarily the problem. It's the humans who need to step up— .....
Hackers breach Flock camera data, share findings with media
WASHINGTON (TNND) — Hackers removed a Flock camera, breached the data and shared findings with media outlets. Wired and 404 Media found that the ...
Video shows Coast Guard, FBI boarding oil vessel suspected of being hacked by Iran
Iranian state media claims hackers had control of the ship's propellers, raising concern that these giant vessels could be used as weapons. Nicole
How a Chinese Hacking Firm Tapped AI to Supercharge Cyber-Spying - WSJ
Internal company materials show AI being used to make stolen foreign government data digestible for police, targeting Russia, Pakistan and others.
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
... Hacker News. "Malicious browser extensions bypass Chromium integrity mechanisms by manipulating Secure Preferences and regenerating required HMACs...
How a Chinese Hacking Firm Tapped AI to Supercharge Cyber-Spying - WSJ
Internal company materials show AI being used to make stolen foreign government data digestible for police, targeting Russia, Pakistan and others.
Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's ...
Russian-Linked Threat Actors Using AI to Exploit PaperCut NG/MF Vulnerabilities
A suspected Russian-speaking cyber actor has used artificial intelligence to devise exploits targeting recently disclosed security flaws in PaperCut N...
Updated daily
