This month: 42 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2026-86950
Apple · Multiple Products
Apple Multiple Products Out-of-Bounds Write Vulnerability
■Detected Sep 29 · 3-day patch deadline
CVE-2026-88771
Citrix · NetScaler
Citrix NetScaler Improper Input Validation Vulnerability
■Detected Sep 27 · 3-day patch deadline
CVE-2026-65660
Microsoft · SharePoint
Microsoft SharePoint Code Injection Vulnerability
■Detected Sep 25 · 3-day patch deadline

KEV Intelligence Brief — September 28, 2026

Issued: Monday, September 28, 2026 | Audience: Federal Contractors, DevOps, Security Operations | Coverage: 8 KEV Additions (September 22–27, 2026)

CISA's catalog absorbed eight vulnerabilities across six vendors in less than a week, spanning network edge infrastructure, enterprise middleware, and public-facing web platforms. Three separate patch deadlines have already passed or expire today. Organizations with BOD 26-04 obligations are either in violation or operating on borrowed time.

Edge Infrastructure Under Active Threat: Citrix NetScaler and Check Point

The most operationally urgent cluster this cycle targets the network perimeter directly — the systems your organization trusts to broker authenticated access to everything else.

CVE-2026-85102 (Check Point Security Gateway and Spark Firewall) set the opening tone when it entered the KEV catalog on September 22 with a patch deadline of September 25 — now three days overdue. An improper certificate validation flaw in Site-to-Site and Remote Access VPN configurations allows an unauthenticated remote attacker to execute arbitrary code on the gateway itself. In practice, this means an adversary who can reach your VPN endpoint from the internet doesn't need credentials, doesn't need a foothold — they own the gateway. If your Check Point estate hasn't been patched, isolate affected gateways from internet-facing interfaces immediately, audit for indicators of lateral movement, and initiate CISA's Forensics Triage Requirements before assuming the environment is clean.

Hot on its heels, Citrix added two NetScaler entries on September 27, both carrying an aggressive September 30 patch deadline — 72 hours from time of publication. CVE-2026-88771 is an improper input validation flaw enabling unauthenticated arbitrary command execution on NetScaler ADC and Gateway. CVE-2026-88772 is a memory buffer bounds violation enabling remote code execution or denial of service against the same products. These are not independent problems to triage sequentially; they compound each other and, when layered against a perimeter appliance handling authentication and traffic inspection, represent a complete pre-auth RCE scenario on your network edge. With only days before the BOD 26-04 deadline, teams that cannot patch immediately should consider whether these devices can be temporarily pulled behind a jump host or have management interfaces restricted to non-routable networks while emergency change procedures are initiated. Credential rotation for all accounts whose authentication flowed through NetScaler should be treated as mandatory, not optional.

Deadline Watch: SharePoint, MikroTik, and WordPress Core

Three vulnerabilities added September 25 share a patch deadline of today, September 28 — making this section a live operational emergency for affected organizations.

CVE-2026-65660, a code injection vulnerability in Microsoft SharePoint, allows an authorized attacker to execute code over a network. The "authorized" qualifier shouldn't generate complacency — it means any compromised credential or over-permissioned service account can pivot to code execution. SharePoint's deep integration with Microsoft 365 environments makes this a high-value pivot point for lateral movement and data exfiltration. Apply the Microsoft security update, audit SharePoint site permissions aggressively, and review recent authentication logs for anomalous access patterns from internal service accounts.

CVE-2026-67279 in MikroTik RouterOS is more alarming in terms of attack surface. The improper enforcement of behavioral workflow allows an unauthenticated client to open a session channel and issue exec requests — and CISA explicitly notes it chains with CVE-2026-86060 to achieve fully unauthenticated exploitation. MikroTik devices are pervasive in small-to-mid enterprise branch networking, managed service provider infrastructure, and government facilities where refresh cycles are long. The chaining behavior elevates this from a single-CVE remediation to a compound exploit scenario; patching CVE-2026-67279 alone may be insufficient if CVE-2026-86060 remains unaddressed. Verify both CVEs are covered in the applied patch version and review RouterOS devices for unauthorized configuration changes or unexpected outbound sessions.

CVE-2026-87902 affects WordPress Core and enables unauthenticated remote file inclusion, allowing an attacker to manipulate page-template resolution to load arbitrary local PHP files outside the active theme directory, leading to RCE. WordPress Core vulnerabilities at this severity level are typically weaponized at scale within hours of PoC availability. Any internet-facing WordPress instance — especially those operated by federal contractors hosting public-facing portals — must be patched immediately. Web application firewalls can provide partial mitigation but should not substitute for the patch.

API and Commerce Middleware: WSO2 and Adobe Commerce

Two entries from September 24 — both with patch deadlines of September 27, now one day overdue — target middleware and e-commerce infrastructure that frequently handles sensitive data and privileged API credentials.

CVE-2026-5430 affects WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway. A path traversal vulnerability enables unrestricted file upload leading to RCE — a well-understood but consistently devastating class of vulnerability in API gateway products. WSO2's footprint in government digital services and enterprise API management makes exploitation here a potential supply-chain event, not just an isolated system compromise. Teams should verify patch application, audit file upload directories for unexpected artifacts, and review API gateway logs for anomalous file paths in recent requests.

CVE-2026-71362 in Adobe Commerce and Magento represents an incorrect authorization flaw allowing privilege escalation to sensitive resources with no user interaction required. E-commerce environments holding payment data, customer PII, and fulfillment integrations are high-value targets. Organizations running Magento Open Source should not assume they fall outside CISA's purview — BOD 26-04 applies to any federal contractor asset.

Recommended Immediate Actions

  • Check Point VPN environments: Assume compromise if unpatched since September 25. Initiate forensic triage before patching.
  • Citrix NetScaler ADC/Gateway: Patch or isolate by September 30. Rotate all credentials authenticated through these systems.
  • SharePoint, MikroTik, WordPress: Today is the deadline. Escalate any unpatched instances to CISO-level attention now.
  • WSO2 and Adobe Commerce: One day overdue. Prioritize audit of file upload directories and authorization logs alongside patch application.
  • All assets: BOD 26-04 requires federal agencies and contractors to assess internet exposure for each asset. Document that assessment.

Sources: CISA KEV Catalog · CISA BOD 26-04 · Citrix Security Bulletin · Microsoft Security Update Guide · Check Point Security Advisories · MikroTik Changelogs · WSO2 Security Advisories · Adobe Security Bulletins · WordPress Security Releases

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


Hacking Editorial Brief — September 29, 2026

Attackers Exploit Citrix NetScaler Zero-Days and Oracle PeopleSoft via WAF Bypass

Citrix confirmed active exploitation of two critical NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, with at least one flaw affecting every deployment running vulnerable versions. The in-the-wild exploitation adds urgency to patching efforts for enterprise gateway systems. Separately, threat actors linked to ShinyHunters are exploiting CVE-2026-35273 in Oracle PeopleSoft by bypassing web application firewall protections using a single URL-encoded character, allowing deployment of web shells across multiple sectors. Mandiant warned that attackers are specifically targeting organizations that applied vendor-recommended workarounds instead of installing the full patch, indicating reconnaissance of defensive posture before compromise. The PeopleSoft campaign demonstrates continued evolution of techniques against the HR platform following initial compromises reported earlier this month.

NeedyMantis Malware Framework Maintains Covert Access; Carbonato Botnet Deploys AI Agents

Microsoft disclosed NeedyMantis, a modular post-compromise malware framework designed to preserve long-term covert access inside already-breached networks across telecommunications, education, and government sectors. The toolset focuses on persistence rather than initial access, indicating mature threat actor operations. In a separate development, security researchers identified the Carbonato botnet deploying AI agents on compromised Docker hosts using the open-source Hermes Agent framework to execute commands. The botnet represents an emerging trend of threat actors integrating autonomous AI capabilities into traditional malware infrastructure. Meanwhile, cryptocurrency exchange Bitget disclosed that suspected North Korean hackers stole $351.6 million from hot and warm wallets in a coordinated backend attack, with attribution pointing to DPRK-linked groups following the massive crypto theft campaign reported this month.

Sources: The Cyber Express · The Hacker News · Hendry Adrian · Cybersecurity News · Dark Reading · Bleeping Computer

📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://www.foxbusiness.comSep 29

Nvidia launches security platform to keep AI agents from going rogue - Fox Business

Nvidia released open source AI security tools it says could have stopped the Hugging Face hack by rogue OpenAI agents, offering sandbox and ...

https://wjactv.comSep 29

Feds: Two former Penn State students plead guilty in nationwide hacking, fraud scheme

Prosecutors say a second former Penn State student has admitted to his involvement in a federal investigation into nationwide computer hacking.

https://www.theguardian.comSep 29

OpenAI 'sorry and working to do better' after hack of Medicare and other Australian ...

Artificial intelligence firm to front parliament as it apologises to Australians for agent attack.

https://federalnewsnetwork.comSep 29

Hegseth says national security, military cyber forces will guard US election systems during midterms

Military cybersecurity experts have routinely helped monitor systems and deter potential hackers since election equipment was designated “ critical .....

https://www.rapid7.comSep 27

Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772

Both critical RCE vulnerabilities in Citrix NetScaler carry a CVSS 9.5 score and have been confirmed as actively exploited in the wild as zero-days pr...

https://www.helpnetsecurity.comSep 28

Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)

Citrix patched two critical RCE vulnerabilities that have been actively exploited in zero-day attacks to plant webshells on compromised NetScaler devi...

https://techcrunch.comSep 22

Hacking group ShinyHunters claims it breached the FBI, stole agents' and applicants' data

ShinyHunters, a prolific cybercriminal group, claims it breached the FBI and stole sensitive data on thousands of agents and job applicants.

https://thehackernews.comSep 25

Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

Cryptocurrency exchange Bitget disclosed that suspected North Korean threat actors stole $351.6 million from its hot and warm wallets through a backen...


Updated daily