CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief — September 16, 2026
Prepared by: Cybersecurity Intelligence | Distribution: Federal Contractors, DevOps, SecOps Leadership Reference Period: September 10–16, 2026 | Governing Directive: CISA BOD 26-04
Critical: Overdue and Expiring Deadlines Demand Immediate Action
Three vulnerabilities added to the KEV catalog between September 10–11 carry patch deadlines that have already passed or expire within 24–48 hours of this writing. If your organization has not already remediated these, you are out of compliance with BOD 26-04.
MikroTik RouterOS (CVE-2026-67277) had a patch deadline of September 13 — three days ago. This missing authentication vulnerability in the RouterOS btest service exposes kernel memory and enables denial-of-service conditions without any authentication requirement. MikroTik devices are pervasive in small-to-mid-market enterprise and ISP environments and are historically slow to receive operator attention. If you have internet-exposed RouterOS devices running btest, treat this as an active incident: isolate, patch, and conduct forensic triage per BOD 26-04 requirements. If patching is not immediately achievable, disable the btest service and restrict management plane access to trusted IP ranges.
ConnectWise ScreenConnect (CVE-2026-84869) and GitLab CE/EE (CVE-2026-85706) both carried a September 14 deadline — also now past. The ScreenConnect vulnerability is particularly dangerous in operational context: it permits file transfer and remote execution through active sessions without host confirmation or authorization checks, meaning an attacker can silently hijack a technician session already in progress. Any organization using ScreenConnect for managed service delivery or remote IT support should audit session logs immediately for anomalous transfers and revoke all standing sessions pending patch confirmation. The GitLab path traversal (CVE-2026-85706) allows unauthenticated reading of arbitrary files through the repository commits API — a direct threat to source code confidentiality and secrets exposure. Self-hosted GitLab instances with public-facing endpoints are the highest priority; rotate any tokens, SSH keys, or CI/CD secrets that may have been accessible from repository file paths.
Developer Toolchain and Identity Infrastructure Under Active Pressure
The week's additions include a cluster of vulnerabilities targeting the software supply chain and access control infrastructure — systems where a single compromise can cascade broadly across an environment.
JFrog Artifactory appears twice, with both CVE-2026-42016 and CVE-2026-42018 added September 11 (deadline: September 25). The authorization flaw in CVE-2026-42016 is particularly insidious: the platform validates token signature and issuer but not token scope, meaning a low-privilege token can be leveraged to escalate to administrative actions. Paired with CVE-2026-42018 — which can return an anonymous-user token to an unauthenticated caller even when anonymous access is explicitly disabled — these two vulnerabilities create a plausible unauthenticated-to-privileged escalation chain within a single product. Artifactory sits at the center of most enterprise build pipelines. Compromise here means access to build artifacts, package signing infrastructure, and potentially upstream supply chain injection. Organizations should immediately audit Artifactory access logs for anomalous token usage, enforce IP allowlisting on the management interface, and rotate all API tokens as a precautionary measure — do not wait for the September 25 deadline.
Cisco Identity Services Engine (CVE-2026-76460), added September 16 with a deadline of September 19, presents an unauthenticated bypass of the ISE web management interface through incorrect use of privileged APIs. ISE is a cornerstone of zero trust and NAC architectures in federal and enterprise environments — a compromise here can expose network segmentation policies, device posture data, and authentication flows across the organization. The deadline is aggressive at three days. If an immediate patch cycle is not feasible, restrict ISE management interface access to out-of-band management networks and disable external-facing administrative access until the patch is applied.
Unauthenticated Remote Threats Across Email, Mobility, and Network Edge
Two final entries round out a week dominated by pre-authentication attack surface.
Cisco Secure Email Gateway (CVE-2026-76461) carries a September 17 deadline — tomorrow. The SQL injection vulnerability in Cisco AsyncOS is severe: an unauthenticated remote attacker can execute arbitrary commands with root privileges on the underlying operating system. This is not a data exfiltration risk alone — it is full system compromise on a device that sits inline with all inbound and outbound organizational email. Cisco SEG appliances exposed to the internet should be considered highest priority. Apply the patch immediately; if patching is impossible before the deadline, consider upstream SMTP filtering or disabling internet-facing management access while the fix is staged.
Google Pixel (CVE-2026-58704), also added today with a September 19 deadline, involves an improper authorization flaw in the cellular modem subsystem that enables privilege escalation through a logic error in permission checks. Federal employees and contractors using Pixel devices for work — particularly those with access to sensitive systems via MDM or VPN clients — should prioritize applying the Google security update that addresses this flaw. MDM administrators should verify device compliance posture and consider temporarily restricting network access for unpatched Pixel devices until remediation is confirmed.
Summary Deadline Tracker
| CVE | Vendor / Product | Deadline | Status | |---|---|---|---| | CVE-2026-67277 | MikroTik RouterOS | Sep 13 | OVERDUE | | CVE-2026-84869 | ConnectWise ScreenConnect | Sep 14 | OVERDUE | | CVE-2026-85706 | GitLab CE/EE | Sep 14 | OVERDUE | | CVE-2026-76461 | Cisco Secure Email Gateway | Sep 17 | Due Tomorrow | | CVE-2026-58704 | Google Pixel | Sep 19 | Due in 3 days | | CVE-2026-76460 | Cisco ISE | Sep 19 | Due in 3 days | | CVE-2026-42016 | JFrog Artifactory | Sep 25 | Due in 9 days | | CVE-2026-42018 | JFrog Artifactory | Sep 25 | Due in 9 days |
Sources: CISA KEV Catalog · CISA BOD 26-04 · Cisco Security Advisories · Google Android Security Bulletins · JFrog Security Center · GitLab Security Releases · ConnectWise Security Advisories · MikroTik Security Advisories
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
Hacking Editorial Brief — September 16, 2026
Microsoft Ships Record 972 CVEs in September Patch Tuesday, Two Zero-Days Under Active Exploit
Microsoft released its largest security update on record, addressing 972 vulnerabilities in September's Patch Tuesday cycle. Among them are two actively exploited zero-day elevation of privilege flaws and 113 rated critical. The scale of disclosed vulnerabilities represents a significant spike in Microsoft's security posture reporting, though the company has not publicly attributed the active exploits to specific threat actors or disclosed exploitation scope. Organizations running Microsoft environments face an unusually large remediation surface this month, with immediate patching priorities centered on the two known-exploited flaws. The sheer volume suggests either improved internal discovery processes or an accumulation of third-party researcher submissions.
Critical WSO2 API Manager Flaw Under Active Exploitation; Iranian APT Uses Medical Imaging in Social Engineering
A critical authentication bypass vulnerability in WSO2 API Manager (CVE-2026-5430) is being actively exploited in the wild, enabling account takeover through improper JWT cryptographic signature verification. The flaw affects enterprise API management infrastructure and requires immediate patching. Separately, the UK's National Cyber Security Centre confirmed that Iranian state-sponsored actors are using fabricated MRI scan results as social engineering lures to compromise targets deemed enemies of the regime. The medical imagery tactic marks a shift toward exploiting sensitive health contexts to establish credibility and urgency in spear-phishing campaigns. Meanwhile, ShinyHunters claimed a breach of Florida's DMV system, asserting theft of 200,000 records, though state officials disputed the password-reset method cited by the group.
Sources: CrowdStrike · WIU Cybersecurity Center · The Record · Fox News
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
How a Chinese Hacking Firm Tapped AI to Supercharge Cyber-Spying - WSJ
Internal company materials show AI being used to make stolen foreign government data digestible for police, targeting Russia, Pakistan and others.
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
... Hacker News. "Malicious browser extensions bypass Chromium integrity mechanisms by manipulating Secure Preferences and regenerating required HMACs...
How a Chinese Hacking Firm Tapped AI to Supercharge Cyber-Spying - WSJ
Internal company materials show AI being used to make stolen foreign government data digestible for police, targeting Russia, Pakistan and others.
Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's ...
Russian-Linked Threat Actors Using AI to Exploit PaperCut NG/MF Vulnerabilities
A suspected Russian-speaking cyber actor has used artificial intelligence to devise exploits targeting recently disclosed security flaws in PaperCut N...
China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campa...
CISA Confirms Ransomware Gangs Abusing Microsoft SharePoint RCE Vulnerability
CISA confirmed that ransomware gangs have begun actively exploiting a high-severity Microsoft SharePoint remote code execution vulnerability since ear...
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and ...
Updated daily
