Skip to content

Data collected

CVEs Live

Added to CISA KEV, 7 Sep 2026 to 13 Sep 2026

14 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog in this week. Listed by risk: highest EPSS first.

Build snapshot collected · KEV catalog 2026.10.02 · EPSS of 2 Oct 2026 · not a live feed: collected once, at build time

  1. CVE-2026-85706Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    GitLab · Community Edition and Enterprise Edition

    GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability

    Severity

    10.0CRITICALCVSS 3.1 · gitlab.com

    Attack probability (EPSS)

    93.0%99.8th pct

    KEV dates

    added due
  2. CVE-2026-20079Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Cisco · Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management

    Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

    Severity

    10.0CRITICALCVSS 3.1 · cisco.com

    Attack probability (EPSS)

    88.2%99.8th pct

    KEV dates

    added due
  3. CVE-2026-19490Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Citrix · NetScaler

    Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability

    Severity

    9.3CRITICALCVSS 4.0 · 50a63c94-1ea7-4568-8c11-eb79e7c5a2b5

    Attack probability (EPSS)

    23.2%98th pct

    KEV dates

    added due
  4. CVE-2026-86218Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    N-able · N-central

    N-able N-central Static Code Injection Vulnerability

    Severity

    10.0CRITICALCVSS 4.0 · a5532a13-c4dd-4202-bef1-e0b8f2f8d12b

    Attack probability (EPSS)

    12.9%96th pct

    KEV dates

    added due
  5. CVE-2026-42018Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    JFrog · Artifactory

    JFrog Artifactory Improper Authentication Vulnerability

    Severity

    7.5HIGHCVSS 3.1 · jfrog.com

    Attack probability (EPSS)

    9.80%95th pct

    KEV dates

    added due
  6. CVE-2026-42016Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    JFrog · Artifactory

    JFrog Artifactory Incorrect Authorization Vulnerability

    Severity

    8.8HIGHCVSS 3.1 · NVD

    Attack probability (EPSS)

    8.64%95th pct

    KEV dates

    added due
  7. CVE-2026-86060Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    MikroTik · RouterOS

    MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

    Severity

    9.2CRITICALCVSS 4.0 · cert.pl

    Attack probability (EPSS)

    6.39%93th pct

    KEV dates

    added due
  8. CVE-2026-75650Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Adobe · Commerce and Magento

    Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

    Severity

    10.0CRITICALCVSS 3.1 · adobe.com

    Attack probability (EPSS)

    3.95%90th pct

    KEV dates

    added due
  9. CVE-2025-25249Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Fortinet · Multiple Products

    Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · NVD

    Attack probability (EPSS)

    3.86%90th pct

    KEV dates

    added due
  10. CVE-2026-85880Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Microsoft · Windows

    Microsoft Windows Heap-Based Buffer Overflow Vulnerability

    Severity

    7.8HIGHCVSS 3.1 · microsoft.com

    Attack probability (EPSS)

    3.62%89th pct

    KEV dates

    added due
  11. CVE-2026-87491Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Google · Chromium V8

    Google Chromium V8 Out of Bounds Write Vulnerability

    Severity

    8.8HIGHCVSS 3.1 · CISA-ADP

    Attack probability (EPSS)

    3.14%87th pct

    KEV dates

    added due
  12. CVE-2026-67277Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    MikroTik · RouterOS

    MikroTik RouterOS Missing Authentication for Critical Function Vulnerability

    Severity

    8.8HIGHCVSS 4.0 · cert.pl

    Attack probability (EPSS)

    1.56%74th pct

    KEV dates

    added due
  13. CVE-2026-84869Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    ConnectWise · ScreenConnect

    ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

    Severity

    9.9CRITICALCVSS 3.1 · 7d616e1a-3288-43b1-a0dd-0a65d3e70a49

    Attack probability (EPSS)

    0.92%59th pct

    KEV dates

    added due
  14. CVE-2026-81963Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Microsoft · Windows

    Microsoft Windows Link Following Vulnerability

    Severity

    7.8HIGHCVSS 3.1 · microsoft.com

    Attack probability (EPSS)

    0.39%31th pct

    KEV dates

    added due

All entries are in KEV, so the order is EPSS probability, then published CVSS. Scores are shown as each source published them.

The week in numbers

11 vendors had products added: JFrog (2), MikroTik (2), Microsoft (2), GitLab (1), Cisco (1), Citrix (1), N-able (1), Adobe (1), Fortinet (1), Google (1), ConnectWise (1). CISA marks none of the 14 as known to be used in ransomware campaigns.

Due dates in this batch run from 11 Sep 2026 to 25 Sep 2026. They bind US federal civilian agencies; for everyone else they indicate how urgent CISA considers each fix.

Other weeks

Questions

How many vulnerabilities were added to CISA KEV in the week of 7 Sep 2026?

14, between 7 Sep 2026 and 13 Sep 2026, according to catalog version 2026.10.02 collected on 3 Oct 2026.

Why do additions come in batches?

CISA updates the catalog on US business days and often adds several CVEs in one notice, for example a set of vulnerabilities in the same product that are chained in an attack. Weeks with no additions also happen.

How is the week defined?

By the "dateAdded" field of each entry, grouped in ISO 8601 weeks, Monday to Sunday.

Related sections