Added to CISA KEV, 7 Sep 2026 to 13 Sep 2026
14 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog in this week. Listed by risk: highest EPSS first.
Build snapshot collected · KEV catalog 2026.10.02 · EPSS of 2 Oct 2026 · not a live feed: collected once, at build time
- CVE-2026-85706Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
GitLab · Community Edition and Enterprise Edition
GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
Severity
10.0CRITICALCVSS 3.1 · gitlab.comAttack probability (EPSS)
93.0%99.8th pctKEV dates
added due - CVE-2026-20079Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Cisco · Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
Severity
10.0CRITICALCVSS 3.1 · cisco.comAttack probability (EPSS)
88.2%99.8th pctKEV dates
added due - CVE-2026-19490Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Citrix · NetScaler
Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
Severity
9.3CRITICALCVSS 4.0 · 50a63c94-1ea7-4568-8c11-eb79e7c5a2b5Attack probability (EPSS)
23.2%98th pctKEV dates
added due - CVE-2026-86218Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
N-able · N-central
N-able N-central Static Code Injection Vulnerability
Severity
10.0CRITICALCVSS 4.0 · a5532a13-c4dd-4202-bef1-e0b8f2f8d12bAttack probability (EPSS)
12.9%96th pctKEV dates
added due - CVE-2026-42018Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
JFrog · Artifactory
JFrog Artifactory Improper Authentication Vulnerability
Severity
7.5HIGHCVSS 3.1 · jfrog.comAttack probability (EPSS)
9.80%95th pctKEV dates
added due - CVE-2026-42016Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
JFrog · Artifactory
JFrog Artifactory Incorrect Authorization Vulnerability
Severity
8.8HIGHCVSS 3.1 · NVDAttack probability (EPSS)
8.64%95th pctKEV dates
added due - CVE-2026-86060Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
MikroTik · RouterOS
MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
Severity
9.2CRITICALCVSS 4.0 · cert.plAttack probability (EPSS)
6.39%93th pctKEV dates
added due - CVE-2026-75650Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Adobe · Commerce and Magento
Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Severity
10.0CRITICALCVSS 3.1 · adobe.comAttack probability (EPSS)
3.95%90th pctKEV dates
added due - CVE-2025-25249Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Fortinet · Multiple Products
Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
Severity
9.8CRITICALCVSS 3.1 · NVDAttack probability (EPSS)
3.86%90th pctKEV dates
added due - CVE-2026-85880Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Microsoft · Windows
Microsoft Windows Heap-Based Buffer Overflow Vulnerability
Severity
7.8HIGHCVSS 3.1 · microsoft.comAttack probability (EPSS)
3.62%89th pctKEV dates
added due - CVE-2026-87491Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Google · Chromium V8
Google Chromium V8 Out of Bounds Write Vulnerability
Severity
8.8HIGHCVSS 3.1 · CISA-ADPAttack probability (EPSS)
3.14%87th pctKEV dates
added due - CVE-2026-67277Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
MikroTik · RouterOS
MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
Severity
8.8HIGHCVSS 4.0 · cert.plAttack probability (EPSS)
1.56%74th pctKEV dates
added due - CVE-2026-84869Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
ConnectWise · ScreenConnect
ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
Severity
9.9CRITICALCVSS 3.1 · 7d616e1a-3288-43b1-a0dd-0a65d3e70a49Attack probability (EPSS)
0.92%59th pctKEV dates
added due - CVE-2026-81963Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Microsoft · Windows
Microsoft Windows Link Following Vulnerability
Severity
7.8HIGHCVSS 3.1 · microsoft.comAttack probability (EPSS)
0.39%31th pctKEV dates
added due
All entries are in KEV, so the order is EPSS probability, then published CVSS. Scores are shown as each source published them.
The week in numbers
11 vendors had products added: JFrog (2), MikroTik (2), Microsoft (2), GitLab (1), Cisco (1), Citrix (1), N-able (1), Adobe (1), Fortinet (1), Google (1), ConnectWise (1). CISA marks none of the 14 as known to be used in ransomware campaigns.
- All Microsoft entries in KEV
- All Cisco entries in KEV
- All Citrix entries in KEV
- All Adobe entries in KEV
- All Fortinet entries in KEV
- All Google entries in KEV
Due dates in this batch run from 11 Sep 2026 to 25 Sep 2026. They bind US federal civilian agencies; for everyone else they indicate how urgent CISA considers each fix.
Other weeks
Questions
How many vulnerabilities were added to CISA KEV in the week of 7 Sep 2026?
14, between 7 Sep 2026 and 13 Sep 2026, according to catalog version 2026.10.02 collected on 3 Oct 2026.
Why do additions come in batches?
CISA updates the catalog on US business days and often adds several CVEs in one notice, for example a set of vulnerabilities in the same product that are chained in an attack. Weeks with no additions also happen.
How is the week defined?
By the "dateAdded" field of each entry, grouped in ISO 8601 weeks, Monday to Sunday.
Related sections
- WatchlistWhat attackers started using this month, most urgent first.
- Exploited catalogEvery flaw CISA lists as used in real attacks (KEV), searchable.
- CVE lookupType one identifier: attack status, probability, severity, versions.
- Attack probabilityEPSS score for up to 100 identifiers at once.
- VendorsWhich vendors have the most exploited flaws.
- RSS and JSON feedsFollow new exploited flaws for the vendors you run.
- Sources and methodWhere each number comes from and how the order is decided.