Added to CISA KEV, 14 Sep 2026 to 20 Sep 2026
7 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog in this week. Listed by risk: highest EPSS first.
Build snapshot collected · KEV catalog 2026.10.02 · EPSS of 2 Oct 2026 · not a live feed: collected once, at build time
- CVE-2026-76461Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Cisco · Secure Email Gateway
Cisco Secure Email Gateway SQL Injection Vulnerability
Severity
9.8CRITICALCVSS 3.1 · cisco.comAttack probability (EPSS)
28.3%98th pctKEV dates
added due - CVE-2026-76460Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Cisco · Identity Services Engine
Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
Severity
10.0CRITICALCVSS 3.1 · cisco.comAttack probability (EPSS)
14.0%96th pctKEV dates
added due - CVE-2025-39682Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Linux · Kernel
Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
Severity
9.8CRITICALCVSS 3.1 · NVDAttack probability (EPSS)
2.88%86th pctKEV dates
added due - CVE-2025-39964Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Linux · Kernel
Linux Kernel Race Condition Vulnerability
Severity
5.5MEDIUMCVSS 3.1 · NVDAttack probability (EPSS)
1.00%61th pctKEV dates
added due - CVE-2026-53266Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Linux · Kernel
Linux Kernel Out-of-Bounds Write Vulnerability
Severity
8.8HIGHCVSS 3.1 · 416baaa9-dc9f-4396-8d5f-8c081fb06d67Attack probability (EPSS)
0.83%56th pctKEV dates
added due - CVE-2026-58704Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Google · Pixel
Google Pixel Improper Authorization Vulnerability
Severity
8.8HIGHCVSS 3.1 · CISA-ADPAttack probability (EPSS)
0.59%46th pctKEV dates
added due - CVE-2026-87886Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Acronis · Backup
Acronis Backup Incorrect Default Permissions Vulnerability
Severity
7.8HIGHCVSS 3.0 · acronis.comAttack probability (EPSS)
0.23%13th pctKEV dates
added due
All entries are in KEV, so the order is EPSS probability, then published CVSS. Scores are shown as each source published them.
The week in numbers
4 vendors had products added: Linux (3), Cisco (2), Google (1), Acronis (1). CISA marks none of the 7 as known to be used in ransomware campaigns.
Due dates in this batch run from 17 Sep 2026 to 21 Sep 2026. They bind US federal civilian agencies; for everyone else they indicate how urgent CISA considers each fix.
Other weeks
Questions
How many vulnerabilities were added to CISA KEV in the week of 14 Sep 2026?
7, between 14 Sep 2026 and 20 Sep 2026, according to catalog version 2026.10.02 collected on 3 Oct 2026.
Why do additions come in batches?
CISA updates the catalog on US business days and often adds several CVEs in one notice, for example a set of vulnerabilities in the same product that are chained in an attack. Weeks with no additions also happen.
How is the week defined?
By the "dateAdded" field of each entry, grouped in ISO 8601 weeks, Monday to Sunday.
Related sections
- WatchlistWhat attackers started using this month, most urgent first.
- Exploited catalogEvery flaw CISA lists as used in real attacks (KEV), searchable.
- CVE lookupType one identifier: attack status, probability, severity, versions.
- Attack probabilityEPSS score for up to 100 identifiers at once.
- VendorsWhich vendors have the most exploited flaws.
- RSS and JSON feedsFollow new exploited flaws for the vendors you run.
- Sources and methodWhere each number comes from and how the order is decided.