Skip to content

Data collected

CVEs Live

Added to CISA KEV, 14 Sep 2026 to 20 Sep 2026

7 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog in this week. Listed by risk: highest EPSS first.

Build snapshot collected · KEV catalog 2026.10.02 · EPSS of 2 Oct 2026 · not a live feed: collected once, at build time

  1. CVE-2026-76461Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Cisco · Secure Email Gateway

    Cisco Secure Email Gateway SQL Injection Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · cisco.com

    Attack probability (EPSS)

    28.3%98th pct

    KEV dates

    added due
  2. CVE-2026-76460Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Cisco · Identity Services Engine

    Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

    Severity

    10.0CRITICALCVSS 3.1 · cisco.com

    Attack probability (EPSS)

    14.0%96th pct

    KEV dates

    added due
  3. CVE-2025-39682Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Linux · Kernel

    Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · NVD

    Attack probability (EPSS)

    2.88%86th pct

    KEV dates

    added due
  4. CVE-2025-39964Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Linux · Kernel

    Linux Kernel Race Condition Vulnerability

    Severity

    5.5MEDIUMCVSS 3.1 · NVD

    Attack probability (EPSS)

    1.00%61th pct

    KEV dates

    added due
  5. CVE-2026-53266Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Linux · Kernel

    Linux Kernel Out-of-Bounds Write Vulnerability

    Severity

    8.8HIGHCVSS 3.1 · 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Attack probability (EPSS)

    0.83%56th pct

    KEV dates

    added due
  6. CVE-2026-58704Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Google · Pixel

    Google Pixel Improper Authorization Vulnerability

    Severity

    8.8HIGHCVSS 3.1 · CISA-ADP

    Attack probability (EPSS)

    0.59%46th pct

    KEV dates

    added due
  7. CVE-2026-87886Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Acronis · Backup

    Acronis Backup Incorrect Default Permissions Vulnerability

    Severity

    7.8HIGHCVSS 3.0 · acronis.com

    Attack probability (EPSS)

    0.23%13th pct

    KEV dates

    added due

All entries are in KEV, so the order is EPSS probability, then published CVSS. Scores are shown as each source published them.

The week in numbers

4 vendors had products added: Linux (3), Cisco (2), Google (1), Acronis (1). CISA marks none of the 7 as known to be used in ransomware campaigns.

Due dates in this batch run from 17 Sep 2026 to 21 Sep 2026. They bind US federal civilian agencies; for everyone else they indicate how urgent CISA considers each fix.

Other weeks

Questions

How many vulnerabilities were added to CISA KEV in the week of 14 Sep 2026?

7, between 14 Sep 2026 and 20 Sep 2026, according to catalog version 2026.10.02 collected on 3 Oct 2026.

Why do additions come in batches?

CISA updates the catalog on US business days and often adds several CVEs in one notice, for example a set of vulnerabilities in the same product that are chained in an attack. Weeks with no additions also happen.

How is the week defined?

By the "dateAdded" field of each entry, grouped in ISO 8601 weeks, Monday to Sunday.

Related sections