Added to CISA KEV, 21 Sep 2026 to 27 Sep 2026
12 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog in this week. Listed by risk: highest EPSS first.
Build snapshot collected · KEV catalog 2026.10.02 · EPSS of 2 Oct 2026 · not a live feed: collected once, at build time
- CVE-2026-71362Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Adobe · Commerce and Magento
Adobe Commerce and Magento Incorrect Authorization Vulnerability
Severity
9.1CRITICALCVSS 3.1 · adobe.comAttack probability (EPSS)
87.5%99.8th pctKEV dates
added due - CVE-2026-87902Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
WordPress · Core
WordPress Core Remote File Inclusion Vulnerability
Severity
8.1HIGHCVSS 3.1 · CISA-ADPAttack probability (EPSS)
45.5%99th pctKEV dates
added due - CVE-2026-93616Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Check Point · Multiple Products
Check Point Multiple Products Path Traversal Vulnerability
Severity
9.8CRITICALCVSS 3.1 · checkpoint.comAttack probability (EPSS)
19.7%97th pctKEV dates
added due - CVE-2026-85102Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Check Point · Multiple Products
Check Point Multiple Products Improper Certificate Validation Vulnerability
Severity
9.8CRITICALCVSS 3.1 · checkpoint.comAttack probability (EPSS)
7.55%94th pctKEV dates
added due - CVE-2026-7273Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Zyxel · GS1900 Series Switches
Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
Severity
8.8HIGHCVSS 3.1 · zyxel.com.twAttack probability (EPSS)
2.50%84th pctKEV dates
added due - CVE-2026-94127Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
F5 · BIG-IP APM
F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
Severity
9.3CRITICALCVSS 4.0 · f5.comAttack probability (EPSS)
2.23%82th pctKEV dates
added due - CVE-2026-65660Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Microsoft · SharePoint
Microsoft SharePoint Code Injection Vulnerability
Severity
8.8HIGHCVSS 3.1 · microsoft.comAttack probability (EPSS)
2.10%81th pctKEV dates
added due - CVE-2026-88772Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Citrix · NetScaler
Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Severity
9.5CRITICALCVSS 4.0 · 50a63c94-1ea7-4568-8c11-eb79e7c5a2b5Attack probability (EPSS)
1.30%69th pctKEV dates
added due - CVE-2026-88771Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Citrix · NetScaler
Citrix NetScaler Improper Input Validation Vulnerability
Severity
9.5CRITICALCVSS 4.0 · 50a63c94-1ea7-4568-8c11-eb79e7c5a2b5Attack probability (EPSS)
1.06%63th pctKEV dates
added due - CVE-2026-93952Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Arista · VeloCloud Orchestrator
Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
Severity
9.5CRITICALCVSS 4.0 · arista.comAttack probability (EPSS)
1.06%63th pctKEV dates
added due - CVE-2026-67279Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
MikroTik · RouterOS
Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
Severity
6.9MEDIUMCVSS 4.0 · cert.plAttack probability (EPSS)
1.03%62th pctKEV dates
added due - CVE-2026-5430Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
WSO2 · Multiple Products
WSO2 Multiple Products Path Traversal Vulnerability
Severity
10.0CRITICALCVSS 3.1 · ed10eef1-636d-4fbe-9993-6890dfa878f8Attack probability (EPSS)
0.59%46th pctKEV dates
added due
All entries are in KEV, so the order is EPSS probability, then published CVSS. Scores are shown as each source published them.
The week in numbers
10 vendors had products added: Check Point (2), Citrix (2), Adobe (1), WordPress (1), Zyxel (1), F5 (1), Microsoft (1), Arista (1), MikroTik (1), WSO2 (1). CISA marks none of the 12 as known to be used in ransomware campaigns.
Due dates in this batch run from 24 Sep 2026 to 30 Sep 2026. They bind US federal civilian agencies; for everyone else they indicate how urgent CISA considers each fix.
Other weeks
Questions
How many vulnerabilities were added to CISA KEV in the week of 21 Sep 2026?
12, between 21 Sep 2026 and 27 Sep 2026, according to catalog version 2026.10.02 collected on 3 Oct 2026.
Why do additions come in batches?
CISA updates the catalog on US business days and often adds several CVEs in one notice, for example a set of vulnerabilities in the same product that are chained in an attack. Weeks with no additions also happen.
How is the week defined?
By the "dateAdded" field of each entry, grouped in ISO 8601 weeks, Monday to Sunday.
Related sections
- WatchlistWhat attackers started using this month, most urgent first.
- Exploited catalogEvery flaw CISA lists as used in real attacks (KEV), searchable.
- CVE lookupType one identifier: attack status, probability, severity, versions.
- Attack probabilityEPSS score for up to 100 identifiers at once.
- VendorsWhich vendors have the most exploited flaws.
- RSS and JSON feedsFollow new exploited flaws for the vendors you run.
- Sources and methodWhere each number comes from and how the order is decided.