Added to CISA KEV, 28 Sep 2026 to 4 Oct 2026
5 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog in this week, which had not ended when the data was collected. Listed by risk: highest EPSS first.
Build snapshot collected · KEV catalog 2026.10.02 · EPSS of 2 Oct 2026 · not a live feed: collected once, at build time
- CVE-2026-104286Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Fortinet · FortiMail
Fortinet FortiMail Path Traversal Vulnerability
Severity
9.8CRITICALCVSS 3.1 · fortinet.comAttack probability (EPSS)
1.78%77th pctKEV dates
added due - CVE-2026-76504Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Cisco · Catalyst SD-WAN Manager
Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
Severity
9.8CRITICALCVSS 3.1 · cisco.comAttack probability (EPSS)
1.57%75th pctKEV dates
added due - CVE-2026-86950Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Apple · Multiple Products
Apple Multiple Products Out-of-Bounds Write Vulnerability
Severity
8.8HIGHCVSS 3.1 · CISA-ADPAttack probability (EPSS)
1.24%68th pctKEV dates
added due - CVE-2026-102489Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Zammad GmbH · Zammad
Zammad GmbH Zammad Session Fixation Vulnerability
Severity
9.4CRITICALCVSS 4.0 · divd.nlAttack probability (EPSS)
0.58%46th pctKEV dates
added due - CVE-2026-102490Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Zammad GmbH · Zammad
Zammad GmbH Zammad Improper Privilege Management Vulnerability
Severity
9.4CRITICALCVSS 4.0 · divd.nlAttack probability (EPSS)
0.26%16th pctKEV dates
added due
All entries are in KEV, so the order is EPSS probability, then published CVSS. Scores are shown as each source published them.
The week in numbers
4 vendors had products added: Zammad GmbH (2), Fortinet (1), Cisco (1), Apple (1). CISA marks none of the 5 as known to be used in ransomware campaigns.
Due dates in this batch run from 2 Oct 2026 to 5 Oct 2026. They bind US federal civilian agencies; for everyone else they indicate how urgent CISA considers each fix.
Other weeks
Questions
How many vulnerabilities were added to CISA KEV in the week of 28 Sep 2026?
5, between 28 Sep 2026 and 4 Oct 2026, according to catalog version 2026.10.02 collected on 3 Oct 2026. The week had not ended at collection time, so the number can still grow.
Why do additions come in batches?
CISA updates the catalog on US business days and often adds several CVEs in one notice, for example a set of vulnerabilities in the same product that are chained in an attack. Weeks with no additions also happen.
How is the week defined?
By the "dateAdded" field of each entry, grouped in ISO 8601 weeks, Monday to Sunday.
Related sections
- WatchlistWhat attackers started using this month, most urgent first.
- Exploited catalogEvery flaw CISA lists as used in real attacks (KEV), searchable.
- CVE lookupType one identifier: attack status, probability, severity, versions.
- Attack probabilityEPSS score for up to 100 identifiers at once.
- VendorsWhich vendors have the most exploited flaws.
- RSS and JSON feedsFollow new exploited flaws for the vendors you run.
- Sources and methodWhere each number comes from and how the order is decided.