Skip to content

Data collected

CVEs Live

Added to CISA KEV, 28 Sep 2026 to 4 Oct 2026

5 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog in this week, which had not ended when the data was collected. Listed by risk: highest EPSS first.

Build snapshot collected · KEV catalog 2026.10.02 · EPSS of 2 Oct 2026 · not a live feed: collected once, at build time

  1. CVE-2026-104286Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Fortinet · FortiMail

    Fortinet FortiMail Path Traversal Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · fortinet.com

    Attack probability (EPSS)

    1.78%77th pct

    KEV dates

    added due
  2. CVE-2026-76504Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Cisco · Catalyst SD-WAN Manager

    Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · cisco.com

    Attack probability (EPSS)

    1.57%75th pct

    KEV dates

    added due
  3. CVE-2026-86950Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Apple · Multiple Products

    Apple Multiple Products Out-of-Bounds Write Vulnerability

    Severity

    8.8HIGHCVSS 3.1 · CISA-ADP

    Attack probability (EPSS)

    1.24%68th pct

    KEV dates

    added due
  4. CVE-2026-102489Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Zammad GmbH · Zammad

    Zammad GmbH Zammad Session Fixation Vulnerability

    Severity

    9.4CRITICALCVSS 4.0 · divd.nl

    Attack probability (EPSS)

    0.58%46th pct

    KEV dates

    added due
  5. CVE-2026-102490Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Zammad GmbH · Zammad

    Zammad GmbH Zammad Improper Privilege Management Vulnerability

    Severity

    9.4CRITICALCVSS 4.0 · divd.nl

    Attack probability (EPSS)

    0.26%16th pct

    KEV dates

    added due

All entries are in KEV, so the order is EPSS probability, then published CVSS. Scores are shown as each source published them.

The week in numbers

4 vendors had products added: Zammad GmbH (2), Fortinet (1), Cisco (1), Apple (1). CISA marks none of the 5 as known to be used in ransomware campaigns.

Due dates in this batch run from 2 Oct 2026 to 5 Oct 2026. They bind US federal civilian agencies; for everyone else they indicate how urgent CISA considers each fix.

Other weeks

Questions

How many vulnerabilities were added to CISA KEV in the week of 28 Sep 2026?

5, between 28 Sep 2026 and 4 Oct 2026, according to catalog version 2026.10.02 collected on 3 Oct 2026. The week had not ended at collection time, so the number can still grow.

Why do additions come in batches?

CISA updates the catalog on US business days and often adds several CVEs in one notice, for example a set of vulnerabilities in the same product that are chained in an attack. Weeks with no additions also happen.

How is the week defined?

By the "dateAdded" field of each entry, grouped in ISO 8601 weeks, Monday to Sunday.

Related sections