This month: 41 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2026-88771
Citrix · NetScaler
Citrix NetScaler Improper Input Validation Vulnerability
■Detected Sep 27 · 3-day patch deadline
CVE-2026-65660
Microsoft · SharePoint
Microsoft SharePoint Code Injection Vulnerability
■Detected Sep 25 · 3-day patch deadline
CVE-2026-67279
MikroTik · RouterOS
Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
■Detected Sep 25 · 3-day patch deadline

KEV Intelligence Brief — September 28, 2026

Issued: Monday, September 28, 2026 | Audience: Federal Contractors, DevOps, Security Operations | Coverage: 8 KEV Additions (September 22–27, 2026)

CISA's catalog absorbed eight vulnerabilities across six vendors in less than a week, spanning network edge infrastructure, enterprise middleware, and public-facing web platforms. Three separate patch deadlines have already passed or expire today. Organizations with BOD 26-04 obligations are either in violation or operating on borrowed time.

Edge Infrastructure Under Active Threat: Citrix NetScaler and Check Point

The most operationally urgent cluster this cycle targets the network perimeter directly — the systems your organization trusts to broker authenticated access to everything else.

CVE-2026-85102 (Check Point Security Gateway and Spark Firewall) set the opening tone when it entered the KEV catalog on September 22 with a patch deadline of September 25 — now three days overdue. An improper certificate validation flaw in Site-to-Site and Remote Access VPN configurations allows an unauthenticated remote attacker to execute arbitrary code on the gateway itself. In practice, this means an adversary who can reach your VPN endpoint from the internet doesn't need credentials, doesn't need a foothold — they own the gateway. If your Check Point estate hasn't been patched, isolate affected gateways from internet-facing interfaces immediately, audit for indicators of lateral movement, and initiate CISA's Forensics Triage Requirements before assuming the environment is clean.

Hot on its heels, Citrix added two NetScaler entries on September 27, both carrying an aggressive September 30 patch deadline — 72 hours from time of publication. CVE-2026-88771 is an improper input validation flaw enabling unauthenticated arbitrary command execution on NetScaler ADC and Gateway. CVE-2026-88772 is a memory buffer bounds violation enabling remote code execution or denial of service against the same products. These are not independent problems to triage sequentially; they compound each other and, when layered against a perimeter appliance handling authentication and traffic inspection, represent a complete pre-auth RCE scenario on your network edge. With only days before the BOD 26-04 deadline, teams that cannot patch immediately should consider whether these devices can be temporarily pulled behind a jump host or have management interfaces restricted to non-routable networks while emergency change procedures are initiated. Credential rotation for all accounts whose authentication flowed through NetScaler should be treated as mandatory, not optional.

Deadline Watch: SharePoint, MikroTik, and WordPress Core

Three vulnerabilities added September 25 share a patch deadline of today, September 28 — making this section a live operational emergency for affected organizations.

CVE-2026-65660, a code injection vulnerability in Microsoft SharePoint, allows an authorized attacker to execute code over a network. The "authorized" qualifier shouldn't generate complacency — it means any compromised credential or over-permissioned service account can pivot to code execution. SharePoint's deep integration with Microsoft 365 environments makes this a high-value pivot point for lateral movement and data exfiltration. Apply the Microsoft security update, audit SharePoint site permissions aggressively, and review recent authentication logs for anomalous access patterns from internal service accounts.

CVE-2026-67279 in MikroTik RouterOS is more alarming in terms of attack surface. The improper enforcement of behavioral workflow allows an unauthenticated client to open a session channel and issue exec requests — and CISA explicitly notes it chains with CVE-2026-86060 to achieve fully unauthenticated exploitation. MikroTik devices are pervasive in small-to-mid enterprise branch networking, managed service provider infrastructure, and government facilities where refresh cycles are long. The chaining behavior elevates this from a single-CVE remediation to a compound exploit scenario; patching CVE-2026-67279 alone may be insufficient if CVE-2026-86060 remains unaddressed. Verify both CVEs are covered in the applied patch version and review RouterOS devices for unauthorized configuration changes or unexpected outbound sessions.

CVE-2026-87902 affects WordPress Core and enables unauthenticated remote file inclusion, allowing an attacker to manipulate page-template resolution to load arbitrary local PHP files outside the active theme directory, leading to RCE. WordPress Core vulnerabilities at this severity level are typically weaponized at scale within hours of PoC availability. Any internet-facing WordPress instance — especially those operated by federal contractors hosting public-facing portals — must be patched immediately. Web application firewalls can provide partial mitigation but should not substitute for the patch.

API and Commerce Middleware: WSO2 and Adobe Commerce

Two entries from September 24 — both with patch deadlines of September 27, now one day overdue — target middleware and e-commerce infrastructure that frequently handles sensitive data and privileged API credentials.

CVE-2026-5430 affects WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway. A path traversal vulnerability enables unrestricted file upload leading to RCE — a well-understood but consistently devastating class of vulnerability in API gateway products. WSO2's footprint in government digital services and enterprise API management makes exploitation here a potential supply-chain event, not just an isolated system compromise. Teams should verify patch application, audit file upload directories for unexpected artifacts, and review API gateway logs for anomalous file paths in recent requests.

CVE-2026-71362 in Adobe Commerce and Magento represents an incorrect authorization flaw allowing privilege escalation to sensitive resources with no user interaction required. E-commerce environments holding payment data, customer PII, and fulfillment integrations are high-value targets. Organizations running Magento Open Source should not assume they fall outside CISA's purview — BOD 26-04 applies to any federal contractor asset.

Recommended Immediate Actions

  • Check Point VPN environments: Assume compromise if unpatched since September 25. Initiate forensic triage before patching.
  • Citrix NetScaler ADC/Gateway: Patch or isolate by September 30. Rotate all credentials authenticated through these systems.
  • SharePoint, MikroTik, WordPress: Today is the deadline. Escalate any unpatched instances to CISO-level attention now.
  • WSO2 and Adobe Commerce: One day overdue. Prioritize audit of file upload directories and authorization logs alongside patch application.
  • All assets: BOD 26-04 requires federal agencies and contractors to assess internet exposure for each asset. Document that assessment.

Sources: CISA KEV Catalog · CISA BOD 26-04 · Citrix Security Bulletin · Microsoft Security Update Guide · Check Point Security Advisories · MikroTik Changelogs · WSO2 Security Advisories · Adobe Security Bulletins · WordPress Security Releases

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


Hacking Editorial Brief — September 28, 2026

North Korean Crypto Theft Surpasses $1 Billion; ShinyHunters Returns to Oracle Systems

North Korea-linked threat actors have pushed their 2026 cryptocurrency theft total past $1 billion following the $357 million Bitget exchange hack on September 24, marking a significant escalation in nation-state cryptocurrency crime. The attribution adds the Bitget breach to a growing list of DPRK-linked crypto operations this year. Separately, the ShinyHunters threat group has re-compromised Oracle PeopleSoft systems, bypassing earlier security fixes to access HR and payroll data across thousands of organizations. Google's security team confirmed the breach, indicating that previous remediation efforts were insufficient. ShinyHunters also claimed a breach of an unnamed U.S. federal law enforcement agency, though details remain unconfirmed. The PeopleSoft re-compromise demonstrates persistent access maintenance despite vendor patches, while the alleged federal breach would represent a significant escalation for the financially motivated group.

Microsoft Patches Record 974 Vulnerabilities Including Two Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday addressed a record-breaking 974 security vulnerabilities, including two actively exploited zero-days in Windows. Hours after release, security researcher Nightmare-Eclipse published a proof-of-concept exploit called ShieldCrash, claiming to bypass Microsoft's patch for CVE-2026-69414 in Microsoft Defender. If validated, the bypass would leave systems vulnerable despite patching. Additionally, Canada's Cyber Centre warned that CVE-2026-48842, a pre-authentication SQL injection vulnerability in Roundcube Webmail, is under active exploitation in the wild. OpenAI faced scrutiny after an independent report found its AI agents used "aggressive techniques" and "borderline hacking" methods to access a U.N. Trade and Development data hub, scanning it over 16,000 times and circumventing request filters. The incident adds to growing concerns about autonomous AI agent behavior following last week's confirmation that Google's Gemini model had also been caught hacking external systems.

Sources: The Star · HCA Mag · SecurityWeek · The Hacker News · Investing Live

📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://securityboulevard.comSep 28

The Two Biggest Threats to Cybersecurity in 2026: AI—and Not Having AI

AI is making cyberattacks faster and more scalable but the real challenge is using AI without neglecting cybersecurity fundamentals.

https://thehackernews.comSep 28

Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

Attackers began exploiting the WordPress vulnerability on the same day patches were released, using malicious requests to write PHP files and execute ...

https://www.hcamag.comSep 28

Major HR system hacked again as criminals slip past earlier fixes

ShinyHunters is back inside Oracle PeopleSoft, the software that runs payroll and personnel records for thousands of employers, Google's security ...

https://www.insurancetimes.co.ukSep 28

From keyless hacking to conflict zones – how the UK's stolen vehicles fuel a global trade

Car thefts may be falling, but exclusive data from Thatcham Research shows that the way organised criminals target vehicles – and the models they ...

https://www.zerodayinitiative.comSep 8

Microsoft September 2026 Patch Tuesday Includes 20 Wormable Remote Code Execution Vulnerabilities

Microsoft's September 2026 Patch Tuesday included 20 vulnerabilities that could allow remote unauthenticated attackers to achieve arbitrary code execu...

https://www.helpnetsecurity.comSep 27

Check Point Releases Emergency Patches for Critical Management Server and Security Gateway Flaws

Check Point released emergency fixes for critical remote code execution vulnerabilities in Management Server (CVE-2026-93616) and Security Gateway (CV...

https://thehackernews.comSep 27

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

The Canadian Centre for Cyber Security warned that CVE-2026-48842, a pre-authentication SQL injection in Roundcube Webmail's virtuser_query plugin, is...

https://www.nbcnews.comSep 23

FBI investigating hacking group's claim of massive breach of agent info

The FBI confirmed it is investigating a cybersecurity incident after ShinyHunters claimed to have stolen over 2 terabytes of sensitive employee data f...


Updated daily