CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief — September 23, 2026
Classification: TLP:CLEAR | Audience: Federal Contractors, DevOps, SecOps Leadership Reporting Period: September 18–22, 2026 | Prepared: September 23, 2026
Eight new entries hit CISA's Known Exploited Vulnerabilities catalog across the past five days, spanning network security infrastructure, SD-WAN orchestration, and the Linux kernel. The pattern is stark: threat actors are actively targeting perimeter enforcement layers and the foundational OS underpinning most enterprise workloads. Three of these deadlines have already passed.
Deadline Watch: Perimeter Infrastructure Under Active Exploitation
The most operationally urgent cluster involves Check Point, Arista, and F5 — all carrying a September 25 patch deadline (two days from publication of this brief) under BOD 26-04. A secondary cluster from Zyxel expired September 24, meaning it is effectively overdue as of today.
CVE-2026-85102 is the highest-priority entry in this cohort. Check Point Security Gateway and Spark Firewall are affected by an improper certificate validation flaw in their Site-to-Site and Remote Access VPN implementations that allows unauthenticated remote code execution on the gateway itself. This is a direct, pre-auth RCE on your VPN perimeter — the device designed to stop attackers is the attack surface. Organizations that cannot immediately patch should place these gateways behind strict network-layer access controls, disable internet-facing VPN portals if feasible, and initiate credential rotation for all accounts that may have authenticated through affected gateways. CISA's forensic triage requirements apply; treat any affected, internet-exposed gateway as potentially compromised prior to patching.
CVE-2026-93616 compounds the Check Point exposure by targeting the management plane — Security Management Server, Multi-Domain Security Management, Log Server, and SmartEvent. A path traversal flaw allows unauthenticated attackers to upload and execute arbitrary scripts. Management servers commonly hold policy configurations, credentials, and audit logs for an entire security estate. If you're patching the gateway (CVE-2026-85102) but not the management server, you may be restoring a clean perimeter while leaving the control plane open. Audit external access to management interfaces immediately.
CVE-2026-93952 affects Arista VeloCloud Orchestrator (on-prem deployments), where improper input validation allows a remote attacker to reach privileged internal functionality, compromising the orchestrator and all managed network data. VCO is a single pane of glass for SD-WAN policy — compromise here translates to lateral movement and policy manipulation across branch infrastructure. Organizations running on-prem VCO should confirm internet isolation of the management interface and review orchestrator audit logs for anomalous API calls dating back at least 30 days.
CVE-2026-94127 rounds out this cluster: F5 BIG-IP APM contains a heap-based buffer overflow triggered when both an access policy and an OAuth profile are configured on a virtual server. This is another unauthenticated RCE pathway on a component that sits between users and protected applications. The specific configuration dependency (OAuth + access policy) narrows exposure but does not eliminate urgency — many enterprise BIG-IP APM deployments use OAuth for SSO integration. Confirm configuration posture and apply F5's hotfix immediately.
CVE-2026-7273 (Zyxel GS1900 Series) is a stack-based buffer overflow in the switch CGI program. The attacker must be LAN-adjacent, which reduces external exposure but raises internal threat concerns — branch office switches, warehouse environments, and OT-adjacent network segments are common deployment zones. The September 24 deadline has passed; firmware updates should be applied during the next available maintenance window with no further delay.
Linux Kernel: Three Exploited Vulnerabilities, Deadlines Already Elapsed
Three Linux Kernel entries added September 18 carried a September 21 patch deadline — now two days overdue. Any federal agency or contractor running affected kernel versions on internet-accessible systems is out of compliance with BOD 26-04 as of this morning.
CVE-2025-39682 exploits the TLS receive path, where a zero-length record in the rx_list bypasses recvmsg() record-type handling, corrupting assumptions for subsequent TLS record processing. In practice, this can undermine the integrity of encrypted communications and destabilize affected services. CISA flags that impacted versions may be end-of-life; for EoL systems, patching is not sufficient — migration to a supported kernel branch is required.
CVE-2025-39964 is a race condition in AF_ALG socket handling. Concurrent writes produce unpredictably interleaved data and internal state corruption. AF_ALG is the kernel's cryptographic API socket interface, and exploitation of this race can lead to privilege escalation or data integrity violations in applications relying on kernel-level crypto operations — a meaningful concern for systems using kernel-space TLS or IPsec offloading.
CVE-2026-53266 is an out-of-bounds write in the ebtables SNAT target. ARP sender hardware address rewrites can push data directly into a nonlinear socket buffer fragment backed by a splice-imported file page — a memory safety violation with exploitation potential for privilege escalation or kernel code execution in container and virtualized environments. Like CVE-2025-39682, CISA notes potential EoL status; organizations should audit kernel versions across their fleet immediately.
For DevOps and platform engineering teams: these three kernel CVEs should be integrated into your base image update pipelines today. Container base images, VM templates, and CI/CD runner environments are all in scope. Running uname -r checks across your fleet against vendor-published fixed versions is a prerequisite for BOD 26-04 compliance attestation.
Recommended Immediate Actions
- Check Point (CVE-2026-85102, CVE-2026-93616): Patch by September 25. Treat internet-exposed gateways as potentially compromised. Rotate VPN credentials and management server service accounts regardless of patch status.
- Arista VCO (CVE-2026-93952): Isolate management interface; apply vendor mitigations by September 25. Review orchestrator audit logs.
- F5 BIG-IP APM (CVE-2026-94127): Confirm OAuth + access policy configurations; apply hotfix by September 25.
- Zyxel GS1900 (CVE-2026-7273): Apply firmware now; deadline elapsed September 24.
- Linux Kernel (CVE-2025-39682, CVE-2025-39964, CVE-2026-53266): Deadline elapsed September 21. Update base images, running kernels, and VM templates. Migrate EoL systems to supported kernel versions.
Sources: CISA KEV Catalog · CISA BOD 26-04 · Check Point Security Advisories · Arista Security Advisories · F5 Security Advisories · Zyxel Security Advisories · Linux Kernel CVE Tracker
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
Hacking Editorial Brief — September 23, 2026
ShinyHunters Claims FBI Data Breach, Investigation Underway
The digital extortion group ShinyHunters has claimed responsibility for breaching FBI systems and stealing personnel data on thousands of current and former federal agents. The FBI has confirmed an investigation is underway following the claim, though the scope and validity of the breach remain under assessment. ShinyHunters, a prolific cybercriminal group known for high-profile data theft operations, represents a significant threat if the claimed access to federal law enforcement personnel information is confirmed. The stolen data would likely include names, contact information, and potentially other personal details that could be used for targeting, doxing, or sold on criminal marketplaces. This marks a notable escalation in targeting of U.S. federal law enforcement infrastructure by established threat actors.
AI-Driven Autonomous Hacking Demonstrates New Offensive Capabilities
Google has confirmed that its Gemini AI autonomously compromised three additional companies in recent demonstrations, following earlier reports of AI-powered exploitation of Hugging Face. The incidents represent practical proof of "swarm" capabilities where multiple AI agents coordinate to accomplish complex hacking tasks without human intervention. Security researchers have expressed concern about the operational maturity of these AI-driven attack techniques, which can accelerate reconnaissance, vulnerability identification, and exploitation phases beyond human-paced operations. The confirmed breaches underscore that AI-assisted offensive capabilities are no longer theoretical—they are actively being demonstrated against real enterprise targets and represent a fundamental shift in attack velocity and automation.
Sources: Reuters/US News · ABC News · Axios · Security Magazine · CBS News
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
Russian Threat Actor Using AI to Rapidly Develop Exploits for PaperCut Vulnerabilities
A suspected Russian-speaking cyber actor is using artificial intelligence to devise exploits targeting PaperCut NG/MF security flaws and break into hu...
Cybercriminal group claims to steal thousands of FBI employee records - POLITICO
The FBI said it was probing a suspected hack, after the cybercriminal group ShinyHunters claimed to have breached its systems.
FBI investigating apparent breach after hackers claim to have stolen thousands of federal ... - CNN
The FBI is investigating an apparent breach of its networks after a prolific cybercriminal group claimed on Tuesday to have stolen thousands of ...
ShinyHunters Claims FBI System Compromise, Issues Extortion Threat
ShinyHunters claimed to have compromised FBI systems including CJ, HR, and Medlink, issuing threats to expose sensitive data about FBI agents and appl...
Federal Authorities Disrupt China-Backed Hacking Operation Targeting US Critical Infrastructure
The FBI and Department of Justice seized domains linked to QTFY, a China-nexus hacking operation that targeted multiple federal agencies and critical ...
Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
Microsoft released fixes for a maximum-severity CVSS 10.0 security flaw in Azure AI Foundry (CVE-2026-85889) that could allow unauthenticated attacker...
Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
The Hacker News has contacted Hacktron with questions about how the forum code execution was achieved and about the scope of the account access. What ...
Cisco ISE Authentication Bypass Under Active Exploit - CVE-2026-76460
Cisco disclosed CVE-2026-76460, an authentication bypass affecting Identity Services Engine (ISE) that allows unauthenticated remote attackers to exec...
Updated daily
