Vulnerability Report - September 2026
Introduction
This vulnerability report has been generated with the help of AI, using the VulnMCP tooling on top of Vulnerability-Lookup, with contributions from the platform’s community.
It highlights the most frequently sighted vulnerabilities for September 2026, based on data aggregated from Vulnerability-Lookup, the CISA Known Exploited Vulnerabilities catalog, the CIRCL KEV catalog, the ENISA EUVD / EU CSIRTs Network feed, honeypot observations from The Shadowserver Foundation, the Previdian catalog (formerly known as KEVIntel – same catalog, new name), and contributor comments and bundles. These five KEV catalogs are federated through the GCVE initiative: each one is identified by the UUID of the Global Naming Authority (GNA) that publishes it, and exchanged between instances following the GCVE-BCP-07 specification – which is what makes the catalog coverage comparison further down possible. Sightings come from MISP, Exploit-DB, Bluesky, Mastodon, Telegram, GitHub Gists, Nuclei, SPLOITUS, Metasploit, and more. For further details, please visit this page.
September was the month of the network edge. Citrix NetScaler, Check Point, F5 BIG-IP, Cisco (four different products), Fortinet, SonicWall, MikroTik, Zyxel and Arista all had exploited vulnerabilities enter the CISA catalog, and the four vulnerabilities that every European catalog agreed on – two NetScaler issues, the Check Point VPN certificate flaw and the F5 BIG-IP APM heap overflow – are all unauthenticated remote code execution on security appliances. The second thread is exploitation reports arriving from more directions than before: CERT.PL’s “MikroTrick” research reached the ENISA feed five days before CISA listed it, NCSC-NL flagged WordPress core and two Zammad zero-days, and CIRCL confirmed seven exploitations including a ransomware case. The CVE Program set another monthly record at nearly 15,000 CVEs, and the KEV catalogs collectively flagged 166 vulnerabilities, up from 102 in August.
The Month at a Glance
14,959 CVEs were published in September 2026 (from the CVE List v5 source alone), up from 12,315 in August – a 21.5% month-over-month increase and, once again, the highest monthly volume ever recorded. Vulnerability-Lookup also ingested 14,128 GitHub security advisories and 186 PySec advisories over the same period.

Evolution of published CVEs in 2026 (CVE Program source), as shown on the Vulnerability-Lookup dashboard. The October data point only covers the first day of the month.
Vulnerability-Lookup collected 43,109 sightings across 15,296 distinct vulnerabilities during September 2026, up from 33,732 in August (+27.8%). The breakdown:
| Sighting type | Count | Distinct vulnerabilities |
|---|---|---|
| Seen | 32,981 | 14,680 |
| Published proof of concept | 6,482 | 3,736 |
| Exploited | 3,589 | 930 |
| Confirmed | 57 | 57 |
The August figures used for comparison are those returned by the API today (the August report quoted higher totals at the time of publication, before the sighting data was consolidated). On that basis every category except one grew: “seen” mentions rose from 25,643 to 32,981 (+29%), published proof-of-concept sightings from 4,819 to 6,482 (+35%), and exploitation-typed sightings from 3,204 to 3,589 (+12%), spread over 930 distinct vulnerabilities against 883 in August. The exception is confirmed sightings, which fell from 66 to 57 – each one on a different vulnerability, so the confirmed set is 57 distinct issues, among them the F5 BIG-IP APM RCE, the WordPress core file inclusion and the GitLab path traversal. No “patched” sightings were recorded.
The daily breakdown is dominated by 1 September, the busiest day of the month with 5,114 sightings, of which 4,979 are “seen”: a bulk batch of Telegram-sourced mentions covering 3,039 distinct vulnerabilities, led by Log4Shell, the MSHTML CVE-2021-40444, PrintNightmare and Confluence CVE-2022-26134 – a catalogue of 2021-era classics rather than new activity. The proof-of-concept peak comes two days later, on 3 September (911), spread thinly over 595 vulnerabilities. After that the “seen” band follows the disclosure calendar: 8–9 September (Patch Tuesday, the Windows ALPC and Update Stack privilege escalations, both Chrome V8 issues, N-central and Adobe Commerce), 15 September (the Cisco Secure Email Gateway SQL injection), 23 September (F5 BIG-IP APM, WordPress core and the two Check Point issues) and 29 September (the NetScaler pair and the Apple CoreGraphics zero-day). Exploitation-typed sightings peak on 10 and 19 September (222 and 212). The quietest stretch is the weekend of 20–21 September, under 600 per day.
In the exploitation-typed sightings, Log4Shell (CVE-2021-44228, 74 exploitation reports) remains the single most reported vulnerability for yet another month. It is followed by a relative newcomer, the NetScaler SAML IdP memory overread CVE-2026-3055 (44), listed by CISA at the end of March and still being actively reported, then by the Cisco IOS XE web UI privilege escalation CVE-2023-20198 (37), the cPanel/WHM authentication bypass CVE-2026-41940 (37) and Confluence CVE-2022-26134 (35). Proof-of-concept activity again concentrated on the Linux kernel rtmutex flaw CVE-2026-43499 (59, second month at the top), the WordPress core page-template file inclusion CVE-2026-87902 (45), the cPanel bypass (34) and an Android Contacts Provider SQL injection, CVE-2026-28576 (33), which no tracked catalog lists.
Top 10 Vendors of the Month
Linux keeps the top of the vendor ranking for a second month, now with close to 40% of the month’s attributed CVEs – the kernel CVE flood shows no sign of slowing – ahead of Microsoft, Google and Oracle. Dell enters the top ten, and the “unknown” slice (records without a usable vendor field) is large enough to rank fifth.
Top 10 Assigners of the Month
The kernel CNA leads the assigners, followed by VulnCheck and GitHub’s CNA, with Microsoft, VulDB, Oracle and WPScan behind them.
Top 10 Credits of the Month
WPScan stays first with around 550 credited vulnerabilities, but the VulDB CNA Team has closed most of the gap at roughly 510. A single researcher, George Chen, takes third place with more than 200 credits, well ahead of Mozilla, Patchstack’s bug bounty program, HPE Networking’s internal research team, VulnCheck and Wordfence PRISM.
The complete list of credits is available on Vulnerability-Lookup.
Top 10 Vulnerabilities of the Month
| Vulnerability | Sighting Count | Vendor | Product | VLAI Severity |
|---|---|---|---|---|
| CVE-2026-87902 | 247 | WordPress | Core (page templates) | Critical (confidence: 0.6985) |
| CVE-2026-85706 | 246 | GitLab | GitLab CE/EE | High (confidence: 0.7211) |
| CVE-2026-88771 | 217 | Citrix | NetScaler ADC / Gateway | Critical (confidence: 0.9895) |
| CVE-2021-44228 | 196 | Apache | Log4j2 | High (confidence: 0.7501) |
| CVE-2026-88772 | 191 | Citrix | NetScaler ADC / Gateway | Critical (confidence: 0.9889) |
| CVE-2026-85046 | 162 | Chrome (V8) | High (confidence: 0.9883) | |
| CVE-2026-94127 | 143 | F5 | BIG-IP APM | Critical (confidence: 0.9345) |
| CVE-2026-41940 | 131 | WebPros | cPanel & WHM | Critical (confidence: 0.9793) |
| CVE-2026-76461 | 117 | Cisco | Secure Email Gateway | Critical (confidence: 0.9582) |
| CVE-2026-43499 | 113 | Linux | Kernel (rtmutex) | High (confidence: 0.9738) |
Two vulnerabilities share the top of the list, one sighting apart. The WordPress core
remote file inclusion CVE-2026-87902,
disclosed on 22 September, lets an unauthenticated attacker point page-template resolution at
any readable .php file on the server; NCSC-NL reported active abuse the next day and CISA
listed it on 25 September. It is followed by the GitLab repository commits API path
traversal CVE-2026-85706, an
unauthenticated arbitrary file read disclosed in mid-September and listed by CISA on the 11th
– a second GitLab entry in as many months after August’s GraphQL code injection. The two
NetScaler issues of 27 September take third and fifth place in just four days of
sightings: the improper input validation RCE
CVE-2026-88771 and the memory overflow
CVE-2026-88772, both exploited before the
bulletin was out and both entered into four catalogs within 24 hours. Log4Shell, in fourth
place, is the only pre-2026 entry. The rest of the list is a tour of September’s CISA
additions: the Chrome V8 type confusion
CVE-2026-85046 (the first of two V8 entries
this month), the F5 BIG-IP APM OAuth heap overflow
CVE-2026-94127, the cPanel bypass that has
sat in the top ten since May, the Cisco Secure Email Gateway SQL injection
CVE-2026-76461 – root command execution
through a crafted e-mail – and the Linux kernel rtmutex issue, which ties for tenth place with
the Adobe Commerce template injection
CVE-2026-75650 and the JFrog Artifactory
authentication bypass CVE-2026-82329, all
at 113 sightings.
Known Exploited Vulnerabilities
New entries were added to the tracked Known Exploited Vulnerabilities catalogs during September. The five catalogs are complementary rather than redundant: CISA is the reference set, CIRCL and the ENISA / EU CSIRTs Network feed add European confirmations, Shadowserver’s honeypots show what is actually being attacked on the wire, and Previdian aggregates public exploitation reports at higher volume and often earlier – each of the last two surfacing vulnerabilities no other catalog lists.
A total of 166 distinct vulnerabilities entered at least one tracked catalog this month, against 102 in August: 43 were added by CISA, 7 by CIRCL, 19 were reported through the ENISA / EU CSIRTs Network feed, 16 were observed for the first time by Shadowserver’s honeypots and 156 were added by Previdian. Every catalog grew except Shadowserver, whose feed stopped delivering new observations after 7 September (see below), so its figure only covers the first week.

The exploited CVE ratio per publication year: share of CVEs with at least one exploitation or proof-of-concept sighting over all published CVEs of that year. Recent years are undercounted, as sightings accumulate over time.

The same ratio per publication month of 2026. September’s 4.55% is the lowest full month of the year, mechanically: the record volume of new CVEs has not yet had time to accumulate exploitation sightings, whereas April’s 20.78% reflects five months of catch-up.
The month’s story is the security appliance. Citrix NetScaler entered the CISA catalog three times: the authentication bypass CVE-2026-19490 on 9 September (the companion of the bulletin a contributor bundled in August, and flagged by Previdian six days earlier), then CVE-2026-88771 and CVE-2026-88772 on Saturday 27 September, the same day Citrix published its bulletin and the ENISA feed, Previdian and – the next day – CIRCL picked them up. Check Point contributed a pair on 22 September: the VPN certificate validation RCE CVE-2026-85102, which reaches any Quantum gateway with site-to-site or remote-access VPN, and the management server path traversal CVE-2026-93616. F5 BIG-IP APM followed the same day with the OAuth authorization-server heap overflow CVE-2026-94127, which CIRCL confirmed on 23 September. Cisco had four distinct products listed: the Secure Firewall Management Center authentication bypass CVE-2026-20079, tagged as ransomware-exploited with confirmed EU victims in the ENISA feed, the Secure Email Gateway SQL injection, the ISE API authentication bypass CVE-2026-76460 and, on the last day of the month, the Catalyst SD-WAN Manager admin-session bypass CVE-2026-76504. Fortinet (FortiOS heap overflow CVE-2025-25249), SonicWall (two SMA1000 issues), Arista VeloCloud Orchestrator, Zyxel GS1900 switches and Palo Alto (the GlobalProtect bypass CVE-2026-0257, which CIRCL tied to a ransomware incident on 1 September) complete the picture. Across the month, more than a third of CISA’s additions concern a firewall, VPN, load balancer or network-management product.
MikroTik RouterOS deserves its own paragraph. CERT.PL’s “MikroTrick” research produced four SSH-related CVEs, three of which the Polish CSIRT reported to the ENISA feed on 5 September: the policy-mask privilege escalation CVE-2026-86060, the btest kernel memory disclosure CVE-2026-67277 and the RSA exponent-one user impersonation CVE-2026-67276. CISA listed the first two on 10 September – five days after the ENISA feed – and added the pre-authentication rekey bypass CVE-2026-67279 on 25 September, noting that it chains with the privilege escalation for a fully unauthenticated compromise. The impersonation flaw remains visible only through ENISA and Previdian.
On the developer and operations tooling side, JFrog Artifactory had three CISA entries (the default-configuration administrative bypass CVE-2026-82329 on 2 September, then a token-scope and an anonymous-token issue on the 11th), N-able N-central returned for a third month with the pre-authentication RCE CVE-2026-86218, and ConnectWise ScreenConnect, Acronis’s cPanel backup plugin, WSO2 (a JWT algorithm-mismatch account takeover rated CVSS 10.0) and Kestra joined them. The AI stack is quieter than in August but not absent: CISA listed the LiteLLM MCP authentication bypass CVE-2026-59822 and the Starlette host-header path confusion it chains with, Previdian added Langflow (CVE-2026-0769, 38.6% EPSS), two Flowise issues, Dify, Nuclio, Red Hat OpenShift AI’s Feast component and two agent frameworks (OmniRoute, Flyto2) that expose command execution over MCP.
Client-side entries were few but notable: two Chrome V8 issues (CVE-2026-85046 on 4 September, CVE-2026-87491 on the 9th), the Apple CoreGraphics out-of-bounds write CVE-2026-86950, which Apple says was used “in an extremely sophisticated attack against specific targeted individuals”, a Google Pixel modem permission bypass, the two Windows local privilege escalations of Patch Tuesday, and three Linux kernel entries on 18 September (the AF_ALG race, the TLS zero-length record issue and the ebtables SNAT out-of-bounds write) – continuing the kernel-exploit pattern noticed in August. The ENISA feed also brought two issues no other reference catalog lists: the GeoNetwork unauthenticated RCE chain (CVE-2026-58400, CVE-2026-63219) affecting government geoportal back-ends, and two Zammad zero-days reported by NCSC-NL on 30 September.
Across the month’s KEV additions, the dominant weakness patterns were missing or improper authentication (CWE-287/288/306/863: NetScaler, Cisco FMC, ISE and SD-WAN Manager, Artifactory, WSO2, Kestra, LiteLLM, Adobe Commerce, SonicWall), memory corruption in appliances and clients (CWE-119/122/787: NetScaler, F5, Fortinet, Zyxel, Chrome, Apple, Windows ALPC), path traversal and file inclusion (CWE-22/98: Check Point, GitLab, WordPress, WSO2) and, for the Previdian-only set, SQL injection in older web applications.
Catalog coverage
166 distinct vulnerabilities entered at least one of the tracked KEV catalogs during September. The matrix below shows, for each of them, which catalogs cover it (as of publication) – built with the KEV catalog coverage feature of Vulnerability-Lookup. Previdian is by far the widest net with 163 of the 166, ahead of CISA (49, including entries it had listed before September), ENISA (19), Shadowserver (18) and CIRCL (7). Five vulnerabilities of the month are present in four catalogs at once: the two NetScaler issues (CVE-2026-88771, CVE-2026-88772), the Check Point VPN RCE CVE-2026-85102 and the F5 BIG-IP APM overflow CVE-2026-94127 – all in CISA, CIRCL, ENISA and Previdian – plus Log4Shell CVE-2021-44228, which CIRCL added on 3 September and which was already in CISA, Shadowserver and Previdian. Thirteen more are in three catalogs, among them the WordPress core file inclusion, the SharePoint code injection, the three MikroTik entries, both Cisco FMC issues and the Sangoma Switchvox SQL injection CVE-2026-9586 – the only entry of the month that CISA, Previdian and Shadowserver’s honeypots all saw.
At the other end, 99 entries are visible through a single catalog: 96 only via Previdian (the AI-tooling cluster, a large batch of Chinese enterprise software and WordPress plugin issues, XWiki, Ghost, OpenCTI and a long tail of high-EPSS legacy flaws), 2 only via ENISA (the GeoNetwork pair) and 1 only via CIRCL – GCVE-1-2026-20026, an unauthenticated remote code execution in older firmware, discovered by CIRCL and published under its own GCVE numbering. For the first time, no entry is unique to CISA: every one of its 43 additions is also in Previdian.
CISA
The CISA KEV catalog added 43 entries in September, well above August’s 31 and the busiest month of the year by a wide margin. None of them carries a known ransomware campaign use flag, even though the ENISA feed tags the Cisco FMC pair as ransomware-exploited and CIRCL tied the PAN-OS GlobalProtect bypass to a ransomware case.
| CVE ID | Date Added | Vendor | Product | VLAI Severity |
|---|---|---|---|---|
| CVE-2026-76504 | 2026-09-30 | Cisco | Catalyst SD-WAN Manager | Critical (confidence: 0.9965) |
| CVE-2026-86950 | 2026-09-29 | Apple | Multiple Products | High (confidence: 0.9903) |
| CVE-2026-88772 | 2026-09-27 | Citrix | NetScaler | Critical (confidence: 0.9889) |
| CVE-2026-88771 | 2026-09-27 | Citrix | NetScaler | Critical (confidence: 0.9895) |
| CVE-2026-87902 | 2026-09-25 | WordPress | Core | Critical (confidence: 0.6985) |
| CVE-2026-67279 | 2026-09-25 | MikroTik | RouterOS | High (confidence: 0.3884) |
| CVE-2026-65660 | 2026-09-25 | Microsoft | SharePoint | High (confidence: 0.9941) |
| CVE-2026-71362 | 2026-09-24 | Adobe | Commerce and Magento | Critical (confidence: 0.8496) |
| CVE-2026-5430 | 2026-09-24 | WSO2 | Multiple Products | Critical (confidence: 0.9983) |
| CVE-2026-94127 | 2026-09-22 | F5 | BIG-IP APM | Critical (confidence: 0.9345) |
| CVE-2026-93952 | 2026-09-22 | Arista | VeloCloud Orchestrator | Critical (confidence: 0.9933) |
| CVE-2026-93616 | 2026-09-22 | Check Point | Multiple Products | Critical (confidence: 0.9578) |
| CVE-2026-85102 | 2026-09-22 | Check Point | Multiple Products | Critical (confidence: 0.8336) |
| CVE-2026-7273 | 2026-09-21 | Zyxel | GS1900 Series Switches | High (confidence: 0.9359) |
| CVE-2026-53266 | 2026-09-18 | Linux | Kernel | High (confidence: 0.9115) |
| CVE-2025-39964 | 2026-09-18 | Linux | Kernel | High (confidence: 0.7034) |
| CVE-2025-39682 | 2026-09-18 | Linux | Kernel | Critical (confidence: 0.8456) |
| CVE-2026-87886 | 2026-09-16 | Acronis | Backup | High (confidence: 0.6477) |
| CVE-2026-76460 | 2026-09-16 | Cisco | Identity Services Engine | Critical (confidence: 0.9506) |
| CVE-2026-58704 | 2026-09-16 | Pixel | High (confidence: 0.975) | |
| CVE-2026-76461 | 2026-09-14 | Cisco | Secure Email Gateway | Critical (confidence: 0.9582) |
| CVE-2026-85706 | 2026-09-11 | GitLab | Community Edition and Enterprise Edition | High (confidence: 0.7211) |
| CVE-2026-84869 | 2026-09-11 | ConnectWise | ScreenConnect | Critical (confidence: 0.9651) |
| CVE-2026-42018 | 2026-09-11 | JFrog | Artifactory | Medium (confidence: 0.8322) |
| CVE-2026-42016 | 2026-09-11 | JFrog | Artifactory | High (confidence: 0.9281) |
| CVE-2026-86060 | 2026-09-10 | MikroTik | RouterOS | Critical (confidence: 0.6915) |
| CVE-2026-67277 | 2026-09-10 | MikroTik | RouterOS | High (confidence: 0.9783) |
| CVE-2026-87491 | 2026-09-09 | Chromium V8 | High (confidence: 0.9874) | |
| CVE-2026-20079 | 2026-09-09 | Cisco | Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management | Critical (confidence: 0.9956) |
| CVE-2026-19490 | 2026-09-09 | Citrix | NetScaler | Critical (confidence: 0.957) |
| CVE-2025-25249 | 2026-09-09 | Fortinet | Multiple Products | Medium (confidence: 0.4894) |
| CVE-2026-86218 | 2026-09-08 | N-able | N-central | Critical (confidence: 0.9501) |
| CVE-2026-85880 | 2026-09-08 | Microsoft | Windows | High (confidence: 0.9931) |
| CVE-2026-81963 | 2026-09-08 | Microsoft | Windows | High (confidence: 0.9844) |
| CVE-2026-75650 | 2026-09-08 | Adobe | Commerce and Magento | Critical (confidence: 0.9884) |
| CVE-2026-85046 | 2026-09-04 | Chromium V8 | High (confidence: 0.9883) | |
| CVE-2026-9586 | 2026-09-02 | Sangoma | Switchvox | Critical (confidence: 0.984) |
| CVE-2026-83549 | 2026-09-02 | SonicWall | SMA1000 Appliances | High (confidence: 0.8489) |
| CVE-2026-83548 | 2026-09-02 | SonicWall | SMA1000 Appliances | Critical (confidence: 0.5578) |
| CVE-2026-82329 | 2026-09-02 | JFrog | Artifactory | Critical (confidence: 0.969) |
| CVE-2026-59822 | 2026-09-02 | BerriAI | LiteLLM | High (confidence: 0.7412) |
| CVE-2026-49869 | 2026-09-02 | Kestra | Kestra OSS | Critical (confidence: 0.9926) |
| CVE-2026-48710 | 2026-09-02 | Kludex | Starlette | Medium (confidence: 0.7694) |
More KEV entries from the CISA Catalog.
CIRCL
The CIRCL KEV catalog added 7 entries during September, up from two in August and all marked as confirmed exploitation. The month opened with the Palo Alto GlobalProtect authentication bypass CVE-2026-0257, confirmed through CIRCL’s own incident response as a ransomware case (CISA had listed it in May), and with Log4Shell, still being confirmed in the wild almost five years on. On 9 September CIRCL published GCVE-1-2026-20026, a pre-authentication remote code execution in older firmware that has no CVE and is only identifiable through its GCVE number. The month closed with four entries that corroborate CISA: the F5 BIG-IP APM overflow on 23 September, the day after its CISA listing, then on 28 September the Check Point VPN RCE and both NetScaler issues, the latter one day after CISA.
| CVE ID | Date Added | Vendor | Product | VLAI Severity |
|---|---|---|---|---|
| CVE-2026-85102 | 2026-09-28 | Check Point | Quantum Security Gateway | Critical (confidence: 0.8336) |
| CVE-2026-88772 | 2026-09-28 | Citrix | NetScaler ADC / Gateway | Critical (confidence: 0.9889) |
| CVE-2026-88771 | 2026-09-28 | Citrix | NetScaler ADC / Gateway | Critical (confidence: 0.9895) |
| CVE-2026-94127 | 2026-09-23 | F5 | BIG-IP APM | Critical (confidence: 0.9345) |
| GCVE-1-2026-20026 | 2026-09-09 | – | – | – |
| CVE-2021-44228 | 2026-09-03 | Apache Software Foundation | Apache Log4j2 | High (confidence: 0.7501) |
| CVE-2026-0257 | 2026-09-01 | Palo Alto Networks | PAN-OS GlobalProtect | Medium (confidence: 0.7834) |
More KEV entries from the CIRCL Catalog.
ENISA (EUVD)
Nineteen entries were reported through the ENISA / EU CSIRTs Network (CNW) KEV feed during September, nearly three times August’s seven and the feed’s busiest month so far. Seven came from ENISA itself (both Check Point issues, F5, the two WordPress core issues of July (SQL injection and REST route confusion) re-reported with “EU victimology”, and the two Cisco FMC issues, tagged as ransomware with confirmed EU victims), four from CERT.PL (the MikroTrick research), four through the CNW channel (GeoNetwork and NetScaler), three from NCSC-NL (WordPress core on 23 September, two days before CISA, and the two Zammad zero-days) and one from CSIRT-IE (the SharePoint code injection). Five entries – the GeoNetwork pair, the MikroTik impersonation flaw and both Zammad issues – are not in the CISA catalog.
More KEV entries from the ENISA Catalog.
The Shadowserver Foundation
The Shadowserver KEV catalog is fed by honeypot-observed exploitation attempts. 16 vulnerabilities were observed for the first time during September, all between 1 and 7 September: the catalog’s most recent observation date is 7 September, so no honeypot data reached Vulnerability-Lookup for the last three weeks of the month and this section is necessarily partial. Two of the sixteen are in the CISA KEV catalog – the Sangoma Switchvox SQL injection CVE-2026-9586, hit on 4 September, two days after its CISA listing, and the MeteoBridge command injection CVE-2025-4008 from October 2025. The rest is the usual honeypot fare: consumer routers (four Totolink models, two Tenda CH22 issues, two D-Link models and a Shenzhen Aitemi Wi-Fi repeater), a Grandstream VoIP phone, PaperCut NG, ESDS Emagic, Weaver E-cology and a WordPress analytics plugin, each at one to three connections a day. Severity values are reproduced as published by Shadowserver (CVSS).
More KEV entries from the Shadowserver Catalog.
Previdian (formerly KEVIntel)
The Previdian catalog – the catalog reported as KEVIntel in previous editions, renamed but otherwise unchanged – aggregates public exploitation reports and added 156 entries in September, up from 91 in August and by far the highest volume of the tracked feeds. It covers all 43 of CISA’s additions for the month, a first since this report started comparing the two.
Eighteen of those it flagged before CISA did: the Adobe Commerce authorization bypass CVE-2026-71362 on 10 September, a full 14 days ahead; the WSO2 JWT account takeover CVE-2026-5430 by 8 days; the NetScaler authentication bypass CVE-2026-19490 by 6 days; the Adobe Commerce template injection CVE-2026-75650 by 3 days; the WordPress core file inclusion, the MikroTik rekey bypass, ScreenConnect and N-central by 2 days each; and ten more by one day, among them the Apple CoreGraphics zero-day, the SharePoint code injection, all three Artifactory issues and both SonicWall SMA1000 entries. The remaining 25 were listed on the same day as CISA, and none came later.
96 entries are unique to Previdian this month, 36 of them 2026 CVEs. The largest block is Chinese enterprise software added in two batches (14–18 and 29–30 September): Yonyou U8 CRM, U8 Cloud and A6 OA, Inspur HCM Cloud, Hongjing e-HR, Weaver E-cology, Chanjet CRM, Fumeng Cloud, iDocView, DedeCMS and Mingsoft MCMS – a cluster that only Shadowserver’s honeypots used to surface. The second block is WordPress plugins and small PHP applications with unauthenticated SQL injection or file upload (LearnPress, TI WooCommerce Wishlist, Modern Events Calendar, Elementor Pro, Super Forms, JetEngine and a dozen others). The AI cluster is again visible – Langflow CVE-2026-0769, two Flowise issues (CVE-2026-56271, CVE-2026-69255), Dify, Nuclio, OmniRoute, Flyto2 and Red Hat OpenShift AI – alongside XWiki (three entries, two above 77% EPSS), Ghost (CVE-2026-26980, 70.2% EPSS), OpenCTI (CVE-2026-27960, default admin account), Roundcube, Grav, Dolibarr, Veeam, two further N-central issues and the KGUARD DVR command execution CVE-2026-87827, the only entry of the month Previdian marks as used in malware. The legacy tail is as high-EPSS as ever: Drupalgeddon CVE-2014-3704 (99.97%), Joomla CVE-2017-8917 (99.8%), the Jenkins Script Security sandbox bypass CVE-2019-1003000 (98.4%), XWiki CVE-2023-37462 (91.5%) and FileCatalyst Workflow CVE-2024-5276 (90.1%).
Vendor, product, CVSS and EPSS values below are reproduced as published by Previdian.
| CVE ID | Date Added | Vendor | Product | Severity (Previdian) | EPSS |
|---|---|---|---|---|---|
| CVE-2026-76504 | 2026-09-30 | Cisco | Cisco Catalyst SD-WAN Manager | Critical (CVSS 9.8) | – |
| CVE-2026-102490 | 2026-09-30 | Zammad | Zammad | High (CVSS 8.5) | 0.32% |
| CVE-2026-102489 | 2026-09-30 | Zammad | Zammad | High (CVSS 8.7) | 0.71% |
| CVE-2024-58387 | 2026-09-30 | Inspur | Haiyue HCM Cloud | High (CVSS 8.7) | – |
| CVE-2023-54403 | 2026-09-30 | Yonyou | U8 CRM | High (CVSS 8.7) | – |
| CVE-2023-54402 | 2026-09-30 | iDocView | iDocView | High (CVSS 8.7) | – |
| CVE-2026-85520 | 2026-09-29 | MyPresta | Google Merchant Center Feed | Critical (CVSS 9.3) | – |
| CVE-2025-62023 | 2026-09-29 | Cristián Lávaque | s2Member | Critical (CVSS 9.0) | 0.42% |
| CVE-2023-54400 | 2026-09-29 | Fumasoft | Fumeng Cloud | Critical (CVSS 9.3) | – |
| CVE-2015-20122 | 2026-09-29 | Yonyou | A6 OA | High (CVSS 8.7) | – |
| CVE-2026-86950 | 2026-09-28 | Apple | iOS and iPadOS, macOS | High (CVSS 8.8) | 0.81% |
| CVE-2026-49076 | 2026-09-28 | Crocoblock | JetEngine | Critical (CVSS 9.3) | 0.40% |
| CVE-2026-88772 | 2026-09-27 | Citrix NetScaler | ADC, Gateway | Critical (CVSS 9.5) | – |
| CVE-2026-88771 | 2026-09-27 | Citrix NetScaler | ADC, Gateway | Critical (CVSS 9.5) | – |
| CVE-2026-42608 | 2026-09-27 | Getgrav | grav | High (CVSS 8.8) | 0.52% |
| CVE-2026-65660 | 2026-09-24 | Microsoft | Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, … | High (CVSS 8.8) | 1.19% |
| CVE-2026-48842 | 2026-09-24 | Roundcube | Webmail | High (CVSS 8.1) | 0.89% |
| CVE-2026-87902 | 2026-09-23 | WordPress | WordPress | High (CVSS 8.1) | 0.42% |
| CVE-2026-67279 | 2026-09-23 | Mikrotik | RouterOS | Medium (CVSS 6.9) | 0.45% |
| CVE-2026-94127 | 2026-09-22 | F5 | BIG-IP | Critical (CVSS 9.3) | 1.39% |
| CVE-2026-93952 | 2026-09-22 | Arista Networks | VeloCloud Orchestrator (VCO) On-Prem | Critical (CVSS 9.5) | 0.42% |
| CVE-2026-93616 | 2026-09-22 | Checkpoint | Quantum Security Management | Critical (CVSS 9.8) | – |
| CVE-2026-85102 | 2026-09-22 | Checkpoint | Quantum Security Gateway | Critical (CVSS 9.8) | 0.33% |
| CVE-2026-79756 | 2026-09-22 | Nuclio | nuclio | High (CVSS 8.7) | 5.15% |
| CVE-2026-75949 | 2026-09-22 | Cmsjunkie.com | J-BusinessDirectory extension for Joomla | Critical (CVSS 10.0) | 0.31% |
| CVE-2026-66457 | 2026-09-22 | Pixelite | Events Manager | High (CVSS 7.1) | 0.19% |
| CVE-2026-56271 | 2026-09-22 | Flowise | Flowise | Critical (CVSS 9.3) | 0.66% |
| CVE-2026-54569 | 2026-09-22 | Senaite | senaite.core | Critical (CVSS 9.8) | 0.78% |
| CVE-2016-20080 | 2026-09-22 | Brandfolder | Brandfolder | Medium (CVSS 6.9) | 0.39% |
| CVE-2026-88062 | 2026-09-21 | Diegosouzapw | OmniRoute | Critical (CVSS 9.5) | 0.94% |
| CVE-2026-7273 | 2026-09-21 | Zyxel | GS1900-48HPv2 firmware, GS1900-8 firmware, … | High (CVSS 8.8) | 0.32% |
| CVE-2026-32996 | 2026-09-21 | Veeam | Backup and Replication | High (CVSS 7.3) | 0.15% |
| CVE-2026-27960 | 2026-09-21 | OpenCTI-Platform | opencti | Critical (CVSS 9.8) | 1.99% |
| CVE-2026-26980 | 2026-09-21 | TryGhost | Ghost | Critical (CVSS 9.4) | 70.21% |
| CVE-2024-52270 | 2026-09-21 | DropBox(HelloSign) | DropBox Sign | High (CVSS 8.2) | 0.19% |
| CVE-2021-30134 | 2026-09-21 | Php_curl_class_project, Ht_slider_range_for_amazon_affiliates_project, Qiwi, Teamleade, Ptwooplugins, Shopello_api_project | PHP Curl Class, HT Slider Range FOR Amazon Affiliates, … | Medium (CVSS 6.1) | 1.26% |
| CVE-2018-13980 | 2026-09-21 | Zeta-producer | Zeta Producer | Medium (CVSS 5.5) | 6.90% |
| CVE-2026-53266 | 2026-09-18 | Linux | Linux | High (CVSS 8.8) | 0.12% |
| CVE-2026-42796 | 2026-09-18 | Arelle | Arelle | Critical (CVSS 9.2) | 2.75% |
| CVE-2026-32882 | 2026-09-18 | Strukturag | libheif | High (CVSS 7.1) | 0.34% |
| CVE-2026-0769 | 2026-09-18 | Langflow | Langflow | Critical (CVSS 9.8) | 38.64% |
| CVE-2025-39964 | 2026-09-18 | Linux | Linux | High (CVSS 7.8) | 0.32% |
| CVE-2025-39682 | 2026-09-18 | Linux | Linux | Critical (CVSS 9.8) | 0.51% |
| CVE-2024-53900 | 2026-09-18 | Mongoosejs | Mongoose | Critical (CVSS 9.1) | 3.90% |
| CVE-2023-54399 | 2026-09-18 | Hongjing | e-HR | Critical (CVSS 9.3) | – |
| CVE-2023-46359 | 2026-09-18 | Hardy-barth | cph2 Echarge Firmware | Critical (CVSS 9.8) | 87.61% |
| CVE-2023-29827 | 2026-09-18 | Ejs | EJS | Critical (CVSS 9.8) | 5.55% |
| CVE-2021-48008 | 2026-09-18 | Chanjet Information Technology | CRM | High (CVSS 8.7) | – |
| CVE-2019-25776 | 2026-09-18 | Weaver Network | E-cology | High (CVSS 8.7) | – |
| CVE-2017-20284 | 2026-09-18 | Caucho Technology | Resin | High (CVSS 8.7) | – |
| CVE-2026-89013 | 2026-09-17 | Dolibarr | Dolibarr | High (CVSS 8.7) | 0.37% |
| CVE-2026-86538 | 2026-09-17 | Knowns-dev | knowns | High (CVSS 8.7) | 0.74% |
| CVE-2026-40242 | 2026-09-17 | Getarcaneapp | arcane | High (CVSS 7.2) | 0.62% |
| CVE-2026-32255 | 2026-09-17 | Kanbn | kan | High (CVSS 8.6) | 20.78% |
| CVE-2022-45362 | 2026-09-17 | Paytm | Paytm Payment Gateway | High (CVSS 7.2) | 41.76% |
| CVE-2022-25497 | 2026-09-17 | Cuppa CMS | Cuppacms | Medium (CVSS 5.3) | 3.64% |
| CVE-2021-24946 | 2026-09-17 | Webnus | Modern Events Calendar Lite | Critical (CVSS 9.8) | 72.80% |
| CVE-2016-15043 | 2026-09-17 | Websitez.com | WP Mobile Detector | Critical (CVSS 9.8) | 7.76% |
| CVE-2026-76460 | 2026-09-16 | Cisco | Cisco Identity Services Engine Software, Cisco ISE Passive Identity Connector, … | Critical (CVSS 10.0) | – |
| CVE-2026-58704 | 2026-09-16 | Android | High (CVSS 8.8) | 0.11% | |
| CVE-2026-5430 | 2026-09-16 | WSO2 | WSO2 Universal Gateway, WSO2 Traffic Manager, … | Critical (CVSS 10.0) | 0.32% |
| CVE-2026-54196 | 2026-09-16 | Jetmonsters | JetFormBuilder | Medium (CVSS 6.8) | 0.24% |
| CVE-2022-0434 | 2026-09-16 | a3rev | Page View Count | Critical (CVSS 9.8) | 14.78% |
| CVE-2022-0412 | 2026-09-16 | TemplateInvaders | TI WooCommerce Wishlist, TI WooCommerce Wishlist Pro | Critical (CVSS 9.8) | 74.00% |
| CVE-2019-1003000 | 2026-09-16 | Jenkins project | Script Security Plugin | High (CVSS 8.8) | 98.38% |
| CVE-2026-89026 | 2026-09-15 | Issabel | Issabel Framework | Critical (CVSS 9.3) | 0.52% |
| CVE-2026-87886 | 2026-09-15 | Acronis | Acronis Backup | High (CVSS 7.8) | – |
| CVE-2026-69255 | 2026-09-15 | FlowiseAI | Flowise | Critical (CVSS 9.2) | 0.60% |
| CVE-2026-39364 | 2026-09-15 | Vitejs | vite, vite-plus | High (CVSS 8.2) | 2.00% |
| CVE-2025-9603 | 2026-09-15 | Telesquare | TLR-2005KSH | Medium (CVSS 5.3) | 7.58% |
| CVE-2024-58385 | 2026-09-15 | Yonyou | U8 CRM | Critical (CVSS 9.3) | – |
| CVE-2023-54398 | 2026-09-15 | Yonyou | U8 Cloud | Critical (CVSS 9.3) | – |
| CVE-2017-7876 | 2026-09-15 | Qnap | QTS | Critical (CVSS 10.0) | 3.34% |
| CVE-2016-10760 | 2026-09-15 | Seowonintech | swr-300a Firmware, swr-300b Firmware, … | Critical (CVSS 9.8) | 3.23% |
| CVE-2026-76461 | 2026-09-14 | Cisco | Cisco Secure Email | Critical (CVSS 9.8) | – |
| CVE-2026-55786 | 2026-09-14 | Flyto2 | flyto-core | High (CVSS 8.4) | – |
| CVE-2026-51990 | 2026-09-14 | Tencent / Sogou | Sogou Input Method for Windows | High (CVSS 8.8) | – |
| CVE-2026-27540 | 2026-09-14 | Rymera Web | Woocommerce Wholesale Lead Capture | Critical (CVSS 9.0) | 1.73% |
| CVE-2026-23536 | 2026-09-14 | Red Hat | Red Hat OpenShift AI (RHOAI) | High (CVSS 7.5) | 1.91% |
| CVE-2024-8529 | 2026-09-14 | Thimpress | LearnPress – WordPress LMS Plugin | Critical (CVSS 10.0) | 11.83% |
| CVE-2024-24112 | 2026-09-14 | Exrick | Xmall | Critical (CVSS 9.8) | 3.35% |
| CVE-2022-32028 | 2026-09-14 | Car_rental_management_system_project | CAR Rental Management System | High (CVSS 7.2) | 5.06% |
| CVE-2022-32026 | 2026-09-14 | Car_rental_management_system_project | CAR Rental Management System | High (CVSS 7.2) | 5.31% |
| CVE-2022-32025 | 2026-09-14 | Car_rental_management_system_project | CAR Rental Management System | High (CVSS 7.2) | 4.56% |
| CVE-2022-32024 | 2026-09-14 | Car_rental_management_system_project | CAR Rental Management System | High (CVSS 7.2) | 4.56% |
| CVE-2022-30047 | 2026-09-14 | Mingsoft | Mcms | Critical (CVSS 9.8) | 1.44% |
| CVE-2022-27927 | 2026-09-14 | Microfinance_management_system_project | Microfinance Management System | Critical (CVSS 9.8) | 13.83% |
| CVE-2018-10736 | 2026-09-14 | Nagios | Nagios XI | High (CVSS 7.2) | 42.56% |
| CVE-2018-10735 | 2026-09-14 | Nagios | Nagios XI | High (CVSS 7.2) | 42.56% |
| CVE-2017-17731 | 2026-09-14 | Dedecms | Dedecms | Critical (CVSS 9.8) | 13.19% |
| CVE-2025-32969 | 2026-09-13 | Xwiki | xwiki-platform | Critical (CVSS 9.3) | 77.77% |
| CVE-2021-24827 | 2026-09-13 | Asgaros | Asgaros Forum | Critical (CVSS 9.8) | 12.56% |
| CVE-2026-85706 | 2026-09-11 | GitLab | GitLab | Critical (CVSS 10.0) | 1.15% |
| CVE-2025-29085 | 2026-09-11 | Vipshop | Saturn | Critical (CVSS 9.8) | 30.69% |
| CVE-2025-2636 | 2026-09-11 | Instawp | InstaWP Connect – 1-click WP Staging & Migration | High (CVSS 8.1) | 10.42% |
| CVE-2025-1661 | 2026-09-11 | realmag777 | HUSKY – Products Filter Professional for WooCommerce | Critical (CVSS 9.8) | 56.38% |
| CVE-2018-18084 | 2026-09-11 | Comsenz | Duomicms | Critical (CVSS 9.8) | 1.26% |
| CVE-2017-8917 | 2026-09-11 | Joomla | Joomla! | Critical (CVSS 9.8) | 99.83% |
| CVE-2026-86206 | 2026-09-10 | N-able | N-central | Medium (CVSS 6.9) | 0.68% |
| CVE-2026-86060 | 2026-09-10 | Mikrotik | RouterOS | Critical (CVSS 9.2) | 0.40% |
| CVE-2026-71362 | 2026-09-10 | Adobe | Adobe Commerce, Adobe Commerce B2B, Magento Open Source | Critical (CVSS 9.1) | 25.14% |
| CVE-2026-67277 | 2026-09-10 | Mikrotik | RouterOS | High (CVSS 8.8) | 0.43% |
| CVE-2026-67276 | 2026-09-10 | Mikrotik | RouterOS | Critical (CVSS 9.2) | 0.24% |
| CVE-2026-45695 | 2026-09-10 | Kopia | kopia | Critical (CVSS 9.8) | 1.61% |
| CVE-2026-42031 | 2026-09-10 | Ckan | ckan | High (CVSS 8.3) | 1.82% |
| CVE-2026-42018 | 2026-09-10 | Jfrog | artifactory | High (CVSS 7.5) | 0.35% |
| CVE-2026-42016 | 2026-09-10 | Jfrog | artifactory | High (CVSS 8.1) | 0.27% |
| CVE-2024-5276 | 2026-09-10 | Fortra | FileCatalyst Workflow | Critical (CVSS 9.8) | 90.07% |
| CVE-2024-50340 | 2026-09-10 | Symfony | symfony | High (CVSS 7.3) | 64.43% |
| CVE-2024-36412 | 2026-09-10 | Salesagility | SuiteCRM | Critical (CVSS 10.0) | 5.69% |
| CVE-2024-31982 | 2026-09-10 | Xwiki | xwiki-platform | Critical (CVSS 10.0) | 34.28% |
| CVE-2022-1057 | 2026-09-10 | Varktech | Pricing Deals for WooCommerce | Critical (CVSS 9.8) | 8.11% |
| CVE-2022-0169 | 2026-09-10 | 10Web | Photo Gallery | – | 74.61% |
| CVE-2019-10232 | 2026-09-10 | Teclib-edition | Gestionnaire Libre DE Parc Informatique | Critical (CVSS 9.8) | 23.21% |
| CVE-2026-87827 | 2026-09-09 | KGUARD | KGUARD_firmware | Critical (CVSS 10.0) | – |
| CVE-2026-87491 | 2026-09-09 | Chrome | High (CVSS 8.8) | 0.29% | |
| CVE-2026-86207 | 2026-09-09 | N-able | N-central | High (CVSS 7.7) | 0.73% |
| CVE-2026-84869 | 2026-09-09 | ConnectWise | ScreenConnect | Critical (CVSS 9.9) | 0.38% |
| CVE-2026-20079 | 2026-09-09 | Cisco | Cisco Secure Firewall Management Center (FMC) | Critical (CVSS 10.0) | 35.95% |
| CVE-2024-2851 | 2026-09-09 | Tenda | AC15 | Medium (CVSS 6.3) | 4.01% |
| GHSA-6V53-HR58-556R | 2026-09-08 | – | – | Critical (CVSS 9.8) | – |
| CVE-2026-85880 | 2026-09-08 | Microsoft | Windows 10 Version 1607, Windows 10 Version 1809, … | High (CVSS 7.8) | – |
| CVE-2026-81963 | 2026-09-08 | Microsoft | Windows 11 version 23H2, Windows 11 Version 23H2, … | High (CVSS 7.8) | – |
| CVE-2025-25249 | 2026-09-08 | Fortinet | FortiSwitchManager, FortiOS | High (CVSS 8.1) | 0.76% |
| CVE-2023-37462 | 2026-09-08 | Xwiki | xwiki-platform | Critical (CVSS 9.9) | 91.49% |
| CVE-2018-17254 | 2026-09-08 | – | n/a | Critical (CVSS 9.8) | 82.98% |
| CVE-2025-60687 | 2026-09-07 | ToToLink | LR1200GB Router | Medium (CVSS 6.5) | – |
| CVE-2025-6068 | 2026-09-07 | Bradvin | FooGallery – Responsive Photo Gallery, Image Viewer, … | Medium (CVSS 6.4) | – |
| CVE-2025-14208 | 2026-09-07 | D-Link | DIR-823X | Medium (CVSS 5.3) | – |
| CVE-2023-37569 | 2026-09-07 | ESDS | Emagic Data Center Management Suite | High (CVSS 8.8) | – |
| CVE-2026-86218 | 2026-09-06 | N-able | N-central | Critical (CVSS 10.0) | 0.41% |
| CVE-2026-75650 | 2026-09-05 | Adobe | Adobe Commerce, Adobe Commerce B2B, Magento Open Source | Critical (CVSS 10.0) | 2.15% |
| CVE-2025-60698 | 2026-09-05 | D-Link | DIR-882 Router | High (CVSS 7.3) | 3.93% |
| CVE-2026-85046 | 2026-09-04 | Chrome | High (CVSS 8.8) | 0.46% | |
| CVE-2026-58457 | 2026-09-04 | Shenzhen Aitemi E Commerce | M300 Wi-Fi Repeater | Critical (CVSS 9.3) | 2.94% |
| CVE-2026-14894 | 2026-09-04 | WebRehab | Super Forms – Drag & Drop Form Builder | Critical (CVSS 9.8) | 5.27% |
| CVE-2019-10655 | 2026-09-04 | Grandstream | GAC2500 | Critical (CVSS 9.8) | 15.47% |
| CVE-2026-19490 | 2026-09-03 | NetScaler | ADC, Gateway | Critical (CVSS 9.3) | 3.37% |
| CVE-2014-3704 | 2026-09-03 | Drupal | Drupal | High (CVSS 7.5) | 99.97% |
| CVE-2026-59822 | 2026-09-02 | BerriAI | litellm | High (CVSS 8.8) | 0.52% |
| CVE-2026-49869 | 2026-09-02 | Kestra-io | kestra | Critical (CVSS 10.0) | 0.99% |
| CVE-2026-48710 | 2026-09-02 | Kludex | starlette | Medium (CVSS 6.5) | 2.10% |
| CVE-2026-32475 | 2026-09-02 | Elementor | Elementor Pro | Critical (CVSS 9.0) | 2.37% |
| CVE-2026-9586 | 2026-09-01 | Sangoma | Switchvox SMB Edition | Critical (CVSS 9.3) | 0.43% |
| CVE-2026-83549 | 2026-09-01 | SonicWall | SMA1000 | High (CVSS 7.8) | 0.92% |
| CVE-2026-83548 | 2026-09-01 | SonicWall | SMA1000 | Critical (CVSS 10.0) | 0.27% |
| CVE-2026-82329 | 2026-09-01 | Jfrog | artifactory | Critical (CVSS 9.8) | 0.38% |
| CVE-2026-78141 | 2026-09-01 | Tenda | CH22 | Medium (CVSS 5.3) | 1.07% |
| CVE-2026-5153 | 2026-09-01 | Tenda | CH22 | Medium (CVSS 5.3) | 3.30% |
| CVE-2026-41948 | 2026-09-01 | Langgenius | dify | Critical (CVSS 9.3) | 7.39% |
| CVE-2026-1547 | 2026-09-01 | Totolink | A7000R | Medium (CVSS 5.3) | 2.82% |
| CVE-2025-60702 | 2026-09-01 | TOTOLINK | A950RG Router | Medium (CVSS 6.5) | 2.54% |
| CVE-2025-40553 | 2026-09-01 | SolarWinds | Web Help Desk | Critical (CVSS 9.8) | 60.39% |
| CVE-2024-0250 | 2026-09-01 | Analytics Insights | Analytics Insights for Google Analytics 4 | Medium (CVSS 6.1) | 1.25% |
| CVE-2023-54391 | 2026-09-01 | Proxmox Server Solutions | Proxmox Virtual Environment (VE) | Critical (CVSS 9.3) | – |
| CVE-2023-39470 | 2026-09-01 | PaperCut | NG | High (CVSS 7.2) | 1.76% |
More KEV entries from the Previdian Catalog.
Top 10 Weaknesses of the Month
Memory safety keeps the top three places for the third month running, and the gap is widening: heap-based buffer overflow (CWE-122) approaches 10,000 occurrences, almost double August’s figure, ahead of use-after-free (CWE-416, about 5,900) and out-of-bounds read (CWE-125, about 5,200). Cross-site scripting (CWE-79) stays fourth, missing authorization (CWE-862) fifth, and integer overflow (CWE-190) and stack-based buffer overflow (CWE-121) both enter the top ten – which makes five memory-corruption classes out of ten.
Insights from Contributors
Two community comments were published this month:
- A contradictory timeline – a contributor revisits the Microsoft Entra ID deserialization RCE CVE-2026-69836 (CVSS 10.0), reported in August as a CISA entry visible in no other catalog. The comment documents the back-and-forth around its “exploited” flag, which Microsoft withdrew, and the resulting absence from the CISA KEV – the entry no longer appears in any tracked catalog today. Its wider point is about server-side patches on multi-tenant cloud services: with no binary to download and no version to check, defenders can only trust the vendor and shift from patching to detection.
- LG TV discovery traffic and CVE-2026-13230 – a possible interaction with CVE-2026-9770? – an annotation on the TP-Link Kasa EC70/EC71 hard-coded private key CVE-2026-9770, noting that LG TVs broadcast discovery packets on UDP/9999 every 25 seconds, the same port used by the Kasa discovery mechanism of CVE-2026-13230, which leaks the camera’s GPS coordinates without authentication. The suggested interaction is tagged
vulnerability:exploitability=theoretical.
Contributors also curated advisories and research into five bundles during September:
- Ubuntu 24.04 LTS NVIDIA Kernel Update USN-8760-1 Security Issues (550 CVEs) – the month’s largest bundle by far, grouping every kernel CVE fixed in a single Ubuntu update for NVIDIA systems; a reminder of what the kernel’s CVE volume looks like once it reaches a distribution.
- Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 to CVE-2026-88778 (8 CVEs) – the 27 September bulletin, bundled the day it came out, covering the two KEV-listed RCEs and six further issues in the same releases.
- GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends (6 CVEs and advisories) – the unauthenticated formatter upload CVE-2026-63219 chained with the unsafe Saxon XSLT configuration CVE-2026-58400, bundled on 3 September alongside two earlier related CVEs; both GeoNetwork CVEs reached the ENISA feed the day before.
- Active exploitation of Cisco Secure Firewall Management Center vulnerabilities (2 CVEs) – Cisco Talos’s report on the FMC authentication bypass CVE-2026-20079 and the static-credential issue CVE-2026-20316, bundled on 10 September, the day after CISA listed the former.
- Critical vulnerabilities in Checkpoint VPN Firewall (2 CVEs) – the VPN certificate validation RCE CVE-2026-85102 together with the ASN.1 decoding heap overflow CVE-2026-85103, bundled twelve days before the former entered the CISA catalog.
Thank you
Thank you to all the contributors and our diverse sources!
If you want to contribute to the next report, you can create your account.
Feedback and Support
If you have suggestions, please feel free to open a ticket on our GitHub repository. Your feedback is invaluable to us!
https://github.com/vulnerability-lookup/vulnerability-lookup/issues/
Funding

The main objective of Federated European Team for Threat Analysis (FETTA) is improvement of Cyber Threat Intelligence (CTI) products available to the public and private sector in Poland, Luxembourg, and the European Union as a whole.
Developing actionable CTI products (reports, indicators, etc) is a complex task and requires an in-depth understanding of the threat landscape and the ability to analyse and interpret large amounts of data. Many SOCs and CSIRTs build their capabilities in this area independently, leading to a fragmented approach and duplication of work.
The Computer Incident Response Center Luxembourg (CIRCL) is a government-driven initiative designed to provide a systematic response facility to computer security threats and incidents. The organization brings to the table its extensive experience in cybersecurity incident management, threat intelligence, and proactive response strategies. With a strong background in developing innovative open source cybersecurity tools and solutions, CIRCL’s contribution to the FETTA project is instrumental in achieving enhanced collaboration and intelligence sharing across Europe.
AIPITCH (AI-Powered Innovative Toolkit for Cybersecurity Hubs) is a co-funded EU project supported by the European Cybersecurity Competence Centre (ECCC) under the DIGITAL-ECCC-2024-DEPLOY-CYBER-06-ENABLINGTECH program and CIRCL.
The VLAI severity levels used throughout this report are produced by models developed as part of AIPITCH.



