Vulnerability Report - September 2026

All vulnerability reports

Introduction

This vulnerability report has been generated with the help of AI, using the VulnMCP tooling on top of Vulnerability-Lookup, with contributions from the platform’s community.

It highlights the most frequently sighted vulnerabilities for September 2026, based on data aggregated from Vulnerability-Lookup, the CISA Known Exploited Vulnerabilities catalog, the CIRCL KEV catalog, the ENISA EUVD / EU CSIRTs Network feed, honeypot observations from The Shadowserver Foundation, the Previdian catalog (formerly known as KEVIntel – same catalog, new name), and contributor comments and bundles. These five KEV catalogs are federated through the GCVE initiative: each one is identified by the UUID of the Global Naming Authority (GNA) that publishes it, and exchanged between instances following the GCVE-BCP-07 specification – which is what makes the catalog coverage comparison further down possible. Sightings come from MISP, Exploit-DB, Bluesky, Mastodon, Telegram, GitHub Gists, Nuclei, SPLOITUS, Metasploit, and more. For further details, please visit this page.

September was the month of the network edge. Citrix NetScaler, Check Point, F5 BIG-IP, Cisco (four different products), Fortinet, SonicWall, MikroTik, Zyxel and Arista all had exploited vulnerabilities enter the CISA catalog, and the four vulnerabilities that every European catalog agreed on – two NetScaler issues, the Check Point VPN certificate flaw and the F5 BIG-IP APM heap overflow – are all unauthenticated remote code execution on security appliances. The second thread is exploitation reports arriving from more directions than before: CERT.PL’s “MikroTrick” research reached the ENISA feed five days before CISA listed it, NCSC-NL flagged WordPress core and two Zammad zero-days, and CIRCL confirmed seven exploitations including a ransomware case. The CVE Program set another monthly record at nearly 15,000 CVEs, and the KEV catalogs collectively flagged 166 vulnerabilities, up from 102 in August.

The Month at a Glance

14,959 CVEs were published in September 2026 (from the CVE List v5 source alone), up from 12,315 in August – a 21.5% month-over-month increase and, once again, the highest monthly volume ever recorded. Vulnerability-Lookup also ingested 14,128 GitHub security advisories and 186 PySec advisories over the same period.

Area chart showing the evolution of published CVEs per month in 2026, rising from about 4,300 in January to a peak of nearly 15,000 in September

Evolution of published CVEs in 2026 (CVE Program source), as shown on the Vulnerability-Lookup dashboard. The October data point only covers the first day of the month.

Vulnerability-Lookup collected 43,109 sightings across 15,296 distinct vulnerabilities during September 2026, up from 33,732 in August (+27.8%). The breakdown:

Sighting typeCountDistinct vulnerabilities
Seen32,98114,680
Published proof of concept6,4823,736
Exploited3,589930
Confirmed5757

The August figures used for comparison are those returned by the API today (the August report quoted higher totals at the time of publication, before the sighting data was consolidated). On that basis every category except one grew: “seen” mentions rose from 25,643 to 32,981 (+29%), published proof-of-concept sightings from 4,819 to 6,482 (+35%), and exploitation-typed sightings from 3,204 to 3,589 (+12%), spread over 930 distinct vulnerabilities against 883 in August. The exception is confirmed sightings, which fell from 66 to 57 – each one on a different vulnerability, so the confirmed set is 57 distinct issues, among them the F5 BIG-IP APM RCE, the WordPress core file inclusion and the GitLab path traversal. No “patched” sightings were recorded.

The daily breakdown is dominated by 1 September, the busiest day of the month with 5,114 sightings, of which 4,979 are “seen”: a bulk batch of Telegram-sourced mentions covering 3,039 distinct vulnerabilities, led by Log4Shell, the MSHTML CVE-2021-40444, PrintNightmare and Confluence CVE-2022-26134 – a catalogue of 2021-era classics rather than new activity. The proof-of-concept peak comes two days later, on 3 September (911), spread thinly over 595 vulnerabilities. After that the “seen” band follows the disclosure calendar: 8–9 September (Patch Tuesday, the Windows ALPC and Update Stack privilege escalations, both Chrome V8 issues, N-central and Adobe Commerce), 15 September (the Cisco Secure Email Gateway SQL injection), 23 September (F5 BIG-IP APM, WordPress core and the two Check Point issues) and 29 September (the NetScaler pair and the Apple CoreGraphics zero-day). Exploitation-typed sightings peak on 10 and 19 September (222 and 212). The quietest stretch is the weekend of 20–21 September, under 600 per day.

01,0002,0003,0004,0005,0006,0001471013161922252830seenpublished proof of conceptexploitedconfirmed
Daily sightings collected by Vulnerability-Lookup in September 2026, by sighting type. The 1 September bar is a bulk batch of Telegram-sourced mentions of older vulnerabilities; the later "seen" peaks follow Patch Tuesday (8--9 September) and the Cisco, F5/Check Point/WordPress and NetScaler/Apple disclosure days.

In the exploitation-typed sightings, Log4Shell (CVE-2021-44228, 74 exploitation reports) remains the single most reported vulnerability for yet another month. It is followed by a relative newcomer, the NetScaler SAML IdP memory overread CVE-2026-3055 (44), listed by CISA at the end of March and still being actively reported, then by the Cisco IOS XE web UI privilege escalation CVE-2023-20198 (37), the cPanel/WHM authentication bypass CVE-2026-41940 (37) and Confluence CVE-2022-26134 (35). Proof-of-concept activity again concentrated on the Linux kernel rtmutex flaw CVE-2026-43499 (59, second month at the top), the WordPress core page-template file inclusion CVE-2026-87902 (45), the cPanel bypass (34) and an Android Contacts Provider SQL injection, CVE-2026-28576 (33), which no tracked catalog lists.

Top 10 Vendors of the Month

Linux keeps the top of the vendor ranking for a second month, now with close to 40% of the month’s attributed CVEs – the kernel CVE flood shows no sign of slowing – ahead of Microsoft, Google and Oracle. Dell enters the top ten, and the “unknown” slice (records without a usable vendor field) is large enough to rank fifth.

Top 10 Vendors of the Month

Top 10 Assigners of the Month

The kernel CNA leads the assigners, followed by VulnCheck and GitHub’s CNA, with Microsoft, VulDB, Oracle and WPScan behind them.

Top 10 Assigners of the Month

Top 10 Credits of the Month

WPScan stays first with around 550 credited vulnerabilities, but the VulDB CNA Team has closed most of the gap at roughly 510. A single researcher, George Chen, takes third place with more than 200 credits, well ahead of Mozilla, Patchstack’s bug bounty program, HPE Networking’s internal research team, VulnCheck and Wordfence PRISM.

Top 10 Credits of the Month

The complete list of credits is available on Vulnerability-Lookup.

Top 10 Vulnerabilities of the Month

VulnerabilitySighting CountVendorProductVLAI Severity
CVE-2026-87902247WordPressCore (page templates)Critical (confidence: 0.6985)
CVE-2026-85706246GitLabGitLab CE/EEHigh (confidence: 0.7211)
CVE-2026-88771217CitrixNetScaler ADC / GatewayCritical (confidence: 0.9895)
CVE-2021-44228196ApacheLog4j2High (confidence: 0.7501)
CVE-2026-88772191CitrixNetScaler ADC / GatewayCritical (confidence: 0.9889)
CVE-2026-85046162GoogleChrome (V8)High (confidence: 0.9883)
CVE-2026-94127143F5BIG-IP APMCritical (confidence: 0.9345)
CVE-2026-41940131WebProscPanel & WHMCritical (confidence: 0.9793)
CVE-2026-76461117CiscoSecure Email GatewayCritical (confidence: 0.9582)
CVE-2026-43499113LinuxKernel (rtmutex)High (confidence: 0.9738)

Two vulnerabilities share the top of the list, one sighting apart. The WordPress core remote file inclusion CVE-2026-87902, disclosed on 22 September, lets an unauthenticated attacker point page-template resolution at any readable .php file on the server; NCSC-NL reported active abuse the next day and CISA listed it on 25 September. It is followed by the GitLab repository commits API path traversal CVE-2026-85706, an unauthenticated arbitrary file read disclosed in mid-September and listed by CISA on the 11th – a second GitLab entry in as many months after August’s GraphQL code injection. The two NetScaler issues of 27 September take third and fifth place in just four days of sightings: the improper input validation RCE CVE-2026-88771 and the memory overflow CVE-2026-88772, both exploited before the bulletin was out and both entered into four catalogs within 24 hours. Log4Shell, in fourth place, is the only pre-2026 entry. The rest of the list is a tour of September’s CISA additions: the Chrome V8 type confusion CVE-2026-85046 (the first of two V8 entries this month), the F5 BIG-IP APM OAuth heap overflow CVE-2026-94127, the cPanel bypass that has sat in the top ten since May, the Cisco Secure Email Gateway SQL injection CVE-2026-76461 – root command execution through a crafted e-mail – and the Linux kernel rtmutex issue, which ties for tenth place with the Adobe Commerce template injection CVE-2026-75650 and the JFrog Artifactory authentication bypass CVE-2026-82329, all at 113 sightings.

Known Exploited Vulnerabilities

New entries were added to the tracked Known Exploited Vulnerabilities catalogs during September. The five catalogs are complementary rather than redundant: CISA is the reference set, CIRCL and the ENISA / EU CSIRTs Network feed add European confirmations, Shadowserver’s honeypots show what is actually being attacked on the wire, and Previdian aggregates public exploitation reports at higher volume and often earlier – each of the last two surfacing vulnerabilities no other catalog lists.

A total of 166 distinct vulnerabilities entered at least one tracked catalog this month, against 102 in August: 43 were added by CISA, 7 by CIRCL, 19 were reported through the ENISA / EU CSIRTs Network feed, 16 were observed for the first time by Shadowserver’s honeypots and 156 were added by Previdian. Every catalog grew except Shadowserver, whose feed stopped delivering new observations after 7 September (see below), so its figure only covers the first week.

Stacked bar chart of published CVEs per publication year with the exploited share highlighted, peaking at 17.68% for 2025 and 8.43% for 2026 so far

The exploited CVE ratio per publication year: share of CVEs with at least one exploitation or proof-of-concept sighting over all published CVEs of that year. Recent years are undercounted, as sightings accumulate over time.

Stacked bar chart of published CVEs per month of 2026 with the exploited share highlighted, from 10.98% in January and 20.78% in April down to 4.55% in September

The same ratio per publication month of 2026. September’s 4.55% is the lowest full month of the year, mechanically: the record volume of new CVEs has not yet had time to accumulate exploitation sightings, whereas April’s 20.78% reflects five months of catch-up.

The month’s story is the security appliance. Citrix NetScaler entered the CISA catalog three times: the authentication bypass CVE-2026-19490 on 9 September (the companion of the bulletin a contributor bundled in August, and flagged by Previdian six days earlier), then CVE-2026-88771 and CVE-2026-88772 on Saturday 27 September, the same day Citrix published its bulletin and the ENISA feed, Previdian and – the next day – CIRCL picked them up. Check Point contributed a pair on 22 September: the VPN certificate validation RCE CVE-2026-85102, which reaches any Quantum gateway with site-to-site or remote-access VPN, and the management server path traversal CVE-2026-93616. F5 BIG-IP APM followed the same day with the OAuth authorization-server heap overflow CVE-2026-94127, which CIRCL confirmed on 23 September. Cisco had four distinct products listed: the Secure Firewall Management Center authentication bypass CVE-2026-20079, tagged as ransomware-exploited with confirmed EU victims in the ENISA feed, the Secure Email Gateway SQL injection, the ISE API authentication bypass CVE-2026-76460 and, on the last day of the month, the Catalyst SD-WAN Manager admin-session bypass CVE-2026-76504. Fortinet (FortiOS heap overflow CVE-2025-25249), SonicWall (two SMA1000 issues), Arista VeloCloud Orchestrator, Zyxel GS1900 switches and Palo Alto (the GlobalProtect bypass CVE-2026-0257, which CIRCL tied to a ransomware incident on 1 September) complete the picture. Across the month, more than a third of CISA’s additions concern a firewall, VPN, load balancer or network-management product.

MikroTik RouterOS deserves its own paragraph. CERT.PL’s “MikroTrick” research produced four SSH-related CVEs, three of which the Polish CSIRT reported to the ENISA feed on 5 September: the policy-mask privilege escalation CVE-2026-86060, the btest kernel memory disclosure CVE-2026-67277 and the RSA exponent-one user impersonation CVE-2026-67276. CISA listed the first two on 10 September – five days after the ENISA feed – and added the pre-authentication rekey bypass CVE-2026-67279 on 25 September, noting that it chains with the privilege escalation for a fully unauthenticated compromise. The impersonation flaw remains visible only through ENISA and Previdian.

On the developer and operations tooling side, JFrog Artifactory had three CISA entries (the default-configuration administrative bypass CVE-2026-82329 on 2 September, then a token-scope and an anonymous-token issue on the 11th), N-able N-central returned for a third month with the pre-authentication RCE CVE-2026-86218, and ConnectWise ScreenConnect, Acronis’s cPanel backup plugin, WSO2 (a JWT algorithm-mismatch account takeover rated CVSS 10.0) and Kestra joined them. The AI stack is quieter than in August but not absent: CISA listed the LiteLLM MCP authentication bypass CVE-2026-59822 and the Starlette host-header path confusion it chains with, Previdian added Langflow (CVE-2026-0769, 38.6% EPSS), two Flowise issues, Dify, Nuclio, Red Hat OpenShift AI’s Feast component and two agent frameworks (OmniRoute, Flyto2) that expose command execution over MCP.

Client-side entries were few but notable: two Chrome V8 issues (CVE-2026-85046 on 4 September, CVE-2026-87491 on the 9th), the Apple CoreGraphics out-of-bounds write CVE-2026-86950, which Apple says was used “in an extremely sophisticated attack against specific targeted individuals”, a Google Pixel modem permission bypass, the two Windows local privilege escalations of Patch Tuesday, and three Linux kernel entries on 18 September (the AF_ALG race, the TLS zero-length record issue and the ebtables SNAT out-of-bounds write) – continuing the kernel-exploit pattern noticed in August. The ENISA feed also brought two issues no other reference catalog lists: the GeoNetwork unauthenticated RCE chain (CVE-2026-58400, CVE-2026-63219) affecting government geoportal back-ends, and two Zammad zero-days reported by NCSC-NL on 30 September.

Across the month’s KEV additions, the dominant weakness patterns were missing or improper authentication (CWE-287/288/306/863: NetScaler, Cisco FMC, ISE and SD-WAN Manager, Artifactory, WSO2, Kestra, LiteLLM, Adobe Commerce, SonicWall), memory corruption in appliances and clients (CWE-119/122/787: NetScaler, F5, Fortinet, Zyxel, Chrome, Apple, Windows ALPC), path traversal and file inclusion (CWE-22/98: Check Point, GitLab, WordPress, WSO2) and, for the Previdian-only set, SQL injection in older web applications.

Catalog coverage

166 distinct vulnerabilities entered at least one of the tracked KEV catalogs during September. The matrix below shows, for each of them, which catalogs cover it (as of publication) – built with the KEV catalog coverage feature of Vulnerability-Lookup. Previdian is by far the widest net with 163 of the 166, ahead of CISA (49, including entries it had listed before September), ENISA (19), Shadowserver (18) and CIRCL (7). Five vulnerabilities of the month are present in four catalogs at once: the two NetScaler issues (CVE-2026-88771, CVE-2026-88772), the Check Point VPN RCE CVE-2026-85102 and the F5 BIG-IP APM overflow CVE-2026-94127 – all in CISA, CIRCL, ENISA and Previdian – plus Log4Shell CVE-2021-44228, which CIRCL added on 3 September and which was already in CISA, Shadowserver and Previdian. Thirteen more are in three catalogs, among them the WordPress core file inclusion, the SharePoint code injection, the three MikroTik entries, both Cisco FMC issues and the Sangoma Switchvox SQL injection CVE-2026-9586 – the only entry of the month that CISA, Previdian and Shadowserver’s honeypots all saw.

At the other end, 99 entries are visible through a single catalog: 96 only via Previdian (the AI-tooling cluster, a large batch of Chinese enterprise software and WordPress plugin issues, XWiki, Ghost, OpenCTI and a long tail of high-EPSS legacy flaws), 2 only via ENISA (the GeoNetwork pair) and 1 only via CIRCL – GCVE-1-2026-20026, an unauthenticated remote code execution in older firmware, discovered by CIRCL and published under its own GCVE numbering. For the first time, no entry is unique to CISA: every one of its 43 additions is also in Previdian.

VulnerabilityFirst addedCISACIRCLENISAPrevidianShadowserver
CVE-2026-765042026-09-30✓✓
CVE-2026-1024902026-09-30✓✓
CVE-2026-1024892026-09-30✓✓
CVE-2024-583872026-09-30✓
CVE-2023-544032026-09-30✓
CVE-2023-544022026-09-30✓
CVE-2026-855202026-09-29✓
CVE-2025-620232026-09-29✓
CVE-2023-544002026-09-29✓
CVE-2015-201222026-09-29✓
CVE-2026-869502026-09-28✓✓
CVE-2026-490762026-09-28✓
CVE-2026-887722026-09-27✓✓✓✓
CVE-2026-887712026-09-27✓✓✓✓
CVE-2026-426082026-09-27✓
CVE-2026-656602026-09-24✓✓✓
CVE-2026-488422026-09-24✓
CVE-2026-879022026-09-23✓✓✓
CVE-2026-672792026-09-23✓✓✓
CVE-2026-941272026-09-22✓✓✓✓
CVE-2026-939522026-09-22✓✓
CVE-2026-936162026-09-22✓✓✓
CVE-2026-851022026-09-22✓✓✓✓
CVE-2026-797562026-09-22✓
CVE-2026-759492026-09-22✓
CVE-2026-664572026-09-22✓
CVE-2026-562712026-09-22✓
CVE-2026-545692026-09-22✓
CVE-2016-200802026-09-22✓
CVE-2026-880622026-09-21✓
CVE-2026-72732026-09-21✓✓
CVE-2026-630302026-09-21✓✓✓
CVE-2026-601372026-09-21✓✓✓
CVE-2026-329962026-09-21✓
CVE-2026-279602026-09-21✓
CVE-2026-269802026-09-21✓
CVE-2024-522702026-09-21✓
CVE-2021-301342026-09-21✓
CVE-2018-139802026-09-21✓
CVE-2026-532662026-09-18✓✓
CVE-2026-427962026-09-18✓
CVE-2026-328822026-09-18✓
CVE-2026-07692026-09-18✓
CVE-2025-399642026-09-18✓✓
CVE-2025-396822026-09-18✓✓
CVE-2024-539002026-09-18✓
CVE-2023-543992026-09-18✓
CVE-2023-463592026-09-18✓
CVE-2023-298272026-09-18✓
CVE-2021-480082026-09-18✓
CVE-2019-257762026-09-18✓
CVE-2017-202842026-09-18✓
CVE-2026-890132026-09-17✓
CVE-2026-865382026-09-17✓
CVE-2026-402422026-09-17✓
CVE-2026-322552026-09-17✓
CVE-2022-453622026-09-17✓
CVE-2022-254972026-09-17✓
CVE-2021-249462026-09-17✓
CVE-2016-150432026-09-17✓
CVE-2026-764602026-09-16✓✓
CVE-2026-587042026-09-16✓✓
CVE-2026-54302026-09-16✓✓
CVE-2026-541962026-09-16✓
CVE-2022-04342026-09-16✓
CVE-2022-04122026-09-16✓
CVE-2019-10030002026-09-16✓
CVE-2026-890262026-09-15✓
CVE-2026-878862026-09-15✓✓
CVE-2026-692552026-09-15✓
CVE-2026-393642026-09-15✓
CVE-2025-96032026-09-15✓
CVE-2024-583852026-09-15✓
CVE-2023-543982026-09-15✓
CVE-2017-78762026-09-15✓✓
CVE-2016-107602026-09-15✓
CVE-2026-764612026-09-14✓✓
CVE-2026-557862026-09-14✓
CVE-2026-519902026-09-14✓
CVE-2026-275402026-09-14✓
CVE-2026-235362026-09-14✓
CVE-2024-85292026-09-14✓
CVE-2024-241122026-09-14✓
CVE-2022-320282026-09-14✓
CVE-2022-320262026-09-14✓
CVE-2022-320252026-09-14✓
CVE-2022-320242026-09-14✓
CVE-2022-300472026-09-14✓
CVE-2022-279272026-09-14✓
CVE-2018-107362026-09-14✓
CVE-2018-107352026-09-14✓
CVE-2017-177312026-09-14✓
CVE-2025-329692026-09-13✓
CVE-2021-248272026-09-13✓
CVE-2026-857062026-09-11✓✓
CVE-2025-290852026-09-11✓
CVE-2025-26362026-09-11✓
CVE-2025-16612026-09-11✓
CVE-2018-180842026-09-11✓
CVE-2017-89172026-09-11✓
CVE-2026-862062026-09-10✓
CVE-2026-713622026-09-10✓✓
CVE-2026-456952026-09-10✓
CVE-2026-420312026-09-10✓
CVE-2026-420182026-09-10✓✓
CVE-2026-420162026-09-10✓✓
CVE-2024-52762026-09-10✓
CVE-2024-503402026-09-10✓
CVE-2024-364122026-09-10✓
CVE-2024-319822026-09-10✓
CVE-2022-10572026-09-10✓
CVE-2022-01692026-09-10✓
CVE-2019-102322026-09-10✓
GCVE-1-2026-200262026-09-09✓
CVE-2026-878272026-09-09✓
CVE-2026-874912026-09-09✓✓
CVE-2026-862072026-09-09✓
CVE-2026-848692026-09-09✓✓
CVE-2026-203162026-09-09✓✓✓
CVE-2026-200792026-09-09✓✓✓
CVE-2024-28512026-09-09✓
GHSA-6V53-HR58-556R2026-09-08✓
CVE-2026-858802026-09-08✓✓
CVE-2026-819632026-09-08✓✓
CVE-2025-252492026-09-08✓✓
CVE-2023-374622026-09-08✓
CVE-2018-172542026-09-08✓
CVE-2025-606872026-09-07✓✓
CVE-2025-60682026-09-07✓✓
CVE-2025-142082026-09-07✓✓
CVE-2023-375692026-09-07✓✓
CVE-2026-862182026-09-06✓✓
CVE-2025-40082026-09-06✓✓✓
CVE-2026-860602026-09-05✓✓✓
CVE-2026-756502026-09-05✓✓
CVE-2026-672772026-09-05✓✓✓
CVE-2026-672762026-09-05✓✓
CVE-2025-606982026-09-05✓✓
CVE-2026-850462026-09-04✓✓
CVE-2026-584572026-09-04✓✓
CVE-2026-148942026-09-04✓
CVE-2019-106552026-09-04✓✓
CVE-2026-194902026-09-03✓✓
CVE-2021-442282026-09-03✓✓✓✓
CVE-2014-37042026-09-03✓
CVE-2026-632192026-09-02✓
CVE-2026-598222026-09-02✓✓
CVE-2026-584002026-09-02✓
CVE-2026-498692026-09-02✓✓
CVE-2026-487102026-09-02✓✓
CVE-2026-324752026-09-02✓
CVE-2026-95862026-09-01✓✓✓
CVE-2026-835492026-09-01✓✓
CVE-2026-835482026-09-01✓✓
CVE-2026-823292026-09-01✓✓
CVE-2026-781412026-09-01✓✓
CVE-2026-51532026-09-01✓✓
CVE-2026-419482026-09-01✓
CVE-2026-15472026-09-01✓✓
CVE-2026-02572026-09-01✓✓✓
CVE-2025-607022026-09-01✓✓
CVE-2025-405532026-09-01✓
CVE-2024-02502026-09-01✓✓
CVE-2023-543912026-09-01✓
CVE-2023-394702026-09-01✓✓
CVE-2016-200972026-09-01✓✓

CISA

The CISA KEV catalog added 43 entries in September, well above August’s 31 and the busiest month of the year by a wide margin. None of them carries a known ransomware campaign use flag, even though the ENISA feed tags the Cisco FMC pair as ransomware-exploited and CIRCL tied the PAN-OS GlobalProtect bypass to a ransomware case.

CVE IDDate AddedVendorProductVLAI Severity
CVE-2026-765042026-09-30CiscoCatalyst SD-WAN ManagerCritical (confidence: 0.9965)
CVE-2026-869502026-09-29AppleMultiple ProductsHigh (confidence: 0.9903)
CVE-2026-887722026-09-27CitrixNetScalerCritical (confidence: 0.9889)
CVE-2026-887712026-09-27CitrixNetScalerCritical (confidence: 0.9895)
CVE-2026-879022026-09-25WordPressCoreCritical (confidence: 0.6985)
CVE-2026-672792026-09-25MikroTikRouterOSHigh (confidence: 0.3884)
CVE-2026-656602026-09-25MicrosoftSharePointHigh (confidence: 0.9941)
CVE-2026-713622026-09-24AdobeCommerce and MagentoCritical (confidence: 0.8496)
CVE-2026-54302026-09-24WSO2Multiple ProductsCritical (confidence: 0.9983)
CVE-2026-941272026-09-22F5BIG-IP APMCritical (confidence: 0.9345)
CVE-2026-939522026-09-22AristaVeloCloud OrchestratorCritical (confidence: 0.9933)
CVE-2026-936162026-09-22Check PointMultiple ProductsCritical (confidence: 0.9578)
CVE-2026-851022026-09-22Check PointMultiple ProductsCritical (confidence: 0.8336)
CVE-2026-72732026-09-21ZyxelGS1900 Series SwitchesHigh (confidence: 0.9359)
CVE-2026-532662026-09-18LinuxKernelHigh (confidence: 0.9115)
CVE-2025-399642026-09-18LinuxKernelHigh (confidence: 0.7034)
CVE-2025-396822026-09-18LinuxKernelCritical (confidence: 0.8456)
CVE-2026-878862026-09-16AcronisBackupHigh (confidence: 0.6477)
CVE-2026-764602026-09-16CiscoIdentity Services EngineCritical (confidence: 0.9506)
CVE-2026-587042026-09-16GooglePixelHigh (confidence: 0.975)
CVE-2026-764612026-09-14CiscoSecure Email GatewayCritical (confidence: 0.9582)
CVE-2026-857062026-09-11GitLabCommunity Edition and Enterprise EditionHigh (confidence: 0.7211)
CVE-2026-848692026-09-11ConnectWiseScreenConnectCritical (confidence: 0.9651)
CVE-2026-420182026-09-11JFrogArtifactoryMedium (confidence: 0.8322)
CVE-2026-420162026-09-11JFrogArtifactoryHigh (confidence: 0.9281)
CVE-2026-860602026-09-10MikroTikRouterOSCritical (confidence: 0.6915)
CVE-2026-672772026-09-10MikroTikRouterOSHigh (confidence: 0.9783)
CVE-2026-874912026-09-09GoogleChromium V8High (confidence: 0.9874)
CVE-2026-200792026-09-09CiscoSecure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementCritical (confidence: 0.9956)
CVE-2026-194902026-09-09CitrixNetScalerCritical (confidence: 0.957)
CVE-2025-252492026-09-09FortinetMultiple ProductsMedium (confidence: 0.4894)
CVE-2026-862182026-09-08N-ableN-centralCritical (confidence: 0.9501)
CVE-2026-858802026-09-08MicrosoftWindowsHigh (confidence: 0.9931)
CVE-2026-819632026-09-08MicrosoftWindowsHigh (confidence: 0.9844)
CVE-2026-756502026-09-08AdobeCommerce and MagentoCritical (confidence: 0.9884)
CVE-2026-850462026-09-04GoogleChromium V8High (confidence: 0.9883)
CVE-2026-95862026-09-02SangomaSwitchvoxCritical (confidence: 0.984)
CVE-2026-835492026-09-02SonicWallSMA1000 AppliancesHigh (confidence: 0.8489)
CVE-2026-835482026-09-02SonicWallSMA1000 AppliancesCritical (confidence: 0.5578)
CVE-2026-823292026-09-02JFrogArtifactoryCritical (confidence: 0.969)
CVE-2026-598222026-09-02BerriAILiteLLMHigh (confidence: 0.7412)
CVE-2026-498692026-09-02KestraKestra OSSCritical (confidence: 0.9926)
CVE-2026-487102026-09-02KludexStarletteMedium (confidence: 0.7694)

More KEV entries from the CISA Catalog.

CIRCL

The CIRCL KEV catalog added 7 entries during September, up from two in August and all marked as confirmed exploitation. The month opened with the Palo Alto GlobalProtect authentication bypass CVE-2026-0257, confirmed through CIRCL’s own incident response as a ransomware case (CISA had listed it in May), and with Log4Shell, still being confirmed in the wild almost five years on. On 9 September CIRCL published GCVE-1-2026-20026, a pre-authentication remote code execution in older firmware that has no CVE and is only identifiable through its GCVE number. The month closed with four entries that corroborate CISA: the F5 BIG-IP APM overflow on 23 September, the day after its CISA listing, then on 28 September the Check Point VPN RCE and both NetScaler issues, the latter one day after CISA.

CVE IDDate AddedVendorProductVLAI Severity
CVE-2026-851022026-09-28Check PointQuantum Security GatewayCritical (confidence: 0.8336)
CVE-2026-887722026-09-28CitrixNetScaler ADC / GatewayCritical (confidence: 0.9889)
CVE-2026-887712026-09-28CitrixNetScaler ADC / GatewayCritical (confidence: 0.9895)
CVE-2026-941272026-09-23F5BIG-IP APMCritical (confidence: 0.9345)
GCVE-1-2026-200262026-09-09–––
CVE-2021-442282026-09-03Apache Software FoundationApache Log4j2High (confidence: 0.7501)
CVE-2026-02572026-09-01Palo Alto NetworksPAN-OS GlobalProtectMedium (confidence: 0.7834)

More KEV entries from the CIRCL Catalog.

ENISA (EUVD)

Nineteen entries were reported through the ENISA / EU CSIRTs Network (CNW) KEV feed during September, nearly three times August’s seven and the feed’s busiest month so far. Seven came from ENISA itself (both Check Point issues, F5, the two WordPress core issues of July (SQL injection and REST route confusion) re-reported with “EU victimology”, and the two Cisco FMC issues, tagged as ransomware with confirmed EU victims), four from CERT.PL (the MikroTrick research), four through the CNW channel (GeoNetwork and NetScaler), three from NCSC-NL (WordPress core on 23 September, two days before CISA, and the two Zammad zero-days) and one from CSIRT-IE (the SharePoint code injection). Five entries – the GeoNetwork pair, the MikroTik impersonation flaw and both Zammad issues – are not in the CISA catalog.

CVE IDDate ReportedVendorProductReported byVLAI Severity
CVE-2026-1024902026-09-30ZammadZammadNCSC-NLHigh (confidence: 0.9479)
CVE-2026-1024892026-09-30ZammadZammadNCSC-NLHigh (confidence: 0.9891)
CVE-2026-887722026-09-27CitrixNetScaler ADC, NetScaler GatewayCNWCritical (confidence: 0.9889)
CVE-2026-887712026-09-27CitrixNetScaler ADC, NetScaler GatewayCNWCritical (confidence: 0.9895)
CVE-2026-672792026-09-27MikroTikRouterOSCERT.PLHigh (confidence: 0.3884)
CVE-2026-656602026-09-25MicrosoftMicrosoft SharePoint Server 2019, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server Subscription EditionCSIRT-IEHigh (confidence: 0.9941)
CVE-2026-879022026-09-23WordPress FoundationWordPressNCSC-NLCritical (confidence: 0.6985)
CVE-2026-941272026-09-22F5BIG-IPENISACritical (confidence: 0.9345)
CVE-2026-936162026-09-22checkpointQuantum Security GatewayENISACritical (confidence: 0.9578)
CVE-2026-851022026-09-22checkpointQuantum Security GatewayENISACritical (confidence: 0.8336)
CVE-2026-630302026-09-21WordPress FoundationWordPressENISAHigh (confidence: 0.6186)
CVE-2026-601372026-09-21WordPress FoundationWordPressENISAHigh (confidence: 0.7802)
CVE-2026-203162026-09-09CiscoCisco Secure Firewall Management Center (FMC)ENISAMedium (confidence: 0.9978)
CVE-2026-200792026-09-09CiscoCisco Secure Firewall Management Center (FMC)ENISACritical (confidence: 0.9956)
CVE-2026-860602026-09-05MikroTikRouterOSCERT.PLCritical (confidence: 0.6915)
CVE-2026-672772026-09-05MikroTikRouterOSCERT.PLHigh (confidence: 0.9783)
CVE-2026-672762026-09-05MikroTikRouterOSCERT.PLCritical (confidence: 0.9593)
CVE-2026-632192026-09-02geonetworkcore-geonetworkCNWCritical (confidence: 0.4713)
CVE-2026-584002026-09-02geonetworkcore-geonetworkCNWCritical (confidence: 0.8087)

More KEV entries from the ENISA Catalog.

The Shadowserver Foundation

The Shadowserver KEV catalog is fed by honeypot-observed exploitation attempts. 16 vulnerabilities were observed for the first time during September, all between 1 and 7 September: the catalog’s most recent observation date is 7 September, so no honeypot data reached Vulnerability-Lookup for the last three weeks of the month and this section is necessarily partial. Two of the sixteen are in the CISA KEV catalog – the Sangoma Switchvox SQL injection CVE-2026-9586, hit on 4 September, two days after its CISA listing, and the MeteoBridge command injection CVE-2025-4008 from October 2025. The rest is the usual honeypot fare: consumer routers (four Totolink models, two Tenda CH22 issues, two D-Link models and a Shenzhen Aitemi Wi-Fi repeater), a Grandstream VoIP phone, PaperCut NG, ESDS Emagic, Weaver E-cology and a WordPress analytics plugin, each at one to three connections a day. Severity values are reproduced as published by Shadowserver (CVSS).

CVE IDFirst SeenVendorProductSeverity (Shadowserver)In CISA KEV
CVE-2026-584572026-09-07Shenzhen AitemiM300 Wi-Fi RepeaterCritical (CVSS 9.3)
CVE-2025-606872026-09-07TotolinkTotolink LR1200GBMedium (CVSS 6.5)
CVE-2025-60682026-09-07TotolinkTotolink A720RMedium (CVSS 6.5)
CVE-2025-142082026-09-07D-LinkD-Link DIR-823XMedium (CVSS 6.3)
CVE-2023-375692026-09-07ESDSEmagic Data Center Management SuiteHigh (CVSS 8.8)
CVE-2025-40082026-09-06SmartbeddedMeteoBridgeHigh (CVSS 8.7)✓
CVE-2025-606982026-09-05D-LinkD-Link DIR-882High (CVSS 7.3)
CVE-2026-95862026-09-04SangomaSangoma SwitchvoxCritical (CVSS 9.8)✓
CVE-2019-106552026-09-04GrandstreamGXV3240/GXP2200Critical (CVSS 9.8)
CVE-2026-781412026-09-01TendaTenda CH22High (CVSS 7.4)
CVE-2026-51532026-09-01TendaTenda CH22High (CVSS 8.8)
CVE-2026-15472026-09-01TotolinkTotolink A7000RCritical (CVSS 9.8)
CVE-2025-607022026-09-01TotolinkTotolink A950RG–
CVE-2024-02502026-09-01WordpressWordpres Analytics Insights for Google Analytics 4 (AIWP) pluginMedium (CVSS 6.1)
CVE-2023-394702026-09-01PaperCutPaperCut NGHigh (CVSS 7.2)
CVE-2016-200972026-09-01WeaverWeaver E-cologyHigh (CVSS 7.5)

More KEV entries from the Shadowserver Catalog.

Previdian (formerly KEVIntel)

The Previdian catalog – the catalog reported as KEVIntel in previous editions, renamed but otherwise unchanged – aggregates public exploitation reports and added 156 entries in September, up from 91 in August and by far the highest volume of the tracked feeds. It covers all 43 of CISA’s additions for the month, a first since this report started comparing the two.

Eighteen of those it flagged before CISA did: the Adobe Commerce authorization bypass CVE-2026-71362 on 10 September, a full 14 days ahead; the WSO2 JWT account takeover CVE-2026-5430 by 8 days; the NetScaler authentication bypass CVE-2026-19490 by 6 days; the Adobe Commerce template injection CVE-2026-75650 by 3 days; the WordPress core file inclusion, the MikroTik rekey bypass, ScreenConnect and N-central by 2 days each; and ten more by one day, among them the Apple CoreGraphics zero-day, the SharePoint code injection, all three Artifactory issues and both SonicWall SMA1000 entries. The remaining 25 were listed on the same day as CISA, and none came later.

96 entries are unique to Previdian this month, 36 of them 2026 CVEs. The largest block is Chinese enterprise software added in two batches (14–18 and 29–30 September): Yonyou U8 CRM, U8 Cloud and A6 OA, Inspur HCM Cloud, Hongjing e-HR, Weaver E-cology, Chanjet CRM, Fumeng Cloud, iDocView, DedeCMS and Mingsoft MCMS – a cluster that only Shadowserver’s honeypots used to surface. The second block is WordPress plugins and small PHP applications with unauthenticated SQL injection or file upload (LearnPress, TI WooCommerce Wishlist, Modern Events Calendar, Elementor Pro, Super Forms, JetEngine and a dozen others). The AI cluster is again visible – Langflow CVE-2026-0769, two Flowise issues (CVE-2026-56271, CVE-2026-69255), Dify, Nuclio, OmniRoute, Flyto2 and Red Hat OpenShift AI – alongside XWiki (three entries, two above 77% EPSS), Ghost (CVE-2026-26980, 70.2% EPSS), OpenCTI (CVE-2026-27960, default admin account), Roundcube, Grav, Dolibarr, Veeam, two further N-central issues and the KGUARD DVR command execution CVE-2026-87827, the only entry of the month Previdian marks as used in malware. The legacy tail is as high-EPSS as ever: Drupalgeddon CVE-2014-3704 (99.97%), Joomla CVE-2017-8917 (99.8%), the Jenkins Script Security sandbox bypass CVE-2019-1003000 (98.4%), XWiki CVE-2023-37462 (91.5%) and FileCatalyst Workflow CVE-2024-5276 (90.1%).

Vendor, product, CVSS and EPSS values below are reproduced as published by Previdian.

CVE IDDate AddedVendorProductSeverity (Previdian)EPSS
CVE-2026-765042026-09-30CiscoCisco Catalyst SD-WAN ManagerCritical (CVSS 9.8)–
CVE-2026-1024902026-09-30ZammadZammadHigh (CVSS 8.5)0.32%
CVE-2026-1024892026-09-30ZammadZammadHigh (CVSS 8.7)0.71%
CVE-2024-583872026-09-30InspurHaiyue HCM CloudHigh (CVSS 8.7)–
CVE-2023-544032026-09-30YonyouU8 CRMHigh (CVSS 8.7)–
CVE-2023-544022026-09-30iDocViewiDocViewHigh (CVSS 8.7)–
CVE-2026-855202026-09-29MyPrestaGoogle Merchant Center FeedCritical (CVSS 9.3)–
CVE-2025-620232026-09-29Cristián Lávaques2MemberCritical (CVSS 9.0)0.42%
CVE-2023-544002026-09-29FumasoftFumeng CloudCritical (CVSS 9.3)–
CVE-2015-201222026-09-29YonyouA6 OAHigh (CVSS 8.7)–
CVE-2026-869502026-09-28AppleiOS and iPadOS, macOSHigh (CVSS 8.8)0.81%
CVE-2026-490762026-09-28CrocoblockJetEngineCritical (CVSS 9.3)0.40%
CVE-2026-887722026-09-27Citrix NetScalerADC, GatewayCritical (CVSS 9.5)–
CVE-2026-887712026-09-27Citrix NetScalerADC, GatewayCritical (CVSS 9.5)–
CVE-2026-426082026-09-27GetgravgravHigh (CVSS 8.8)0.52%
CVE-2026-656602026-09-24MicrosoftMicrosoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, …High (CVSS 8.8)1.19%
CVE-2026-488422026-09-24RoundcubeWebmailHigh (CVSS 8.1)0.89%
CVE-2026-879022026-09-23WordPressWordPressHigh (CVSS 8.1)0.42%
CVE-2026-672792026-09-23MikrotikRouterOSMedium (CVSS 6.9)0.45%
CVE-2026-941272026-09-22F5BIG-IPCritical (CVSS 9.3)1.39%
CVE-2026-939522026-09-22Arista NetworksVeloCloud Orchestrator (VCO) On-PremCritical (CVSS 9.5)0.42%
CVE-2026-936162026-09-22CheckpointQuantum Security ManagementCritical (CVSS 9.8)–
CVE-2026-851022026-09-22CheckpointQuantum Security GatewayCritical (CVSS 9.8)0.33%
CVE-2026-797562026-09-22NuclionuclioHigh (CVSS 8.7)5.15%
CVE-2026-759492026-09-22Cmsjunkie.comJ-BusinessDirectory extension for JoomlaCritical (CVSS 10.0)0.31%
CVE-2026-664572026-09-22PixeliteEvents ManagerHigh (CVSS 7.1)0.19%
CVE-2026-562712026-09-22FlowiseFlowiseCritical (CVSS 9.3)0.66%
CVE-2026-545692026-09-22Senaitesenaite.coreCritical (CVSS 9.8)0.78%
CVE-2016-200802026-09-22BrandfolderBrandfolderMedium (CVSS 6.9)0.39%
CVE-2026-880622026-09-21DiegosouzapwOmniRouteCritical (CVSS 9.5)0.94%
CVE-2026-72732026-09-21ZyxelGS1900-48HPv2 firmware, GS1900-8 firmware, …High (CVSS 8.8)0.32%
CVE-2026-329962026-09-21VeeamBackup and ReplicationHigh (CVSS 7.3)0.15%
CVE-2026-279602026-09-21OpenCTI-PlatformopenctiCritical (CVSS 9.8)1.99%
CVE-2026-269802026-09-21TryGhostGhostCritical (CVSS 9.4)70.21%
CVE-2024-522702026-09-21DropBox(HelloSign)DropBox SignHigh (CVSS 8.2)0.19%
CVE-2021-301342026-09-21Php_curl_class_project, Ht_slider_range_for_amazon_affiliates_project, Qiwi, Teamleade, Ptwooplugins, Shopello_api_projectPHP Curl Class, HT Slider Range FOR Amazon Affiliates, …Medium (CVSS 6.1)1.26%
CVE-2018-139802026-09-21Zeta-producerZeta ProducerMedium (CVSS 5.5)6.90%
CVE-2026-532662026-09-18LinuxLinuxHigh (CVSS 8.8)0.12%
CVE-2026-427962026-09-18ArelleArelleCritical (CVSS 9.2)2.75%
CVE-2026-328822026-09-18StrukturaglibheifHigh (CVSS 7.1)0.34%
CVE-2026-07692026-09-18LangflowLangflowCritical (CVSS 9.8)38.64%
CVE-2025-399642026-09-18LinuxLinuxHigh (CVSS 7.8)0.32%
CVE-2025-396822026-09-18LinuxLinuxCritical (CVSS 9.8)0.51%
CVE-2024-539002026-09-18MongoosejsMongooseCritical (CVSS 9.1)3.90%
CVE-2023-543992026-09-18Hongjinge-HRCritical (CVSS 9.3)–
CVE-2023-463592026-09-18Hardy-barthcph2 Echarge FirmwareCritical (CVSS 9.8)87.61%
CVE-2023-298272026-09-18EjsEJSCritical (CVSS 9.8)5.55%
CVE-2021-480082026-09-18Chanjet Information TechnologyCRMHigh (CVSS 8.7)–
CVE-2019-257762026-09-18Weaver NetworkE-cologyHigh (CVSS 8.7)–
CVE-2017-202842026-09-18Caucho TechnologyResinHigh (CVSS 8.7)–
CVE-2026-890132026-09-17DolibarrDolibarrHigh (CVSS 8.7)0.37%
CVE-2026-865382026-09-17Knowns-devknownsHigh (CVSS 8.7)0.74%
CVE-2026-402422026-09-17GetarcaneapparcaneHigh (CVSS 7.2)0.62%
CVE-2026-322552026-09-17KanbnkanHigh (CVSS 8.6)20.78%
CVE-2022-453622026-09-17PaytmPaytm Payment GatewayHigh (CVSS 7.2)41.76%
CVE-2022-254972026-09-17Cuppa CMSCuppacmsMedium (CVSS 5.3)3.64%
CVE-2021-249462026-09-17WebnusModern Events Calendar LiteCritical (CVSS 9.8)72.80%
CVE-2016-150432026-09-17Websitez.comWP Mobile DetectorCritical (CVSS 9.8)7.76%
CVE-2026-764602026-09-16CiscoCisco Identity Services Engine Software, Cisco ISE Passive Identity Connector, …Critical (CVSS 10.0)–
CVE-2026-587042026-09-16GoogleAndroidHigh (CVSS 8.8)0.11%
CVE-2026-54302026-09-16WSO2WSO2 Universal Gateway, WSO2 Traffic Manager, …Critical (CVSS 10.0)0.32%
CVE-2026-541962026-09-16JetmonstersJetFormBuilderMedium (CVSS 6.8)0.24%
CVE-2022-04342026-09-16a3revPage View CountCritical (CVSS 9.8)14.78%
CVE-2022-04122026-09-16TemplateInvadersTI WooCommerce Wishlist, TI WooCommerce Wishlist ProCritical (CVSS 9.8)74.00%
CVE-2019-10030002026-09-16Jenkins projectScript Security PluginHigh (CVSS 8.8)98.38%
CVE-2026-890262026-09-15IssabelIssabel FrameworkCritical (CVSS 9.3)0.52%
CVE-2026-878862026-09-15AcronisAcronis BackupHigh (CVSS 7.8)–
CVE-2026-692552026-09-15FlowiseAIFlowiseCritical (CVSS 9.2)0.60%
CVE-2026-393642026-09-15Vitejsvite, vite-plusHigh (CVSS 8.2)2.00%
CVE-2025-96032026-09-15TelesquareTLR-2005KSHMedium (CVSS 5.3)7.58%
CVE-2024-583852026-09-15YonyouU8 CRMCritical (CVSS 9.3)–
CVE-2023-543982026-09-15YonyouU8 CloudCritical (CVSS 9.3)–
CVE-2017-78762026-09-15QnapQTSCritical (CVSS 10.0)3.34%
CVE-2016-107602026-09-15Seowonintechswr-300a Firmware, swr-300b Firmware, …Critical (CVSS 9.8)3.23%
CVE-2026-764612026-09-14CiscoCisco Secure EmailCritical (CVSS 9.8)–
CVE-2026-557862026-09-14Flyto2flyto-coreHigh (CVSS 8.4)–
CVE-2026-519902026-09-14Tencent / SogouSogou Input Method for WindowsHigh (CVSS 8.8)–
CVE-2026-275402026-09-14Rymera WebWoocommerce Wholesale Lead CaptureCritical (CVSS 9.0)1.73%
CVE-2026-235362026-09-14Red HatRed Hat OpenShift AI (RHOAI)High (CVSS 7.5)1.91%
CVE-2024-85292026-09-14ThimpressLearnPress – WordPress LMS PluginCritical (CVSS 10.0)11.83%
CVE-2024-241122026-09-14ExrickXmallCritical (CVSS 9.8)3.35%
CVE-2022-320282026-09-14Car_rental_management_system_projectCAR Rental Management SystemHigh (CVSS 7.2)5.06%
CVE-2022-320262026-09-14Car_rental_management_system_projectCAR Rental Management SystemHigh (CVSS 7.2)5.31%
CVE-2022-320252026-09-14Car_rental_management_system_projectCAR Rental Management SystemHigh (CVSS 7.2)4.56%
CVE-2022-320242026-09-14Car_rental_management_system_projectCAR Rental Management SystemHigh (CVSS 7.2)4.56%
CVE-2022-300472026-09-14MingsoftMcmsCritical (CVSS 9.8)1.44%
CVE-2022-279272026-09-14Microfinance_management_system_projectMicrofinance Management SystemCritical (CVSS 9.8)13.83%
CVE-2018-107362026-09-14NagiosNagios XIHigh (CVSS 7.2)42.56%
CVE-2018-107352026-09-14NagiosNagios XIHigh (CVSS 7.2)42.56%
CVE-2017-177312026-09-14DedecmsDedecmsCritical (CVSS 9.8)13.19%
CVE-2025-329692026-09-13Xwikixwiki-platformCritical (CVSS 9.3)77.77%
CVE-2021-248272026-09-13AsgarosAsgaros ForumCritical (CVSS 9.8)12.56%
CVE-2026-857062026-09-11GitLabGitLabCritical (CVSS 10.0)1.15%
CVE-2025-290852026-09-11VipshopSaturnCritical (CVSS 9.8)30.69%
CVE-2025-26362026-09-11InstawpInstaWP Connect – 1-click WP Staging & MigrationHigh (CVSS 8.1)10.42%
CVE-2025-16612026-09-11realmag777HUSKY – Products Filter Professional for WooCommerceCritical (CVSS 9.8)56.38%
CVE-2018-180842026-09-11ComsenzDuomicmsCritical (CVSS 9.8)1.26%
CVE-2017-89172026-09-11JoomlaJoomla!Critical (CVSS 9.8)99.83%
CVE-2026-862062026-09-10N-ableN-centralMedium (CVSS 6.9)0.68%
CVE-2026-860602026-09-10MikrotikRouterOSCritical (CVSS 9.2)0.40%
CVE-2026-713622026-09-10AdobeAdobe Commerce, Adobe Commerce B2B, Magento Open SourceCritical (CVSS 9.1)25.14%
CVE-2026-672772026-09-10MikrotikRouterOSHigh (CVSS 8.8)0.43%
CVE-2026-672762026-09-10MikrotikRouterOSCritical (CVSS 9.2)0.24%
CVE-2026-456952026-09-10KopiakopiaCritical (CVSS 9.8)1.61%
CVE-2026-420312026-09-10CkanckanHigh (CVSS 8.3)1.82%
CVE-2026-420182026-09-10JfrogartifactoryHigh (CVSS 7.5)0.35%
CVE-2026-420162026-09-10JfrogartifactoryHigh (CVSS 8.1)0.27%
CVE-2024-52762026-09-10FortraFileCatalyst WorkflowCritical (CVSS 9.8)90.07%
CVE-2024-503402026-09-10SymfonysymfonyHigh (CVSS 7.3)64.43%
CVE-2024-364122026-09-10SalesagilitySuiteCRMCritical (CVSS 10.0)5.69%
CVE-2024-319822026-09-10Xwikixwiki-platformCritical (CVSS 10.0)34.28%
CVE-2022-10572026-09-10VarktechPricing Deals for WooCommerceCritical (CVSS 9.8)8.11%
CVE-2022-01692026-09-1010WebPhoto Gallery–74.61%
CVE-2019-102322026-09-10Teclib-editionGestionnaire Libre DE Parc InformatiqueCritical (CVSS 9.8)23.21%
CVE-2026-878272026-09-09KGUARDKGUARD_firmwareCritical (CVSS 10.0)–
CVE-2026-874912026-09-09GoogleChromeHigh (CVSS 8.8)0.29%
CVE-2026-862072026-09-09N-ableN-centralHigh (CVSS 7.7)0.73%
CVE-2026-848692026-09-09ConnectWiseScreenConnectCritical (CVSS 9.9)0.38%
CVE-2026-200792026-09-09CiscoCisco Secure Firewall Management Center (FMC)Critical (CVSS 10.0)35.95%
CVE-2024-28512026-09-09TendaAC15Medium (CVSS 6.3)4.01%
GHSA-6V53-HR58-556R2026-09-08––Critical (CVSS 9.8)–
CVE-2026-858802026-09-08MicrosoftWindows 10 Version 1607, Windows 10 Version 1809, …High (CVSS 7.8)–
CVE-2026-819632026-09-08MicrosoftWindows 11 version 23H2, Windows 11 Version 23H2, …High (CVSS 7.8)–
CVE-2025-252492026-09-08FortinetFortiSwitchManager, FortiOSHigh (CVSS 8.1)0.76%
CVE-2023-374622026-09-08Xwikixwiki-platformCritical (CVSS 9.9)91.49%
CVE-2018-172542026-09-08–n/aCritical (CVSS 9.8)82.98%
CVE-2025-606872026-09-07ToToLinkLR1200GB RouterMedium (CVSS 6.5)–
CVE-2025-60682026-09-07BradvinFooGallery – Responsive Photo Gallery, Image Viewer, …Medium (CVSS 6.4)–
CVE-2025-142082026-09-07D-LinkDIR-823XMedium (CVSS 5.3)–
CVE-2023-375692026-09-07ESDSEmagic Data Center Management SuiteHigh (CVSS 8.8)–
CVE-2026-862182026-09-06N-ableN-centralCritical (CVSS 10.0)0.41%
CVE-2026-756502026-09-05AdobeAdobe Commerce, Adobe Commerce B2B, Magento Open SourceCritical (CVSS 10.0)2.15%
CVE-2025-606982026-09-05D-LinkDIR-882 RouterHigh (CVSS 7.3)3.93%
CVE-2026-850462026-09-04GoogleChromeHigh (CVSS 8.8)0.46%
CVE-2026-584572026-09-04Shenzhen Aitemi E CommerceM300 Wi-Fi RepeaterCritical (CVSS 9.3)2.94%
CVE-2026-148942026-09-04WebRehabSuper Forms – Drag & Drop Form BuilderCritical (CVSS 9.8)5.27%
CVE-2019-106552026-09-04GrandstreamGAC2500Critical (CVSS 9.8)15.47%
CVE-2026-194902026-09-03NetScalerADC, GatewayCritical (CVSS 9.3)3.37%
CVE-2014-37042026-09-03DrupalDrupalHigh (CVSS 7.5)99.97%
CVE-2026-598222026-09-02BerriAIlitellmHigh (CVSS 8.8)0.52%
CVE-2026-498692026-09-02Kestra-iokestraCritical (CVSS 10.0)0.99%
CVE-2026-487102026-09-02KludexstarletteMedium (CVSS 6.5)2.10%
CVE-2026-324752026-09-02ElementorElementor ProCritical (CVSS 9.0)2.37%
CVE-2026-95862026-09-01SangomaSwitchvox SMB EditionCritical (CVSS 9.3)0.43%
CVE-2026-835492026-09-01SonicWallSMA1000High (CVSS 7.8)0.92%
CVE-2026-835482026-09-01SonicWallSMA1000Critical (CVSS 10.0)0.27%
CVE-2026-823292026-09-01JfrogartifactoryCritical (CVSS 9.8)0.38%
CVE-2026-781412026-09-01TendaCH22Medium (CVSS 5.3)1.07%
CVE-2026-51532026-09-01TendaCH22Medium (CVSS 5.3)3.30%
CVE-2026-419482026-09-01LanggeniusdifyCritical (CVSS 9.3)7.39%
CVE-2026-15472026-09-01TotolinkA7000RMedium (CVSS 5.3)2.82%
CVE-2025-607022026-09-01TOTOLINKA950RG RouterMedium (CVSS 6.5)2.54%
CVE-2025-405532026-09-01SolarWindsWeb Help DeskCritical (CVSS 9.8)60.39%
CVE-2024-02502026-09-01Analytics InsightsAnalytics Insights for Google Analytics 4Medium (CVSS 6.1)1.25%
CVE-2023-543912026-09-01Proxmox Server SolutionsProxmox Virtual Environment (VE)Critical (CVSS 9.3)–
CVE-2023-394702026-09-01PaperCutNGHigh (CVSS 7.2)1.76%

More KEV entries from the Previdian Catalog.

Top 10 Weaknesses of the Month

Memory safety keeps the top three places for the third month running, and the gap is widening: heap-based buffer overflow (CWE-122) approaches 10,000 occurrences, almost double August’s figure, ahead of use-after-free (CWE-416, about 5,900) and out-of-bounds read (CWE-125, about 5,200). Cross-site scripting (CWE-79) stays fourth, missing authorization (CWE-862) fifth, and integer overflow (CWE-190) and stack-based buffer overflow (CWE-121) both enter the top ten – which makes five memory-corruption classes out of ten.

Top 10 Weaknesses of the Month

Insights from Contributors

Two community comments were published this month:

  • A contradictory timeline – a contributor revisits the Microsoft Entra ID deserialization RCE CVE-2026-69836 (CVSS 10.0), reported in August as a CISA entry visible in no other catalog. The comment documents the back-and-forth around its “exploited” flag, which Microsoft withdrew, and the resulting absence from the CISA KEV – the entry no longer appears in any tracked catalog today. Its wider point is about server-side patches on multi-tenant cloud services: with no binary to download and no version to check, defenders can only trust the vendor and shift from patching to detection.
  • LG TV discovery traffic and CVE-2026-13230 – a possible interaction with CVE-2026-9770? – an annotation on the TP-Link Kasa EC70/EC71 hard-coded private key CVE-2026-9770, noting that LG TVs broadcast discovery packets on UDP/9999 every 25 seconds, the same port used by the Kasa discovery mechanism of CVE-2026-13230, which leaks the camera’s GPS coordinates without authentication. The suggested interaction is tagged vulnerability:exploitability=theoretical.

Contributors also curated advisories and research into five bundles during September:

Thank you

Thank you to all the contributors and our diverse sources!

If you want to contribute to the next report, you can create your account.

Feedback and Support

If you have suggestions, please feel free to open a ticket on our GitHub repository. Your feedback is invaluable to us!
https://github.com/vulnerability-lookup/vulnerability-lookup/issues/

Funding

eu_funded_en

The main objective of Federated European Team for Threat Analysis (FETTA) is improvement of Cyber Threat Intelligence (CTI) products available to the public and private sector in Poland, Luxembourg, and the European Union as a whole.
Developing actionable CTI products (reports, indicators, etc) is a complex task and requires an in-depth understanding of the threat landscape and the ability to analyse and interpret large amounts of data. Many SOCs and CSIRTs build their capabilities in this area independently, leading to a fragmented approach and duplication of work.

The Computer Incident Response Center Luxembourg (CIRCL) is a government-driven initiative designed to provide a systematic response facility to computer security threats and incidents. The organization brings to the table its extensive experience in cybersecurity incident management, threat intelligence, and proactive response strategies. With a strong background in developing innovative open source cybersecurity tools and solutions, CIRCL’s contribution to the FETTA project is instrumental in achieving enhanced collaboration and intelligence sharing across Europe.

Press release

AIPITCH (AI-Powered Innovative Toolkit for Cybersecurity Hubs) is a co-funded EU project supported by the European Cybersecurity Competence Centre (ECCC) under the DIGITAL-ECCC-2024-DEPLOY-CYBER-06-ENABLINGTECH program and CIRCL.
The VLAI severity levels used throughout this report are produced by models developed as part of AIPITCH.