Skip to content
eastbaycyber

CISA Adds 3 Known Exploited Vulnerabilities to Catalog (September 18, 2026)

Source: CISA KEV Catalog · Updated 2026-09-25

Summary

On September 18, 2026, CISA added 3 vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2025-39964, CVE-2026-53266, CVE-2025-39682. A KEV listing means CISA has evidence of active exploitation. CISA sets a remediation due date for US federal civilian agencies under its binding operational directives; any organization running the affected products should treat these as patch-now priorities.

CVE-2025-39964: Linux Kernel Race Condition Vulnerability

Linux · Kernel

Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.

Federal due date
2026-09-21
Ransomware use
Unknown
Added
2026-09-18

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record · Linux KEV history

CVE-2026-53266: Linux Kernel Out-of-Bounds Write Vulnerability

Linux · Kernel

Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

Federal due date
2026-09-21
Ransomware use
Unknown
Added
2026-09-18

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record · Linux KEV history

CVE-2025-39682: Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

Linux · Kernel

Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

Federal due date
2026-09-21
Ransomware use
Unknown
Added
2026-09-18

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record · Linux KEV history

Also added to KEV in September 2026

  • September 25, 2026: CVE-2026-87902, WordPress Core (WordPress Core Remote File Inclusion Vulnerability)
  • September 25, 2026: CVE-2026-67279, MikroTik RouterOS (Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability)
  • September 25, 2026: CVE-2026-65660, Microsoft SharePoint (Microsoft SharePoint Code Injection Vulnerability)
  • September 24, 2026: CVE-2026-71362, Adobe Commerce and Magento (Adobe Commerce and Magento Incorrect Authorization Vulnerability )
  • September 24, 2026: CVE-2026-5430, WSO2 Multiple Products (WSO2 Multiple Products Path Traversal Vulnerability )
  • September 22, 2026: CVE-2026-94127, F5 BIG-IP APM (F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability)
  • September 22, 2026: CVE-2026-93952, Arista VeloCloud Orchestrator (Arista VeloCloud Orchestrator Improper Input Validation Vulnerability)
  • September 22, 2026: CVE-2026-93616, Check Point Multiple Products (Check Point Multiple Products Path Traversal Vulnerability)
  • September 22, 2026: CVE-2026-85102, Check Point Multiple Products (Check Point Multiple Products Improper Certificate Validation Vulnerability)
  • September 21, 2026: CVE-2026-7273, Zyxel GS1900 Series Switches (Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability)
  • September 16, 2026: CVE-2026-87886, Acronis Backup (Acronis Backup Incorrect Default Permissions Vulnerability)
  • September 16, 2026: CVE-2026-76460, Cisco Identity Services Engine (Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability)
  • September 16, 2026: CVE-2026-58704, Google Pixel (Google Pixel Improper Authorization Vulnerability)
  • September 14, 2026: CVE-2026-76461, Cisco Secure Email Gateway (Cisco Secure Email Gateway SQL Injection Vulnerability)
  • September 11, 2026: CVE-2026-85706, GitLab Community Edition and Enterprise Edition (GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability)
  • September 11, 2026: CVE-2026-84869, ConnectWise ScreenConnect (ConnectWise ScreenConnect Improper Privilege Management and Missing Authorizatio)
  • September 11, 2026: CVE-2026-42018, JFrog Artifactory (JFrog Artifactory Improper Authentication Vulnerability)
  • September 11, 2026: CVE-2026-42016, JFrog Artifactory (JFrog Artifactory Incorrect Authorization Vulnerability)
  • September 10, 2026: CVE-2026-86060, MikroTik RouterOS (MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vu)
  • September 10, 2026: CVE-2026-67277, MikroTik RouterOS (MikroTik RouterOS Missing Authentication for Critical Function Vulnerability)
  • September 9, 2026: CVE-2026-87491, Google Chromium V8 (Google Chromium V8 Out of Bounds Write Vulnerability)
  • September 9, 2026: CVE-2026-20079, Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management (Cisco Firewall Management Center Authentication Bypass Using an Alternate Path o)
  • September 9, 2026: CVE-2026-19490, Citrix NetScaler (Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulner)
  • September 9, 2026: CVE-2025-25249, Fortinet Multiple Products (Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability)
  • September 8, 2026: CVE-2026-86218, N-able N-central (N-able N-central Static Code Injection Vulnerability)

Check whether you run these products: our vulnerability scanner comparison covers tools that detect KEV-listed flaws. See also the KEV dashboard and KEV history by vendor.