Skip to content
eastbaycyber

CISA Adds 2 Known Exploited Vulnerabilities to Catalog (September 24, 2026)

Source: CISA KEV Catalog · Updated 2026-09-25

Summary

On September 24, 2026, CISA added 2 vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-5430, CVE-2026-71362. A KEV listing means CISA has evidence of active exploitation. CISA sets a remediation due date for US federal civilian agencies under its binding operational directives; any organization running the affected products should treat these as patch-now priorities.

CVE-2026-5430: WSO2 Multiple Products Path Traversal Vulnerability

WSO2 · Multiple Products

WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.

Federal due date
2026-09-27
Ransomware use
Unknown
Added
2026-09-24

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read our explainer · NVD record

CVE-2026-71362: Adobe Commerce and Magento Incorrect Authorization Vulnerability

Adobe · Commerce and Magento

Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.

Federal due date
2026-09-27
Ransomware use
Unknown
Added
2026-09-24

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record · Adobe KEV history

Also added to KEV in September 2026

  • September 25, 2026: CVE-2026-87902, WordPress Core (WordPress Core Remote File Inclusion Vulnerability)
  • September 25, 2026: CVE-2026-67279, MikroTik RouterOS (Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability)
  • September 25, 2026: CVE-2026-65660, Microsoft SharePoint (Microsoft SharePoint Code Injection Vulnerability)
  • September 22, 2026: CVE-2026-94127, F5 BIG-IP APM (F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability)
  • September 22, 2026: CVE-2026-93952, Arista VeloCloud Orchestrator (Arista VeloCloud Orchestrator Improper Input Validation Vulnerability)
  • September 22, 2026: CVE-2026-93616, Check Point Multiple Products (Check Point Multiple Products Path Traversal Vulnerability)
  • September 22, 2026: CVE-2026-85102, Check Point Multiple Products (Check Point Multiple Products Improper Certificate Validation Vulnerability)
  • September 21, 2026: CVE-2026-7273, Zyxel GS1900 Series Switches (Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability)
  • September 18, 2026: CVE-2026-53266, Linux Kernel (Linux Kernel Out-of-Bounds Write Vulnerability)
  • September 18, 2026: CVE-2025-39964, Linux Kernel (Linux Kernel Race Condition Vulnerability)
  • September 18, 2026: CVE-2025-39682, Linux Kernel (Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability)
  • September 16, 2026: CVE-2026-87886, Acronis Backup (Acronis Backup Incorrect Default Permissions Vulnerability)
  • September 16, 2026: CVE-2026-76460, Cisco Identity Services Engine (Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability)
  • September 16, 2026: CVE-2026-58704, Google Pixel (Google Pixel Improper Authorization Vulnerability)
  • September 14, 2026: CVE-2026-76461, Cisco Secure Email Gateway (Cisco Secure Email Gateway SQL Injection Vulnerability)
  • September 11, 2026: CVE-2026-85706, GitLab Community Edition and Enterprise Edition (GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability)
  • September 11, 2026: CVE-2026-84869, ConnectWise ScreenConnect (ConnectWise ScreenConnect Improper Privilege Management and Missing Authorizatio)
  • September 11, 2026: CVE-2026-42018, JFrog Artifactory (JFrog Artifactory Improper Authentication Vulnerability)
  • September 11, 2026: CVE-2026-42016, JFrog Artifactory (JFrog Artifactory Incorrect Authorization Vulnerability)
  • September 10, 2026: CVE-2026-86060, MikroTik RouterOS (MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vu)
  • September 10, 2026: CVE-2026-67277, MikroTik RouterOS (MikroTik RouterOS Missing Authentication for Critical Function Vulnerability)
  • September 9, 2026: CVE-2026-87491, Google Chromium V8 (Google Chromium V8 Out of Bounds Write Vulnerability)
  • September 9, 2026: CVE-2026-20079, Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management (Cisco Firewall Management Center Authentication Bypass Using an Alternate Path o)
  • September 9, 2026: CVE-2026-19490, Citrix NetScaler (Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulner)
  • September 9, 2026: CVE-2025-25249, Fortinet Multiple Products (Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability)

Check whether you run these products: our vulnerability scanner comparison covers tools that detect KEV-listed flaws. See also the KEV dashboard and KEV history by vendor.