Skip to content
eastbaycyber

CISA Adds 3 Known Exploited Vulnerabilities to Catalog (September 25, 2026)

Source: CISA KEV Catalog · Updated 2026-09-25

Summary

On September 25, 2026, CISA added 3 vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-67279, CVE-2026-65660, CVE-2026-87902. A KEV listing means CISA has evidence of active exploitation. CISA sets a remediation due date for US federal civilian agencies under its binding operational directives; any organization running the affected products should treat these as patch-now priorities.

CVE-2026-67279: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

MikroTik · RouterOS

Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.

Federal due date
2026-09-28
Ransomware use
Unknown
Added
2026-09-25

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record

CVE-2026-65660: Microsoft SharePoint Code Injection Vulnerability

Microsoft · SharePoint

Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.

Federal due date
2026-09-28
Ransomware use
Unknown
Added
2026-09-25

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record · Microsoft KEV history

CVE-2026-87902: WordPress Core Remote File Inclusion Vulnerability

WordPress · Core

WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.

Federal due date
2026-09-28
Ransomware use
Unknown
Added
2026-09-25

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record

Also added to KEV in September 2026

  • September 24, 2026: CVE-2026-71362, Adobe Commerce and Magento (Adobe Commerce and Magento Incorrect Authorization Vulnerability )
  • September 24, 2026: CVE-2026-5430, WSO2 Multiple Products (WSO2 Multiple Products Path Traversal Vulnerability )
  • September 22, 2026: CVE-2026-94127, F5 BIG-IP APM (F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability)
  • September 22, 2026: CVE-2026-93952, Arista VeloCloud Orchestrator (Arista VeloCloud Orchestrator Improper Input Validation Vulnerability)
  • September 22, 2026: CVE-2026-93616, Check Point Multiple Products (Check Point Multiple Products Path Traversal Vulnerability)
  • September 22, 2026: CVE-2026-85102, Check Point Multiple Products (Check Point Multiple Products Improper Certificate Validation Vulnerability)
  • September 21, 2026: CVE-2026-7273, Zyxel GS1900 Series Switches (Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability)
  • September 18, 2026: CVE-2026-53266, Linux Kernel (Linux Kernel Out-of-Bounds Write Vulnerability)
  • September 18, 2026: CVE-2025-39964, Linux Kernel (Linux Kernel Race Condition Vulnerability)
  • September 18, 2026: CVE-2025-39682, Linux Kernel (Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability)
  • September 16, 2026: CVE-2026-87886, Acronis Backup (Acronis Backup Incorrect Default Permissions Vulnerability)
  • September 16, 2026: CVE-2026-76460, Cisco Identity Services Engine (Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability)
  • September 16, 2026: CVE-2026-58704, Google Pixel (Google Pixel Improper Authorization Vulnerability)
  • September 14, 2026: CVE-2026-76461, Cisco Secure Email Gateway (Cisco Secure Email Gateway SQL Injection Vulnerability)
  • September 11, 2026: CVE-2026-85706, GitLab Community Edition and Enterprise Edition (GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability)
  • September 11, 2026: CVE-2026-84869, ConnectWise ScreenConnect (ConnectWise ScreenConnect Improper Privilege Management and Missing Authorizatio)
  • September 11, 2026: CVE-2026-42018, JFrog Artifactory (JFrog Artifactory Improper Authentication Vulnerability)
  • September 11, 2026: CVE-2026-42016, JFrog Artifactory (JFrog Artifactory Incorrect Authorization Vulnerability)
  • September 10, 2026: CVE-2026-86060, MikroTik RouterOS (MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vu)
  • September 10, 2026: CVE-2026-67277, MikroTik RouterOS (MikroTik RouterOS Missing Authentication for Critical Function Vulnerability)
  • September 9, 2026: CVE-2026-87491, Google Chromium V8 (Google Chromium V8 Out of Bounds Write Vulnerability)
  • September 9, 2026: CVE-2026-20079, Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management (Cisco Firewall Management Center Authentication Bypass Using an Alternate Path o)
  • September 9, 2026: CVE-2026-19490, Citrix NetScaler (Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulner)
  • September 9, 2026: CVE-2025-25249, Fortinet Multiple Products (Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability)
  • September 8, 2026: CVE-2026-86218, N-able N-central (N-able N-central Static Code Injection Vulnerability)

Check whether you run these products: our vulnerability scanner comparison covers tools that detect KEV-listed flaws. See also the KEV dashboard and KEV history by vendor.