CISA Adds Two Known Exploited Vulnerabilities to Catalog
2026-09-16T21:24:04Z•4227000ca397d83e03c795ca6a3b4ed24fd97f6bdf9065d51c073d5521901492
CVE-2025-25249CVE-2026-19490CVE-2026-20079CVE-2026-42016CVE-2026-42018CVE-2026-58704CVE-2026-67277CVE-2026-76460CVE-2026-76461CVE-2026-84869CVE-2026-85706CVE-2026-86060CVE-2026-87491CVE-2026-87886AcronisCISA KEVChromiumCiscoCitrix NetScalerConnectWise ScreenConnectFortinetGitLabGoogle PixelJFrog ArtifactoryMikroTik RouterOSSQL injectionactive exploitationauthentication bypassauthorization flawcommand injectionknown exploited vulnerabilitypath traversalprivilege escalationrapid remediationvulnerability management
What happened
CISA added 15 vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog between September 10 and 16, 2026, citing evidence of active exploitation. Affected products include Cisco Identity Services Engine and Secure Email Gateway, Acronis Backup, Google Pixel and Chromium, GitLab, JFrog Artifactory, ConnectWise ScreenConnect, MikroTik RouterOS, Fortinet products, Citrix NetScaler, and Cisco Firewall Management Center. Organizations should prioritize remediation, exposure assessment, and compromise checking, consistent with CISA risk-based vulnerability guidance and BOD 26-04.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- 4227000ca397d83e03c795ca6a3b4ed24fd97f6bdf9065d51c073d5521901492
- Enrichment time
- 2026-09-16T21:24:04Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.