CISA Adds Two Known Exploited Vulnerabilities to Catalog

2026-09-16T21:24:04Z•4227000ca397d83e03c795ca6a3b4ed24fd97f6bdf9065d51c073d5521901492
CVE-2025-25249CVE-2026-19490CVE-2026-20079CVE-2026-42016CVE-2026-42018CVE-2026-58704CVE-2026-67277CVE-2026-76460CVE-2026-76461CVE-2026-84869CVE-2026-85706CVE-2026-86060CVE-2026-87491CVE-2026-87886AcronisCISA KEVChromiumCiscoCitrix NetScalerConnectWise ScreenConnectFortinetGitLabGoogle PixelJFrog ArtifactoryMikroTik RouterOSSQL injectionactive exploitationauthentication bypassauthorization flawcommand injectionknown exploited vulnerabilitypath traversalprivilege escalationrapid remediationvulnerability management

What happened

CISA added 15 vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog between September 10 and 16, 2026, citing evidence of active exploitation. Affected products include Cisco Identity Services Engine and Secure Email Gateway, Acronis Backup, Google Pixel and Chromium, GitLab, JFrog Artifactory, ConnectWise ScreenConnect, MikroTik RouterOS, Fortinet products, Citrix NetScaler, and Cisco Firewall Management Center. Organizations should prioritize remediation, exposure assessment, and compromise checking, consistent with CISA risk-based vulnerability guidance and BOD 26-04.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
4227000ca397d83e03c795ca6a3b4ed24fd97f6bdf9065d51c073d5521901492
Enrichment time
2026-09-16T21:24:04Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.