CISA Adds Two Known Exploited Vulnerabilities to Catalog

2026-09-18T15:24:02Z•6f5fccb2dda9bec9cb8f54f0d432c8825e6c28a2599011d5e37ae1da12c45448
CVE-2025-39964CVE-2026-42016CVE-2026-42018CVE-2026-53266CVE-2026-58704CVE-2026-67277CVE-2026-76460CVE-2026-76461CVE-2026-84869CVE-2026-85706CVE-2026-86060CVE-2026-87886AcronisBOD 26-04CISA KEVCiscoConnectWise ScreenConnectGitLabGoogle PixelJFrog ArtifactoryLinux KernelMikroTik RouterOSactive exploitationknown exploited vulnerabilitiesvulnerability management

What happened

CISA reported additions to its Known Exploited Vulnerabilities (KEV) Catalog from September 11–18, 2026, citing evidence of active exploitation. The affected technologies include Linux Kernel, Cisco Identity Services Engine and Secure Email Gateway, Acronis Backup, Google Pixel, GitLab, JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. Organizations should prioritize remediation, assess internet-facing assets, and investigate potential compromise before patching, consistent with risk-based vulnerability management and BOD 26-04 guidance.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
6f5fccb2dda9bec9cb8f54f0d432c8825e6c28a2599011d5e37ae1da12c45448
Enrichment time
2026-09-18T15:24:02Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.