CISA Adds Two Known Exploited Vulnerabilities to Catalog
2026-09-18T15:24:02Z•6f5fccb2dda9bec9cb8f54f0d432c8825e6c28a2599011d5e37ae1da12c45448
CVE-2025-39964CVE-2026-42016CVE-2026-42018CVE-2026-53266CVE-2026-58704CVE-2026-67277CVE-2026-76460CVE-2026-76461CVE-2026-84869CVE-2026-85706CVE-2026-86060CVE-2026-87886AcronisBOD 26-04CISA KEVCiscoConnectWise ScreenConnectGitLabGoogle PixelJFrog ArtifactoryLinux KernelMikroTik RouterOSactive exploitationknown exploited vulnerabilitiesvulnerability management
What happened
CISA reported additions to its Known Exploited Vulnerabilities (KEV) Catalog from September 11–18, 2026, citing evidence of active exploitation. The affected technologies include Linux Kernel, Cisco Identity Services Engine and Secure Email Gateway, Acronis Backup, Google Pixel, GitLab, JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. Organizations should prioritize remediation, assess internet-facing assets, and investigate potential compromise before patching, consistent with risk-based vulnerability management and BOD 26-04 guidance.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- 6f5fccb2dda9bec9cb8f54f0d432c8825e6c28a2599011d5e37ae1da12c45448
- Enrichment time
- 2026-09-18T15:24:02Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.