CISA Adds Four Known Exploited Vulnerabilities to Catalog

2026-09-22T21:24:03Z•9ab3bdb40bce837357f3b4cec80b99a34052e60cc03b1fb94a6cd051cedae129
CVE-2025-39682CVE-2025-39964CVE-2026-53266CVE-2026-58704CVE-2026-7273CVE-2026-76460CVE-2026-76461CVE-2026-85102CVE-2026-87886CVE-2026-93616CVE-2026-93952CVE-2026-94127Acronis BackupArista VeloCloud OrchestratorBOD 26-04CISA KEVCheck PointCiscoF5 BIG-IPGoogle PixelLinux kernelSQL injectionZyxel GS1900active exploitationbuffer overflowimproper authentication and authorizationimproper input validationknown exploited vulnerabilitiesout-of-bounds writepath traversalrace conditionvulnerability management

What happened

CISA alerts from September 16–22, 2026 report the addition of 12 vulnerabilities to the Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. Affected products include Check Point, Arista VeloCloud Orchestrator, F5 BIG-IP APM, Zyxel GS1900 switches, Linux kernel, Cisco ISE and Secure Email Gateway, Acronis Backup, and Google Pixel. Organizations should prioritize remediation, investigate for compromise before patching, and apply risk-based vulnerability management; FCEB agencies must follow BOD 26-04 requirements.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
9ab3bdb40bce837357f3b4cec80b99a34052e60cc03b1fb94a6cd051cedae129
Enrichment time
2026-09-22T21:24:03Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.