CISA Adds Four Known Exploited Vulnerabilities to Catalog
2026-09-22T21:24:03Z•9ab3bdb40bce837357f3b4cec80b99a34052e60cc03b1fb94a6cd051cedae129
CVE-2025-39682CVE-2025-39964CVE-2026-53266CVE-2026-58704CVE-2026-7273CVE-2026-76460CVE-2026-76461CVE-2026-85102CVE-2026-87886CVE-2026-93616CVE-2026-93952CVE-2026-94127Acronis BackupArista VeloCloud OrchestratorBOD 26-04CISA KEVCheck PointCiscoF5 BIG-IPGoogle PixelLinux kernelSQL injectionZyxel GS1900active exploitationbuffer overflowimproper authentication and authorizationimproper input validationknown exploited vulnerabilitiesout-of-bounds writepath traversalrace conditionvulnerability management
What happened
CISA alerts from September 16–22, 2026 report the addition of 12 vulnerabilities to the Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. Affected products include Check Point, Arista VeloCloud Orchestrator, F5 BIG-IP APM, Zyxel GS1900 switches, Linux kernel, Cisco ISE and Secure Email Gateway, Acronis Backup, and Google Pixel. Organizations should prioritize remediation, investigate for compromise before patching, and apply risk-based vulnerability management; FCEB agencies must follow BOD 26-04 requirements.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- 9ab3bdb40bce837357f3b4cec80b99a34052e60cc03b1fb94a6cd051cedae129
- Enrichment time
- 2026-09-22T21:24:03Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.