CISA Adds One Known Exploited Vulnerability to Catalog

2026-09-11T21:24:03Za246f6992ba49bfa413f897d3d98af88a1704c5f1f99af86c6f6a68e47cd9daf
CVE-2025-25249CVE-2026-19490CVE-2026-20079CVE-2026-42016CVE-2026-42018CVE-2026-48710CVE-2026-49869CVE-2026-59822CVE-2026-67277CVE-2026-75650CVE-2026-81963CVE-2026-82329CVE-2026-83548CVE-2026-84869CVE-2026-85046CVE-2026-85706CVE-2026-85880CVE-2026-86060CVE-2026-86218CVE-2026-87491CVE-2026-9586Adobe CommerceCISACisco FMCCitrix NetScalerConnectWise ScreenConnectFortinetGitLabGoogle ChromiumJFrog ArtifactoryKEVKnown Exploited VulnerabilitiesMicrosoft WindowsMikroTik RouterOSN-able N-centralSonicWallactive exploitationpatchingvulnerability management

What happened

CISA alerts that multiple vulnerabilities were added to the Known Exploited Vulnerabilities (KEV) Catalog between September 4 and 11, 2026, based on evidence of active exploitation. Affected products include GitLab, JFrog Artifactory, ConnectWise ScreenConnect, MikroTik RouterOS, Fortinet, Citrix NetScaler, Google Chromium, Cisco Firewall Management Center, Adobe Commerce/Magento, Microsoft Windows, N-able N-central, Sangoma Switchvox, Starlette, Kestra, LiteLLM, and SonicWall SMA1000. Organizations should prioritize rapid remediation, assess internet-facing systems, and investigate for signs‍

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
a246f6992ba49bfa413f897d3d98af88a1704c5f1f99af86c6f6a68e47cd9daf
Enrichment time
2026-09-11T21:24:03Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.