Cisa-Kev
CVE-2026-88771 & CVE-2026-88772: Unauthenticated RCE Zero-Days Hit Every NetScaler Deployment
Citrix confirms two NetScaler ADC/Gateway zero-days under active exploitation — one an unauthenticated command-execution bug present in every default configuration, the other a DTLS memory overflow enabled by default on VPN virtual servers.
CISA Adds SharePoint CVE-2026-65660 to KEV: SafeControls Bypass Enables Authenticated RCE
CISA confirmed active exploitation of CVE-2026-65660, a SharePoint code-injection bug that bypasses the SafeControls allowlist, letting a low-privilege authenticated user register arbitrary .NET classes and run code as the farm service account.
WordPress Core CVE-2026-87902: Unauthenticated Path Traversal to RCE via pearcmd, Exploited Within Hours
An unauthenticated path traversal bug in WordPress Core's page-template resolution (CVE-2026-87902) lets attackers include arbitrary PHP files and chain to RCE via pearcmd — mass scanning began within five hours of the patch, and CISA added it to KEV on September 25.
CVE-2026-71362: Unauthenticated Account Takeover Hits Adobe Commerce and Magento, Now on CISA KEV
CISA added CVE-2026-71362 to KEV after Sansec confirmed active exploitation. A session-identity bug lets an unauthenticated attacker hijack any customer's Adobe Commerce or Magento account — no credentials, no interaction.
CVE-2026-93952: Actively Exploited CVSS 10 Flaw Hands Attackers Privileged Access to Arista's VeloCloud Orchestrator
A maximum-severity input validation flaw in Arista's VeloCloud Orchestrator lets attackers who hold only the public half of an edge device's certificate reach privileged internal functionality on the SD-WAN control plane — and it's already being exploited in the wild.
CVE-2026-94127: F5 BIG-IP APM OAuth Heap Overflow Lets Attackers Skip Login Entirely and Hit RCE
F5 has patched CVE-2026-94127, a CVSS 9.8 heap-based buffer overflow in BIG-IP Access Policy Manager's OAuth handling that lets an unauthenticated attacker corrupt memory in the data-plane microkernel and execute code — already exploited in the wild and on CISA's KEV list as of September 22.
CISA Adds Three Linux Kernel Flaws to KEV: TLS Receive Path, ebtables SNAT, and AF_ALG Race Condition Under Active Exploitation
CISA added three Linux kernel CVEs to its Known Exploited Vulnerabilities catalog on evidence of in-the-wild exploitation — a CVSS 9.8 TLS receive-path flaw, an 8.8 ebtables SNAT out-of-bounds write, and a 7.8 AF_ALG race condition — with FCEB remediation due September 21.
CVE-2026-87886: Acronis Backup Plugin for cPanel and Plesk Exploited for Root on Shared Hosting
CVE-2026-87886 (CVSS 7.8) lets a low-privileged local user escalate to root on cPanel, WHM, Plesk, and DirectAdmin hosts via world-writable files left behind by Acronis's backup plugin — already exploited in targeted attacks and added to CISA KEV with a September 19 federal deadline.
CVE-2026-76460: Maximum-Severity Cisco ISE Auth Bypass Exploited Before Disclosure
CVE-2026-76460 (CVSS 10.0) lets unauthenticated attackers bypass Cisco ISE's web management entirely via a privileged API endpoint and get root — Cisco found it while cleaning up a customer who was already compromised, and CISA added it to KEV within a day.
Three Strikes: How Cisco's Firewall Brain Became Everyone's Favorite Target
In 2026, Cisco Secure FMC took three separate maximum-severity zero-days — and the third one put a Russian APT and a ransomware affiliate on the same box, in the same weeks, running the same playbook. That convergence is the story, not the CVE.
CVE-2026-20079: CVSS 10 Auth Bypass in Cisco Secure FMC Exploited by Sandworm and Qilin Ransomware
A maximum-severity authentication bypass in Cisco Secure Firewall Management Center gives unauthenticated attackers root — Talos has tied active exploitation to Russia's Sandworm and to Qilin ransomware affiliates, and CISA's KEV deadline lands today.
CVE-2026-85706: Unauthenticated CVSS 10 Path Traversal in GitLab's Commits API Under Active Probing
A maximum-severity, unauthenticated path traversal in GitLab's repository commits API lets attackers read arbitrary server files; CISA added it to KEV and honeypots logged probing within hours of the patch.
N-able Ships Fourth N-central Hotfix in Five Weeks After CVE-2026-86218 Pre-Auth RCE Hits Production
CVE-2026-86218, a maximum-severity static code injection flaw in N-able's N-central RMM platform, let unauthenticated attackers run arbitrary code on the server — and CISA confirms it was already exploited before the patch shipped.
CVE-2026-9586: Unauthenticated SQLi-to-RCE in Sangoma Switchvox Under Active Exploitation
An unauthenticated SQL injection in Sangoma Switchvox's phone-provisioning endpoint escalates to root command execution and is now being used in the wild to plant reverse shells on internet-exposed VoIP servers.
Cisco Nexus 9000 CVE-2026-20212: Unauthenticated Root RCE on Silicon One Data Center Switches
A CVSS 9.8 flaw lets unauthenticated attackers execute code as root on Cisco Nexus 9000 switches with Silicon One ASICs by reaching two hard-coded, unrestricted TCP ports.
CVE-2026-49869: Kestra OSS Auth-Bypass Lets Unauthenticated Attackers Get Root RCE, CISA Sets Today as Federal Deadline
A suffix-match flaw in Kestra OSS's AuthenticationFilter lets anyone skip Basic Auth entirely and reach unauthenticated remote code execution as root, CVSS 10.0, now on CISA's KEV list.
CVE-2026-83548 & CVE-2026-83549: SonicWall SMA1000 Hit by Third Zero-Day Chain of 2026, CVSS 10.0 SSRF to Root RCE
SonicWall SMA1000 appliances are under active exploitation via a chained SSRF and OS command injection pair, CVE-2026-83548 and CVE-2026-83549, the product line's third zero-day incident this year.
CVE-2026-82329: Critical JFrog Artifactory Auth Bypass Under Active Exploitation for Admin Tokens
Attackers are exploiting CVE-2026-82329, a CVSS 9.8 authentication bypass in JFrog Artifactory, to mint themselves administrator tokens and enumerate credentials on internet-facing build-artifact repositories.
CVE-2026-8452: 'DoS-Only' NetScaler Flaw Turns Out to Be Pre-Auth Root RCE, Now Under Active Exploitation
watchTowr Labs turned a Citrix NetScaler bug Citrix rated as a crash-only memory overflow into pre-auth root code execution; CISA confirms in-the-wild exploitation with web shells on unpatched appliances.
PaperCut Ships Emergency Out-of-Cycle Build After Zero-Day Hits Every Supported NG/MF Version
PaperCut confirmed active zero-day exploitation of an unpatched flaw affecting every currently supported PaperCut NG/MF release and shipped emergency out-of-cycle builds hours after a university's forensics team caught it in the wild.