DEV Community

Gary Austin
Gary Austin

Posted on Originally published at thesecuritygator.hashnode.dev

Twenty Got Three Days, Eight Got Fourteen: CISA's KEV Due Date Is the Free Sort Key Nobody Reads

Twenty got three days. Eight got fourteen. Your patch queue's sort key was already free — and it's a date.

CISA's Known Exploited Vulnerabilities catalog publishes no CVSS score. Not for any entry, not ever. What it publishes is a dueDate — one per flaw — and in the first half of September 2026 that single field sorted twenty-eight CVEs into two piles with nothing in between. All ten security and remote-management products landed in the short pile. Here is how to read the field, why a Cisco-rated 10.0 and an Acronis-rated 7.8 drew the same deadline, and the one-afternoon inventory that turns it into a queue.


I pulled the catalog on September 18, 2026. It is a public JSON file — no account, no vendor, no scanner:

https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Enter fullscreen mode Exit fullscreen mode

catalogVersion 2026.09.18 · dateReleased 2026-09-18T13:49:41.7236Z · 1,715 entries in the catalog · 28 of them added since September 1.

Open one entry: CVE ID, vendor, product, vulnerability name, dateAdded, dueDate, knownRansomwareCampaignUse, CWEs, a required action, notes.

Now notice the absence. There is no CVSS field. CISA publishes no severity score in KEV — not a base score, not a vector, nothing. Every CVSS number you have seen sitting next to a KEV entry came from a vendor or from NVD, and somebody else put it there.

What CISA publishes instead is a date.

Twenty got three days. Eight got fourteen. There is no middle.

Subtract dateAdded from dueDate across September's twenty-eight entries and the month falls into exactly two buckets.

Three days — 20 CVEs. Linux Kernel ×2 (CVE-2025-39964, CVE-2026-53266) · Google Pixel (CVE-2026-58704) · Cisco Identity Services Engine (CVE-2026-76460) · Acronis Backup (CVE-2026-87886) · Cisco Secure Email Gateway (CVE-2026-76461) · ConnectWise ScreenConnect (CVE-2026-84869) · GitLab CE/EE (CVE-2026-85706) · MikroTik RouterOS ×2 (CVE-2026-86060, CVE-2026-67277) · Citrix NetScaler (CVE-2026-19490) · Fortinet Multiple Products (CVE-2025-25249) · Cisco Secure Firewall Management Center (CVE-2026-20079) · Adobe Commerce and Magento (CVE-2026-75650) · N-able N-central (CVE-2026-86218) · Kestra OSS (CVE-2026-49869) · JFrog Artifactory (CVE-2026-82329) · Sangoma Switchvox (CVE-2026-9586) · SonicWall SMA1000 ×2 (CVE-2026-83548, CVE-2026-83549)

Fourteen days — 8 CVEs. JFrog Artifactory ×2 (CVE-2026-42016, CVE-2026-42018) · Google Chromium V8 ×2 (CVE-2026-87491, CVE-2026-85046) · Microsoft Windows ×2 (CVE-2026-81963, CVE-2026-85880) · BerriAI LiteLLM (CVE-2026-59822) · Kludex Starlette (CVE-2026-48710)

20 + 8 = 28. No sevens, no twenty-ones, no thirties. Two values and a hard edge between them, which is what a decision looks like once it lands in a data structure. Somebody read each entry and put it in a pile.

One more fact about all twenty-eight, because it is the field people reach for when they want to feel urgency: every September entry carries knownRansomwareCampaignUse: "Unknown". The scary column is blank on the whole month. The date still says three days on twenty of them.

The honest part, before you take this anywhere

BOD 26-04 deadlines are compulsory for Federal Civilian Executive Branch agencies only. They do not bind your company, your MSP, or your clients. Not a little, not implicitly, not "as a best practice." That distinction gets flattened constantly, usually by someone with something to sell — and the flattened version is worthless anyway: "patch within three days or you're non-compliant" describes no obligation a private company actually has. Binding for federal civilian agencies; free for everyone else to copy. Copy the signal, not a claim of compliance.

The field comes from BOD 26-04, Prioritizing Security Updates Based on Risk, issued June 10, 2026, which sets remediation urgency from exposure, KEV status, exploit automation and technical impact. You do not have to adopt the directive to use its output: the dueDate is that four-variable model already run, already published, already free, shipping in the same file as the CVE ID.

The ten — and what they have in common

Ten of September's twenty-eight are security or remote-management products, defined tightly enough to be auditable: products whose purpose is to secure, authenticate, protect, back up, or remotely manage other systems.

# Product CVE Added Due
1 Cisco Identity Services Engine CVE-2026-76460 09-16 09-19
2 Acronis Backup CVE-2026-87886 09-16 09-19
3 Cisco Secure Email Gateway CVE-2026-76461 09-14 09-17
4 ConnectWise ScreenConnect CVE-2026-84869 09-11 09-14
5 Citrix NetScaler CVE-2026-19490 09-09 09-12
6 Fortinet (Multiple Products) CVE-2025-25249 09-09 09-12
7 Cisco Secure Firewall Management Center CVE-2026-20079 09-09 09-12
8 N-able N-central CVE-2026-86218 09-08 09-11
9 SonicWall SMA1000 Appliances CVE-2026-83548 09-02 09-05
10 SonicWall SMA1000 Appliances CVE-2026-83549 09-02 09-05

Every one: three days. Not one of them got fourteen.

State the boundary out loud, because a category you cannot audit is a statistic you cannot trust. MikroTik RouterOS appears twice in the three-day pile and is excluded here as general networking rather than security tooling; count it in and the number is twelve. The claim is ten, under that definition, checkable against the feed in about a minute.

Then read the list again and notice what it is. That is not a software inventory. It is an org chart of a security program — the box that decides who gets on the network, the box that filters the mail, the box that manages the firewall, the box that holds the backups, and the two boxes that reach every machine you own.

Contrast one: Cisco's 10.0 and Acronis's 7.8 drew the same three days

Cisco Identity Services Engine, CVE-2026-76460. Added September 16, due September 19, CWE-648 Incorrect Use of Privileged APIs. Cisco's own advisory scores it 10.0 — Cisco's number; CISA publishes no CVSS score in KEV. It was a zero-day, and Cisco PSIRT states it is aware of active exploitation. A remote, unauthenticated attacker bypasses authentication with crafted requests to an API endpoint that does not apply sufficient authentication controls, and successful exploitation can execute commands with root privileges — which includes hiding or deleting the indicators that anyone was ever there. It affects Cisco ISE and ISE-PIC regardless of device configuration. Fixed in 3.5 Patch 4, 3.4 Patch 7, 3.3 Patch 12, 3.2 Patch 11 and 3.1 Patch 12.

That is the appliance that decides who is allowed onto the network. Root on it means the system of record for who got in becomes a system the intruder controls.

Acronis Backup, CVE-2026-87886. Added the same day, due the same day. CWE-276 Incorrect Default Permissions. Acronis rates it 7.8 — Acronis's number, again not CISA's. Acronis describes it as a local privilege escalation from insecure file permissions, requiring an attacker to already hold authenticated, low-privileged local access to the Linux server. It affects the Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, the extension for Plesk (Linux) before 1.8.11.638, and the plugin for DirectAdmin (Linux) before 1.2.3.238. Acronis confirmed exploitation observed in the wild against the cPanel & WHM plugin.

So: Cisco's 10.0 — remote, unauthenticated, root. And Acronis's 7.8 — local, foothold required first. A 2.2-point spread, two entirely different threat models, and the same deadline to the day.

The scores are not wrong. They answer a different question. Severity asks what could happen; the deadline asks whether somebody is doing it. One of those is a continuum two databases can argue about. The other is a yes or a no, and it changes when you wake up tomorrow. Only one is a sort key.

Contrast two: the browser waited, the backup plugin did not

Google Chromium V8 out-of-bounds write, CVE-2026-87491, added September 9 — fourteen days. The rendering engine on effectively every desktop you own.

Acronis Backup local privilege escalation, CVE-2026-87886, added September 16 — three days. A plugin on a control panel, needing an attacker already authenticated on the box.

Rank those two by instinct and most people invert them. Instinct ranks blast radius. The field ranks evidence.

The MSP item: two management platforms, three days apart

N-able N-central, CVE-2026-86218 — added September 8, due September 11, CWE-96 Static Code Injection. We took that one apart last week; here it is the second data point.

ConnectWise ScreenConnect, CVE-2026-84869 — added September 11, due September 14, CWE-269 Improper Privilege Management plus CWE-862 Missing Authorization. It affects the ScreenConnect client prior to 26.6.5: missing authorization controls allow file transfer and execution through an active remote session without host confirmation. Huntress reported it exploited in the wild since August 20, 2026 — roughly three weeks before it reached the catalog. The behaviour Huntress reported was worm-like: a modified ScreenConnect instance deployed four VBScript files for persistence and propagation to other ScreenConnect clients. The fix is 26.6.5 or later; ConnectWise's interim mitigation is to disable TransferFiles permissions.

I have deliberately not quoted a CVSS figure for either. The week's argument is that the date outranks the score, and the paragraph is stronger without a number in it.

Two remote-management platforms, three days apart, both in the three-day pile. If you run one, that console reaches every endpoint in your book of business — row one on the asset list, not a footnote under "tools." If you buy from someone who runs one: which management platforms reach your estate, are they internet-facing, and when were they last patched? Ask in writing. Keep the answer with a date on it.

The mail gateway, and what a zero-day looks like in the record

Cisco Secure Email Gateway, CVE-2026-76461 — added September 14, due September 17, CWE-89 SQL Injection. Cisco's advisory published on September 14, the same day CISA added it to KEV. That is what "exploited before disclosure" looks like read off a timeline instead of a press release: the vendor's first public word and the catalog entry land together, because the exploitation came first and the paperwork caught up.

Unauthenticated, no user interaction. A crafted email passing through the gateway carries SQL statements, and exploitation can reach root command execution on the underlying OS. Affects AsyncOS 16.5, 16.0, and 15.5 and earlier, on-premises physical and virtual appliances. Fixed in AsyncOS 15.5.5-0141, 16.0.4-3021 and 16.5.0-780. No workaround — meaning the mitigation column on your tracker reads "upgrade" and nothing else, which is worth knowing before the maintenance-window conversation rather than during it.

How to read the due date yourself

Three fields do all the work.

product      → what you search on. NOT the score.
dateAdded    → the day CISA published the entry.
dueDate      → the deadline it carries.

dueDate − dateAdded = CISA's urgency verdict, as an integer.
Enter fullscreen mode Exit fullscreen mode

All three are free and account-free: the JSON feed above; a CSV at the same path with a .csv extension, if you would rather open it in a spreadsheet; and the browsable catalog at cisa.gov/known-exploited-vulnerabilities-catalog. Pull the file, filter entries on product against the names on your own list, and for every hit subtract. A 3 means CISA set a three-day remediation window; a 14 means fourteen. Both are in the catalog because exploitation was observed — the integer is urgency, not evidence.

Search by product, never by score. Most teams get this backwards, and it is the difference between a five-minute answer and an afternoon reconciling severity numbers two databases disagree about. You are not asking "how bad is this CVE." You are asking "is anything I own in this file, and what integer did it get." Product name in, integer out — and read the version off the host, not off the management dashboard, because dashboards report what they were last told and appliances get rebooted, restored and half-upgraded.

The list you have to build first, because you probably don't have it

You cannot filter a feed against a list you never wrote down, and the list this month demands is the one almost nobody has — not the servers, not the laptops, but the tools doing the protecting, including the vendor consoles you neither host nor patch.

Those tools sit in a structural blind spot, and it is the same one every time: excluded from the vulnerability scan because they are the security stack, patched on the vendor's cadence rather than yours, owned by "whoever set it up," and frequently the only boxes in the building with no named human on them. That is precisely the population that went ten-for-ten into the three-day pile this month.

So the afternoon runs in three passes:

  1. Enumerate the security and management stack. One row per product: vendor, product, version read off the host, where it is reachable from, and a named human — not a team, not a mailbox, not someone who left.
  2. Filter the KEV feed on product for every name on that list.
  3. For every hit, record dateAdded, dueDate and the integer between them — then inherit the integer as your own priority order. Federal civilian agencies are bound by that date; you are voluntarily copying homework somebody published for free. Where no fix exists yet, write the actual mitigation in the row: restrict source addresses, take the interface off the internet, disable the feature. "Waiting on the vendor" is a status, not a control.

The artifact is the point

The rule carries over from every review in this series: every claim gets a number and a date.

"We're on top of patching" is a mood. Something shaped like "23 security and management products inventoried Sep 18; 4 matched KEV by product; 3 patched, 1 mitigated by source restriction pending vendor fix; versions read off-host; owner named on every row; next pass Dec 18" is an artifact — and it is the shape of answer that cyber-insurance applications and client security questionnaires keep asking for.

The re-ranking itself costs nothing. It is a change of sort order, not a change of budget, which makes it the cheapest item on any security roadmap this quarter.

The severity number is a judgement two authorities can disagree about. The due date is CISA's verdict on whether the thing is currently being used against people: published in a free file, updated as new exploitation is confirmed, expressed as an integer you can subtract in your head.

The sort key was already free. And it's a date.


The kit is free. The Security Stack Kit (Gatorbyte #014) is this afternoon on paper: the inventory of the tools doing the protecting, the version-read-off-host column, the KEV cross-check by product, the dateAdded / dueDate / days-between fields, and the named-owner column that makes a row survive triage. It supports vulnerability-management and audit-preparation workflows — a practical starting point to review and adapt for your organization; not legal, compliance, or audit advice. Kits are free to use inside your organization and with your clients, including in paid engagements — thesecuritygator.gumroad.com/l/gb014-security-stack-kit

CISA Binding Operational Directive deadlines are compulsory only for the Federal Civilian Executive Branch agencies BOD 26-04 names. Nothing here creates an obligation on a private organization, and nothing here substitutes for managed security, penetration testing, or incident-response services.

Sources: CISA KEV catalog · KEV JSON feed, catalogVersion 2026.09.18, read 2026-09-18 · CISA KEV addition alerts, 2026-09-02, 09-09, 09-14 and 09-16 · Cisco security advisories for CVE-2026-76460 and CVE-2026-76461 · ConnectWise advisory for CVE-2026-84869 · Acronis advisory for CVE-2026-87886 · CISA BOD 26-04 — "Prioritizing Security Updates Based on Risk"

A note on the scores, because it is the article's premise: the KEV catalog contains no CVSS field. The 10.0 is Cisco's, from Cisco's own advisory; the 7.8 is Acronis's. Trade coverage carries CVSS figures for the Cisco Secure Email Gateway and ConnectWise ScreenConnect flaws too — omitted here on purpose, because a piece arguing that the date outranks the score should not lean on the score. No figure here is CISA's. CISA publishes none.

Top comments (0)