DEV Community

Cover image for Actively exploited this week: 6 new CISA KEV entries (28 September to 4 October 2026)
DEVALAND
DEVALAND

Posted on

Actively exploited this week: 6 new CISA KEV entries (28 September to 4 October 2026)

Every week CISA adds vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalogue. The bar for getting on that list is not "severe on paper" but "attackers are using it now". For a small team with limited patching hours, that makes KEV the most useful priority list there is.

Below: every entry added between 28 September and 4 October 2026, copied from the catalogue and linked to its NVD record, plus what Romania's national cyber security directorate and Have I Been Pwned published in the same days. Nothing is estimated or rewritten.

The 6 actively exploited vulnerabilities added this week

Added Product CVE Known ransomware use
4 Oct Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability CVE-2026-88779 not known
2 Oct Zammad GmbH Zammad Improper Privilege Management Vulnerability CVE-2026-102490 not known
2 Oct Zammad GmbH Zammad Session Fixation Vulnerability CVE-2026-102489 not known
1 Oct Fortinet FortiMail Path Traversal Vulnerability CVE-2026-104286 not known
30 Sep Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability CVE-2026-76504 not known
29 Sep Apple Multiple Products Out-of-Bounds Write Vulnerability CVE-2026-86950 not known

What Romania's DNSC flagged the same week

Alerts from DNSC, Romania's national cyber security directorate, with their original titles in Romanian:

When a national authority and CISA point at the same product in the same week, that product goes to the top of the queue.

Breaches added to Have I Been Pwned

If your team's work addresses may be in one of these, check the breach page and the password reuse question, not only the address.

How to use a list like this in an hour

  1. Start with what faces the internet. VPN and access gateways, firewalls, routers, mail servers and public web platforms are how many ransomware incidents start.
  2. Search your inventory by product name, not by memory. "We don't run that" is a claim, and the asset list is the evidence.
  3. Patch or apply the vendor mitigation, then confirm the version. A patch that was downloaded but not applied reads as done in a ticket and is still exploitable.
  4. If you cannot patch today, reduce exposure: restrict the management interface to known addresses, disable the affected feature, or put the service behind an access gateway you trust.

Where this comes from

A small collector reads official sources every hour: DNSC, CERT-EU, CERT-FR (ANSSI), CERT-Bund (BSI), the UK NCSC, CISA KEV, Have I Been Pwned and three specialist newsrooms. It copies each item exactly, with its source link, and publishes the result on one page:

https://devaland.cloud/alerte-live.html (in Romanian, with every title kept in its original language).

Nothing on that page or in this post is written by a model. A security page that paraphrases an advisory wrongly does more harm than no page at all.

Sources: CISA KEV catalogue (dateAdded 2026-09-28 to 2026-10-04), DNSC alerts, Have I Been Pwned. Generated from the sources on 2026-10-05.

Top comments (0)