Every week CISA adds vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalogue. The bar for getting on that list is not "severe on paper" but "attackers are using it now". For a small team with limited patching hours, that makes KEV the most useful priority list there is.
Below: every entry added between 28 September and 4 October 2026, copied from the catalogue and linked to its NVD record, plus what Romania's national cyber security directorate and Have I Been Pwned published in the same days. Nothing is estimated or rewritten.
The 6 actively exploited vulnerabilities added this week
| Added | Product | CVE | Known ransomware use |
|---|---|---|---|
| 4 Oct | Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability | CVE-2026-88779 | not known |
| 2 Oct | Zammad GmbH Zammad Improper Privilege Management Vulnerability | CVE-2026-102490 | not known |
| 2 Oct | Zammad GmbH Zammad Session Fixation Vulnerability | CVE-2026-102489 | not known |
| 1 Oct | Fortinet FortiMail Path Traversal Vulnerability | CVE-2026-104286 | not known |
| 30 Sep | Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability | CVE-2026-76504 | not known |
| 29 Sep | Apple Multiple Products Out-of-Bounds Write Vulnerability | CVE-2026-86950 | not known |
What Romania's DNSC flagged the same week
Alerts from DNSC, Romania's national cyber security directorate, with their original titles in Romanian:
- ALERTĂ: Vulnerabilitate critică la nivelul Fortinet FortiMail, 2 October
- ALERTĂ: Vulnerabilități critice exploatate activ în Citrix NetScaler, 28 September
When a national authority and CISA point at the same product in the same week, that product goes to the top of the queue.
Breaches added to Have I Been Pwned
- Medela: 423,947 accounts, added 30 September. Check the breach page
If your team's work addresses may be in one of these, check the breach page and the password reuse question, not only the address.
How to use a list like this in an hour
- Start with what faces the internet. VPN and access gateways, firewalls, routers, mail servers and public web platforms are how many ransomware incidents start.
- Search your inventory by product name, not by memory. "We don't run that" is a claim, and the asset list is the evidence.
- Patch or apply the vendor mitigation, then confirm the version. A patch that was downloaded but not applied reads as done in a ticket and is still exploitable.
- If you cannot patch today, reduce exposure: restrict the management interface to known addresses, disable the affected feature, or put the service behind an access gateway you trust.
Where this comes from
A small collector reads official sources every hour: DNSC, CERT-EU, CERT-FR (ANSSI), CERT-Bund (BSI), the UK NCSC, CISA KEV, Have I Been Pwned and three specialist newsrooms. It copies each item exactly, with its source link, and publishes the result on one page:
https://devaland.cloud/alerte-live.html (in Romanian, with every title kept in its original language).
Nothing on that page or in this post is written by a model. A security page that paraphrases an advisory wrongly does more harm than no page at all.
Sources: CISA KEV catalogue (dateAdded 2026-09-28 to 2026-10-04), DNSC alerts, Have I Been Pwned. Generated from the sources on 2026-10-05.
Top comments (0)