DEV Community

kozhevniko
kozhevniko

Posted on

The September 2026 KEV wave as an operations dataset, not a news cycle

The September 2026 KEV wave as an operations dataset, not a news cycle

A single exploited vulnerability is an incident. Eleven additions to the CISA Known Exploited Vulnerabilities catalog inside one week is a pattern, and the pattern is more useful than any individual entry. Reading the late September 2026 batch together shows where attackers concentrate effort and where defender effort is spent badly.

What the batch contains

The late September additions include edge remote-access appliances, management planes and a popular web framework. Citrix NetScaler ADC and Gateway contributed two entries, CVE-2026-88771 and CVE-2026-88772, both rated 9.5 and both reachable without authentication. Cisco Catalyst SD-WAN Manager contributed CVE-2026-76504, an API session authentication bypass rated 9.8. Microsoft SharePoint contributed CVE-2026-65660, a code injection reachable by an authenticated low-privilege user. WordPress core contributed CVE-2026-87902, a remote file inclusion that reaches code execution. WSO2 API Manager contributed CVE-2026-5430, and Adobe Commerce and Magento contributed CVE-2026-71362.

What the composition says

The list is not a random sample of product categories. Edge appliances that terminate remote access, management consoles that control large estates, and middleware that sits in the API request path appear repeatedly. These systems share three properties: they are reachable from the internet, they hold credentials or policy for everything behind them, and they are patched on a maintenance window rather than on demand.

The patch gap is the recurring finding

At least one entry, CVE-2026-5430, had a fix available for months before exploitation was observed. That is not a research failure or a vendor failure. It is a scheduling and inventory failure, and it repeats because the tracking unit is usually the product version rather than the vendor's update level.

Turning the batch into an action list

Start with what is internet-facing and holds credentials. For each edge appliance, management console and API gateway in the estate, record the exact build, the vendor's fixed build, and whether the device needs downtime to update. Items that need downtime deserve a scheduled window before the next batch arrives, not after.
Then check for exploitation rather than assuming absence. A patch closes the hole but does not remove an attacker who arrived earlier, and recovery for the credential-holding systems in this batch means rotating what they can reach.

References

Top comments (0)