The September 2026 KEV wave as an operations dataset, not a news cycle
A single exploited vulnerability is an incident. Eleven additions to the CISA Known Exploited Vulnerabilities catalog inside one week is a pattern, and the pattern is more useful than any individual entry. Reading the late September 2026 batch together shows where attackers concentrate effort and where defender effort is spent badly.
What the batch contains
The late September additions include edge remote-access appliances, management planes and a popular web framework. Citrix NetScaler ADC and Gateway contributed two entries, CVE-2026-88771 and CVE-2026-88772, both rated 9.5 and both reachable without authentication. Cisco Catalyst SD-WAN Manager contributed CVE-2026-76504, an API session authentication bypass rated 9.8. Microsoft SharePoint contributed CVE-2026-65660, a code injection reachable by an authenticated low-privilege user. WordPress core contributed CVE-2026-87902, a remote file inclusion that reaches code execution. WSO2 API Manager contributed CVE-2026-5430, and Adobe Commerce and Magento contributed CVE-2026-71362.
What the composition says
The list is not a random sample of product categories. Edge appliances that terminate remote access, management consoles that control large estates, and middleware that sits in the API request path appear repeatedly. These systems share three properties: they are reachable from the internet, they hold credentials or policy for everything behind them, and they are patched on a maintenance window rather than on demand.
The patch gap is the recurring finding
At least one entry, CVE-2026-5430, had a fix available for months before exploitation was observed. That is not a research failure or a vendor failure. It is a scheduling and inventory failure, and it repeats because the tracking unit is usually the product version rather than the vendor's update level.
Turning the batch into an action list
Start with what is internet-facing and holds credentials. For each edge appliance, management console and API gateway in the estate, record the exact build, the vendor's fixed build, and whether the device needs downtime to update. Items that need downtime deserve a scheduled window before the next batch arrives, not after.
Then check for exploitation rather than assuming absence. A patch closes the hole but does not remove an attacker who arrived earlier, and recovery for the credential-holding systems in this batch means rotating what they can reach.
References
- CISA alert on Citrix NetScaler zero-days, 27 September 2026, https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway
- iThome reporting on the Catalyst SD-WAN Manager KEV addition, 1 October 2026, https://www.ithome.com.tw/news/179329
- Weekly security roundup, 2 October 2026, https://www.ithome.com.tw/news/179381
Top comments (0)