The September 2026 KEV wave as an operations dataset, not a news cycle
The September 2026 KEV wave as an operations dataset, not a news cycle A single exploited vulnerability is an incident. Eleven additions to the CISA Known Exploited Vulnerabilities catalog inside one week is a pattern, and the pattern is more useful than any individual entry. Reading the late September 2026 batch together shows where attackers concentrate effort and where defender effort is spent…
In late September 2026, a wave of exploited vulnerabilities was added to the CISA Known Exploited Vulnerabilities catalog. This collection of security flaws offers valuable insights into where attackers focus their efforts and where defenders may be falling short. The batch includes vulnerabilities in edge remote-access appliances, management planes, and a widely-used web framework.
Citrix's NetScaler ADC and Gateway were affected by two CVEs, both rated 9.5 and exploitable without authentication. Cisco's Catalyst SD-WAN Manager had a CVE-2026-76504 with a 9.8 rating, resulting from an API session authentication bypass. Microsoft SharePoint contributed CVE-2026-65660, a code injection issue accessible by an authenticated low-privileged user.
WordPress core included CVE-2026-87902, a remote file inclusion vulnerability leading to code execution. WSO2 API Manager and Adobe Commerce and Magento contributed CVE-2026-5430 and CVE-2026-71362, respectively. The pattern emerging from this batch suggests that edge appliances terminating remote access, management consoles controlling large estates, and middleware sitting in the API request path are particularly vulnerable.
These systems are reachable from the internet, hold credentials or policy for everything behind them, and are typically patched during scheduled maintenance windows rather than on demand. The recurring issue is the patch gap - in at least one case, a fix was available for months before exploitation was observed. This failure stems from a scheduling and inventory issue, where the tracking unit is usually the product version rather than the vendor's update level.
Converting this batch of vulnerabilities into an actionable strategy starts with identifying internet-facing systems that hold credentials. For each edge appliance, management console, and API gateway, record the exact build, the vendor's fixed build, and whether an update requires downtime. Systems requiring downtime should be scheduled before the next batch of vulnerabilities, rather than after.
Additionally, checking for exploitation rather than assuming absence is crucial. While a patch closes the vulnerability, it does not necessarily remove an attacker who may have already gained access. Recovering affected systems involves rotating credentials to prevent further unauthorized access.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.