{
  "id": 8552878,
  "title": "From KEV to Exposure: Mapping the September 2026 Batch to Measurable Services",
  "url": "https://urgent.news/2026/09/19/from-kev-to-exposure-mapping-the-september-2026-batch-to-measurable",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-19T22:40:13.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/kozhevniko/from-kev-to-exposure-mapping-the-september-2026-batch-to-measurable-services-4nco"
  },
  "original_language": "en",
  "account": "Mapping the September 2026 KEV Batch to Measurable Services The September 2026 KEV additions highlight vulnerabilities affecting internet-reachable services holding credentials or controlling other systems. CVE-2026-85706 is an unauthenticated file read in GitLab's repository commits API, CVE-2026-20079 is a pre-authentication bypass in Cisco Secure Firewall Management Center, CVE-2026-59822 is an authentication bypass in BerriAI LiteLLM's MCP Streamable HTTP endpoint, and CVE-2026-56164 is a remotely exploitable authentication bypass in Microsoft SharePoint. The CISA Known Exploited Vulnerabilities catalog provides a reference for these flaws, which are not necessarily exposed in a given environment. Internet measurement aids in bridging the gap between known exploits and actual exposure. ZoomEye queries on September 19, 2026, revealed 1,262,273 matches for GitLab in the IPv4 device dataset and 52,074 in the web dataset. LiteLLM had 34,402 matches in the IPv4 device dataset. The Cisco Secure Firewall Management Center showed no matches, with a single page title query returning 1. GitLab and LiteLLM are highly fingerprintable, making their large populations observable. Conversely, the Cisco FMC, being a management console, presents little identifying content, resulting in minimal fingerprinting results. The bridge between KEV and measurable services involves identifying affected services in your estate and assessing reachability. For fingerprintable services like GitLab and LiteLLM, external and internal records can be reconciled to determine which systems are externally reachable but not internally patched. Management planes like FMC require internal records and discovery due to their unreliable external visibility. ZoomEye's attack surface management capability continuously discovers assets, surfacing previously unregistered systems. Windows zero-days from the September 2026 update pose risks due to their elevation of privilege in critical components. The numbers from measurement do not indicate the actual number of compromised systems or distinguish between deliberately published or accidentally exposed services. In summary, the KEV catalog identifies attacker-focused vulnerabilities, while measurement helps close the gap for fingerprintable services, demonstrating the limitations of passive scanning for management planes.",
  "summary": "From KEV to Exposure: Mapping the September 2026 Batch to Measurable Services The CISA Known Exploited Vulnerabilities catalog is a list of flaws that have been exploited in the wild. It is not a list of what is exposed in a given environment. Bridging those two things is the useful step, and internet measurement is one of the inputs that makes the bridge concrete. The September 2026 KEV…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}