Security — Exploited & Patch Tuesday
KEV & Patch Tuesday
CISA's Known Exploited Vulnerabilities catalogue — 1,713 entries confirmed under attack in the real world — tracked against Microsoft's second-Tuesday release cadence. Sorted by what has a deadline attached, because a KEV listing you have already blown the date on is not a reading item.
was the previous second Tuesday, 9 days ago. CISA has added 18 vulnerabilities to the exploited catalogue since then, 2 of them Microsoft.
- CVE-2026-81963Windows
- CVE-2026-85880Windows
KEV is CISA's exploited-in-the-wild catalogue, not Microsoft's release manifest — this is what became known-exploited in the window, not the size of the patch drop. We do not have a source for the latter, so we do not print a number for it.
Vendor concentrationlast 90 days · 90 additions
Most recent additionsnewest 15
| CVE | Vendor / product | Vulnerability | Added | CISA due date |
|---|---|---|---|---|
| CVE-2026-58704 | GooglePixel | Google Pixel Improper Authorization Vulnerability | 19 Sep 20262d left | |
| CVE-2026-76460 | CiscoIdentity Services Engine | Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability | 19 Sep 20262d left | |
| CVE-2026-87886 | AcronisBackup | Acronis Backup Incorrect Default Permissions Vulnerability | 19 Sep 20262d left | |
| CVE-2026-76461 | CiscoSecure Email Gateway | Cisco Secure Email Gateway SQL Injection Vulnerability | 17 Sep 2026due today | |
| CVE-2026-42016 | JFrogArtifactory | JFrog Artifactory Incorrect Authorization Vulnerability | 25 Sep 20268d left | |
| CVE-2026-42018 | JFrogArtifactory | JFrog Artifactory Improper Authentication Vulnerability | 25 Sep 20268d left | |
| CVE-2026-84869 | ConnectWiseScreenConnect | ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability | 14 Sep 20263d overdue | |
| CVE-2026-85706 | GitLabCommunity Edition and Enterprise Edition | GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability | 14 Sep 20263d overdue | |
| CVE-2026-67277 | MikroTikRouterOS | MikroTik RouterOS Missing Authentication for Critical Function Vulnerability | 13 Sep 20264d overdue | |
| CVE-2026-86060 | MikroTikRouterOS | MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability | 13 Sep 20264d overdue | |
| CVE-2025-25249 | FortinetMultiple Products | Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability | 12 Sep 20265d overdue | |
| CVE-2026-19490 | CitrixNetScaler | Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability | 12 Sep 20265d overdue | |
| CVE-2026-20079 | CiscoSecure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management | Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability | 12 Sep 20265d overdue | |
| CVE-2026-87491 | GoogleChromium V8 | Google Chromium V8 Out of Bounds Write Vulnerability | 23 Sep 20266d left | |
| CVE-2026-75650 | AdobeCommerce and Magento | Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability | 11 Sep 20266d overdue |
Due dates are CISA's binding operational directive deadlines for federal civilian agencies. Everyone else should read them as the date the exploitation curve is expected to have peaked.