Two MikroTik RouterOS flaws added to CISA KEV
CISA added two MikroTik RouterOS vulnerabilities to the Known Exploited Vulnerabilities catalog on 2026-09-10. CVE-2026-86060 is an improper neutralization of argument delimiters issue carrying a CVSS of 9.8, and CVE-2026-67277 is a missing authentication for critical function flaw at CVSS 8.2. Neither is currently flagged as ransomware-linked, but a KEV listing means confirmed in-the-wild exploitation. That is the line between patch eventually and patch now.
RouterOS runs on edge routers that often sit outside your normal Windows patch cadence, so these will not show up in Intune or Defender reporting. Inventory your MikroTik devices, apply vendor fixes, and confirm management interfaces are not exposed to the internet.
Cisco FMC authentication bypass under active attack
BleepingComputer reports that Cisco Firewall Management Center flaws are being exploited by a ransomware gang and state-sponsored hackers. That maps to CVE-2026-20079, the CVSS 10 authentication bypass that tops today's hot list with an EPSS of 0.76 and a KEV listing. Rapid7's latest Metasploit Wrap Up also includes CVE-2026-20079, which means exploit tooling is now widely available.
If you manage Cisco firewalls through FMC, treat this as an emergency patch and review the management plane for signs of unauthorized access.
Ransomware-linked movers to prioritize
Several other critical CVEs on the hot list are both KEV-listed and ransomware-linked, which should drive your patch order:
- CVE-2026-15409, SonicWall SMA1000 server-side request forgery, CVSS 10, EPSS 0.85
- CVE-2026-41940, WebPros cPanel and WHM missing authentication, CVSS 9.8, EPSS 0.99
- CVE-2026-59310, Broadcom VMware vCenter path traversal, CVSS 9.8
- CVE-2026-0257, Palo Alto Networks PAN-OS authentication bypass, CVSS 9.1, EPSS 0.95
- CVE-2026-35273, Oracle PeopleSoft PeopleTools missing authentication, CVSS 9.8
- CVE-2024-1708, ConnectWise ScreenConnect path traversal, still exploited, EPSS 0.95
- CVE-2025-55182, Meta React Server Components remote code execution, EPSS 0.998
What the trusted press adds
Check Point patched critical VPN vulnerabilities CVE-2026-85102 and CVE-2026-85103, covered by SecurityWeek and echoed in CERT-EU advisory 2026-012. GitLab is urging users to patch a maximum severity path traversal flaw, CVE-2026-85706. Both belong on this week's list if you run those products.
On the Microsoft side, BleepingComputer reports the September updates fix Teams and Outlook launch failures on ARM Windows PCs and resolve a mouse settings reset bug tied to update 5120998. Separately, SecurityWeek and Help Net Security detail AI-assisted attacks that exploited PaperCut flaws to breach 395 organizations, and Dark Reading describes voice callers abusing BYOD to reach Microsoft 365 data. Microsoft's own guidance on detecting AI-themed attacks and AI-assisted executive impersonation is worth reading for identity teams.
Do this first
Work top down by real-world risk, not just CVSS:
- Patch Cisco FMC for CVE-2026-20079 now given confirmed ransomware and state-sponsored exploitation.
- Inventory and patch MikroTik RouterOS for CVE-2026-86060 and CVE-2026-67277, both newly KEV-listed.
- Apply the Check Point and GitLab fixes for CVE-2026-85102, CVE-2026-85103, and CVE-2026-85706.
- Clear the ransomware-linked KEV set: SonicWall, cPanel, vCenter, PAN-OS, PeopleSoft, ScreenConnect, and React Server Components.
- Check your own Microsoft patch state. The free Microsoft Patch Tracker in Senserva ranks open patches by CISA KEV, EPSS, and ransomware linkage, and its non-Microsoft exploited-CVE tracker follows KEV additions daily. Siemserva also offers three free unlimited audits of your Microsoft 365, Intune, Defender, and Entra ID environment.
Sources
- CISA Cybersecurity Advisories: CISA Adds Two Known Exploited Vulnerabilities to Catalog (2026-09-10)
- BleepingComputer: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers (2026-09-10)
- Rapid7: Metasploit Wrap Up: This One Goes to Sixteen! (2026-09-11)
- SecurityWeek: Check Point Patches Critical VPN Vulnerabilities (2026-09-11)
- BleepingComputer: GitLab urges users to patch max severity path traversal flaw (2026-09-11)
- CERT-EU: 2026-012: Critical Vulnerabilities in Check Point Products (2026-09-10)
- BleepingComputer: Microsoft says September updates fix mouse settings reset issues (2026-09-10)
- BleepingComputer: Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs (2026-09-11)
- BleepingComputer: AI-powered attack exploited PaperCut flaws to hack 395 organizations (2026-09-10)
- Help Net Security: AI agents exploited PaperCut flaws to breach 395 organizations (2026-09-11)
Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-09-12.
Senserva is a Microsoft security company and a member of the Microsoft Intelligent Security Association. Senserva audits your Microsoft 365, Intune, Defender, and Entra ID environment: complete patch state, 650+ security checks, and full reports, with clear guidance on what to fix first.