Cisco warns of a maximum severity Identity Services Engine zero-day under active attack, while GitLab, SonicWall, and cPanel flaws stay hot on CISA KEV.
Cisco ISE flaw CVE-2026-76460 (CVSS 10) is being exploited unauthenticated and is now on the CISA KEV list. Google Pixel and Acronis Backup were added too.
CISA added a CVSS 10 Cisco Identity Services Engine flaw, an exploited Google Pixel zero-day, and an Acronis Backup bug to the KEV catalog on September 16.
Cisco patched an actively exploited Secure Email Gateway SQL injection (CVE-2026-76461, CVSS 9.8), now on CISA KEV, that lets attackers run commands as root.
CISA added Cisco Secure Email Gateway SQL injection CVE-2026-76461 to KEV on Sept 14, while ScreenConnect and JFrog Artifactory flaws see active exploitation.
ConnectWise patched a ScreenConnect flaw already exploited in worm-like attacks, while September Windows updates broke audio and RDS. Here is what to do first.
CISA added a max severity GitLab path traversal flaw and a 9.9 ScreenConnect bug to KEV on September 11, with GitLab exploited one day after disclosure.
CISA added two actively exploited MikroTik RouterOS flaws to KEV on Sept 10, while Cisco FMC CVE-2026-20079 draws ransomware and state-sponsored attacks.
CISA added a maximum severity Cisco Firewall Management Center authentication bypass to KEV, with ransomware and state-sponsored actors already exploiting it.
Microsoft shipped a record 974 CVEs with two exploited zero-days, and CISA added four KEV entries including a Windows and N-able N-central bug. Patch now.
Microsoft shipped a record 974 fixes with two exploited zero-days, CISA added four KEV entries, and Google patched its seventh Chrome zero-day of 2026.
September 2026 Patch Tuesday: Microsoft fixes 974 vulnerabilities, two exploited zero-days among them; Adobe patches a Magento zero-day used to backdoor sites.
CISA added ownCloud CVE-2023-49105, a Linux kernel flaw, and JFrog Artifactory to the KEV catalog on 2026-08-27, plus fresh Citrix NetScaler exploitation.
Citrix NetScaler CVE-2026-8452 is now exploited in the wild and on the CISA KEV list, alongside nine new KEV additions including an ownCloud auth bypass.
Microsoft fixed 751 CVEs across 67 updates in August 2026, 108 rated Critical, and one is already being exploited. What to patch first, and why.
Adobe ColdFusion path traversal CVE-2026-48282, CVSS 10 and CISA KEV listed, has EPSS 0.99. Plus SharePoint, Exchange, and a Zimbra campaign to check.
Microsoft SharePoint RCE CVE-2026-50522 (CVSS 9.8) is on the CISA KEV list alongside Adobe ColdFusion CVE-2026-48282 and two Exchange flaws. Patch these first.
Russian actors are exploiting an unpatched Zimbra zero-day against US and Ukraine targets while Adobe ColdFusion CVE-2026-48282 sits on CISA KEV at CVSS 10.
CISA added Check Point SmartConsole flaw CVE-2026-16232 (CVSS 9.1) to KEV after in-the-wild exploitation, alongside a SharePoint deserialization bug.
CISA added two WordPress Core flaws (CVE-2026-63030, CVE-2026-60137) to KEV on July 21 as wp2shell attacks install webshells.
Run 650+ Microsoft 365, Intune, Defender, Entra ID, and Purview security checks against a free demo tenant, no cost, no agents.
Get startedPatching across Intune, Windows Autopatch, Defender, Azure, and your endpoint managers: see Senserva patching in action.
Deep security commentary and research notes on Microsoft 365, Intune, Defender, Entra ID (logs included), patch state, CVEs, and Purview, plus behind-the-scenes posts on Senserva Trustworthy AI. Longer articles live on Substack: Senserva on Substack and Mark Shavlik's Substack.