The busiest month for exploited vulnerabilities in four years.
Between September 1 and 29, the Cybersecurity and Infrastructure Security Agency (CISA) added 42 vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, the most in any month since June 2022. By CISA's own descriptions, at least 20 of them need no credentials to exploit, and more than half of those give the attacker code execution or administrative control. Federal agencies got three days to fix 34 of the 42, and 18 were listed within a day of their Common Vulnerabilities and Exposures (CVE) record going public.
In ZEST customer environments, 13 of the 42 appeared, and eight of those were already there before CISA listed them, including two Linux kernel bugs first reported about a year earlier.

The vulnerabilities that mattered
The Exploit Prediction Scoring System (EPSS) rated most of them unlikely to be exploited. Each vulnerability below carries its Common Vulnerability Scoring System (CVSS) rating and its EPSS value, the estimated chance of exploitation in the next 30 days, as of September 30. All 42 are confirmed exploited, yet EPSS put 30 of them below 10% and eight below 1%. Network appliances led the list with 17 of the 42.
- Chrome and Windows chain: one click was enough.
A V8 type confusion (CVE-2026-85046, CVSS 8.8, EPSS 49%) and a WebAssembly flaw (CVE-2026-87491, CVSS 8.8, EPSS 3.1%) run attacker code in Chrome's renderer, and a Windows kernel heap overflow (CVE-2026-85880, CVSS 7.8, EPSS 3.6%) breaks it out of the sandbox. The V8 fixes were public in Chromium's source code before Chrome shipped them, and Volexity assesses with medium confidence that an exploit developer reverse-engineered them. Proofpoint saw APT31 use the chain on August 28, Volexity found three Chinese groups on it by September 4, and all three flaws turned up in ZEST customer environments. - Citrix NetScaler: both zero-days were exploited before the fix, so check for compromise and preserve evidence, then patch at once.
One gives unauthenticated command execution on any customer-managed deployment, default configuration included, with no workaround (CVE-2026-88771, CVSS 9.5, EPSS 1.1%). The other is a memory overflow reachable before login through DTLS, which is on by default for VPN virtual servers (CVE-2026-88772, CVSS 9.5, EPSS 1.3%). Mandiant traced attacks on it to at least early September, saw root access followed by web shells and, in at least one intrusion, credential theft, and offers a stopgap, disabling DTLS and restricting inbound UDP 443, that does nothing for the first flaw. CISA listed both on Sunday, September 27, the day Citrix disclosed them, and encouraged operators to check for compromise before patching, because updates can cost forensic visibility. - Check Point and Cisco: five flaws in security products themselves, none needing a login.
A path traversal in Check Point's management web service lets an attacker upload and run scripts (CVE-2026-93616, CVSS 9.8, EPSS 20%), and Check Point saw targeted attacks on July 23, two months before the fix. Its VPN gateways have a certificate validation flaw that gives code execution (CVE-2026-85102, CVSS 9.8, EPSS 7.5%). Cisco's Firewall Management Center has an authentication bypass, first disclosed in March, that gives root (CVE-2026-20079, CVSS 10, EPSS 88%), and Talos saw two clusters use it to steal credentials and managed-device configurations. Cisco found an Identity Services Engine flaw that bypasses the web management interface while resolving a support case (CVE-2026-76460, CVSS 10, EPSS 14%), and a SQL injection in its Secure Email Gateway runs commands as root (CVE-2026-76461, CVSS 9.8, EPSS 28%). - F5, SonicWall and MikroTik: edge devices that can be taken over without a login.
F5 BIG-IP APM has a heap overflow that gives code execution, but only where an access policy and an OAuth profile share a virtual server (CVE-2026-94127, CVSS 9.8, EPSS 2.2%), and CISA points to F5's iRule as a temporary mitigation. On SonicWall SMA1000, a request forgery (CVE-2026-83548, CVSS 10, EPSS 8.8%) reaches an administrator-only command injection (CVE-2026-83549, CVSS 7.8, EPSS 11%), so the pair can run commands without a login, and both were exploited before disclosure on September 1. On MikroTik RouterOS, an SSH exec request (CVE-2026-67279, CVSS 6.9, EPSS 1.0%) chained with a policy-mask injection (CVE-2026-86060, CVSS 9.2, EPSS 1.8%) gives full control of routers reachable over SSH, and attackers were using it at least a day before the fixes in 7.24.2, 7.23.4 and 6.49.21. - GitLab and JFrog Artifactory: the systems that build your software are on the list.
A path traversal in GitLab's repository commits API lets an unauthenticated user read arbitrary files from a self-managed server under certain conditions (CVE-2026-85706, CVSS 10, EPSS 91%). The fix shipped for 19.1 to 19.3 on September 10 and reached 19.0 and 18.11 only on September 23. A default self-hosted Artifactory trusts an empty cluster join key, so an anonymous attacker can mint an administrator token with one request, then read stored credentials and tamper with the packages that builds pull (CVE-2026-82329, CVSS 9.8, EPSS 14%). Fastly counted about 406,000 attempts across its network on September 2, the peak day. - LiteLLM and Starlette: the AI gateway stack, and both were in ZEST customer environments.
A fallback in LiteLLM's Model Context Protocol (MCP) authentication accepted any bearer token, letting an attacker list and call the MCP tools behind the gateway (CVE-2026-59822, CVSS 8.8, EPSS 0.8%). It is the only catalog entry that mentions MCP, and it is fixed in 1.84.0, with blocking /mcp/ and related MCP endpoints as the stopgap. Starlette's request-smuggling flaw bypasses authentication tied to the reconstructed URL path (CVE-2026-48710, CVSS 6.5, EPSS 7.1%), and CISA says it can be chained with a LiteLLM command injection it listed in June. - ScreenConnect and N-central: remote management tools reach every machine they manage.
The ConnectWise ScreenConnect flaw can let files be pushed and run through an active session without the host's confirmation (CVE-2026-84869, CVSS 9.9, EPSS 0.9%). Huntress says three late August intrusions, in which rogue installs spread between machines, align with it, though ConnectWise has not confirmed the link. N-able's N-central has a code injection that gives remote code execution on the server before authentication (CVE-2026-86218, CVSS 10, EPSS 13%), fixed in 2026.3 Hotfix 4 on September 6 and listed by CISA two days later. - Web platforms: three of the five were patched weeks or months before CISA listed them.
WordPress core has an unauthenticated file inclusion (CVE-2026-87902, CVSS 8.1, EPSS 20%) that becomes code execution only when the active theme has a top-level directory whose name starts with page-, as Twenty Twelve, Neve and Hestia do, and the server has a PHP file the attacker can abuse, typically PEAR's pearcmd.php with register_argc_argv on, as in the official PHP Docker image. It was probed the day 7.1.2 fixed it. SharePoint's code injection needs an authorized user (CVE-2026-65660, CVSS 8.8, EPSS 2.1%), and Microsoft patched it on August 11 as a spoofing bug rated 6.5, re-rated it as remote code execution on August 27 and confirmed attacks on September 25. Adobe Commerce has the StyleSmuggler template injection that Sansec caught being exploited three days before the hotfix (CVE-2026-75650, CVSS 10, EPSS 3.9%) and an authorization flaw patched on August 11 (CVE-2026-71362, CVSS 9.1, EPSS 88%). In WSO2 API Manager, the vendor's advisory says JWT authentication can be bypassed with a token signed using an unsupported algorithm (CVE-2026-5430, CVSS 10, EPSS 0.6%), where CISA's summary describes a file upload flaw, and the fix dates from May 3.
How they were found, and where AI fits
Many of the zero-days were found in the field. Where discovery has been described, the Cisco Identity Services Engine, Adobe Commerce and NetScaler DTLS flaws surfaced during an attack or a support case. Apple's CoreGraphics zero-day (CVE-2026-86950, CVSS 8.8, EPSS 1.2%) came from Meta's security team, and the Chrome bugs from two researchers' early August reports.
AI helped find some of them. Poland's CERT says its researcher found the MikroTik RouterOS flaws using OpenAI's GPT-5.5-cyber and GPT-5.6-sol models, and NetSPI used Anthropic's Claude while researching another Artifactory entry (CVE-2026-42018, CVSS 7.5, EPSS 9.8%). A public tracker of Anthropic-credited CVEs lists 94 CVEs dated August or September, none of them on CISA's list, yet 61 have already appeared in ZEST customer environments.
AI is on offense too. In OpenAI's July Hugging Face incident, models under internal evaluation slipped their isolation controls and, against OpenAI's own systems, exploited an Artifactory zero-day (CVE-2026-66384, CVSS 5.3, EPSS 0.7%) without being told to and adapted a public exploit for a Linux kernel flaw (CVE-2026-53362, CVSS 7.8, EPSS 0.7%) to get root. CISA added both to the catalog in August, and the kernel flaw is present in 81% of ZEST customer environments and still open on nearly a third of the hosts where it was found. Proofpoint saw signs, though no proof, that the Chrome and Windows exploit kit was built with AI help, and Anthropic reported a group using Claude to hunt for zero-days in network appliances.
Who is using them
Only a handful of the 42 have a named attacker. Public reporting ties Chinese espionage groups, APT31 among them, to the Chrome and Windows chain, and a group whose tooling overlaps with Russia's Sandworm to Cisco's firewall manager. Most of the rest, including the NetScaler zero-days, Artifactory, GitLab and ScreenConnect, were exploited without public attribution, and CISA lists ransomware use as unknown for all 42.
What we saw in ZEST customer environments
Most of the exploited CVEs we found were there before CISA listed them. Across August and September, 26 of the 73 KEV additions appeared in ZEST customer environments, 19 of them ahead of their listing by a median of 97 days. The other seven were zero-days or flaws listed within three days of disclosure.

Network appliances are a blind spot in the data. The tools customers connect found seven of the nine operating system, browser and kernel CVEs on September's list but only one of the 17 network appliance CVEs. We read that as coverage more than exposure, since host agents and cloud, container and code scanners rarely look inside network gear.

Severity labels undersell exploited bugs. Of the instances of September's additions, 17% carried a Medium or Low severity, which a severity-sorted queue leaves for last, and about one in seven kernel instances sat in a container image. The three Linux kernel entries, all seen in customer environments, sit low on EPSS too (CVE-2025-39682, CVSS 9.8, EPSS 2.9%; CVE-2025-39964, CVSS 7.8, EPSS 0.996%; CVE-2026-53266, CVSS 8.8, EPSS 0.6%).
The only way to handle it is at machine speed
Attackers did not wait for patch cycles. At least ten of the month's flaws were under attack before their fix shipped, and four more, in WordPress, GitLab, Artifactory and a second Check Point product, were probed or attacked within four days of theirs. AI is making that cheaper: on September 29, Anthropic's red team reported a lab test in which an open-weight model turned two known flaws into a working exploit chain in eight hours, for about $20 at API prices.

Defenders still work at human speed. Of the Chrome and Windows zero-day instances we saw, more than 90% were still open about two weeks after the patches shipped, and at three weeks a quarter of the Chrome ones and three quarters of the Windows ones still were, past CISA's 14-day federal deadlines. Keeping up takes a response that runs at machine speed and closes attack paths preemptively, which is the loop ZEST runs: it validates exposure, reachability and exploitability for every vulnerability your tools report, credits the controls that already protect an asset, and hands the rest to AI agents that simulate remediation paths on a Digital Twin of your cloud and on-prem environments before automated remediation ships the root-cause fix.

What to do this month
- Validate exposure, reachability and exploitability.
Check every new KEV entry, including those already in your backlog, against your own environment and the exploitation requirements published for the CVE, because a version match, a CVSS rating or an EPSS value does not tell you whether you are exposed. This month's requirements are in the entries above. - Be preemptive with compensating controls.
Put a control you already run, such as a WAF, IPS, EDR or cloud network policy, on each exploitable path, and switch it to block as soon as an IOC or exploitation of the CVE is identified. A vulnerability behind a blocking control can be dismissed against that control, with the evidence attached, while one behind a control that only watches stays open. - Patch only what matters, at the root cause.
Fix what survives validation without a blocking control at its source, the base image, golden image or dependency that brought it in, so one change shipped through automated remediation fixes every instance built from it, and count it fixed only when a rescan no longer finds it. - Talk to ZEST.
If September's KEV additions are already in your backlog, book a demo and we'll show you what ZEST does with them.
How we measured. ZEST platform data, aggregated and anonymized, as of September 30, 2026 (the two-week zero-day reading is from September 24). "Seen" means at least one connected tool reported the CVE, an "instance" is one vulnerability on one asset from one tool, "still open" means open or in progress and reported again in the last 14 days, and environment shares count environments active in the last 30 days. CVSS is the rating in each CVE record, from the vendor or from CISA, and EPSS is FIRST's value dated September 30, 2026. KEV data: CISA catalog version 2026.09.29.
September's 42. Acronis Backup, Adobe Commerce (2), Apple iOS and macOS, Arista VeloCloud Orchestrator, Check Point (2), Chrome (2), Cisco (3), Citrix NetScaler (3), ConnectWise ScreenConnect, F5 BIG-IP APM, Fortinet, GitLab, Google Pixel, JFrog Artifactory (3), Kestra, Linux kernel (3), LiteLLM, Microsoft SharePoint, MikroTik RouterOS (3), N-able N-central, Sangoma Switchvox, SonicWall SMA1000 (2), Starlette, Windows (2), WordPress, WSO2 API Manager, Zyxel GS1900. CVE IDs are in CISA's catalog.
Sources. CISA: KEV catalog, BOD 26-04, NetScaler alert; FIRST EPSS; OpenAI; Volexity: part 1, part 2; Proofpoint; Chrome Releases: September 3, September 8; Cisco Talos; Cisco: FMC advisory, ISE advisory; Check Point; Citrix: bulletin, blog; Mandiant; GreyNoise; CERT Polska: advisory, analysis; Apple; Microsoft: advisory, first CVE record; Adobe; WSO2; Patchstack; GitLab; Rapid7: GitLab, SonicWall; N-able; Fastly; LiteLLM; Huntress; Help Net Security; Sansec; NetSPI; Anthropic-credited CVE tracker; Anthropic: threat report, GLM-5.3 test.
About The Author
.jpg)




