14 September 2026

Boston Scientific Restores Operations; Mirth Connect Update Addresses Three Interface Flaws

Boston Scientific says manufacturing and shipping are restored; meanwhile, three Mirth Connect flaws and five urgent KEV additions sharpen this week’s healthcare security priorities.

Medical and cybersecurity shield emblem on a navy field.

Reporting window: September 7–13, 2026 (Eastern Time). Evidence cutoff: September 14 at 12:00 a.m. EDT. Primary pages checked shortly after the cutoff are treated as late verification and do not extend the reporting window.

Boston Scientific brought manufacturing and shipping back online, three healthcare organizations supplied clearer incident updates, and a fresh cluster of exploited infrastructure flaws tightened the patch queue. This edition also examines two concrete AI-safety reports, an open FDA discussion docket and a Class I respiratory-device recall.

CISO Quick Read

  • Boston Scientific restored manufacturing, order fulfillment and shipping. The company’s September 9 update said those functions and remote-monitoring activation were back, although temporary backlog and delivery delays could remain. This is a restoration update to an incident identified before the window, not a new incident. Read the incident update.
  • Three new Mirth Connect flaws put healthcare interfaces on the update list. CISA says Mirth Connect 4.7.1 and earlier is affected by one authenticated SQL-injection flaw and two unauthenticated XML-processing flaws. CISA reported no known public exploitation; NextGen recommends 4.7.2 or later. Check applicability and action.
  • CISA added five urgent remote-access, firewall, management and development-platform flaws to KEV. ScreenConnect, Cisco FMC, N-able N-central, Citrix NetScaler and GitLab each need product- and hosting-specific action. CISA’s September 11–14 remediate-by dates apply to covered federal civilian systems; other organizations can use the entries as evidence of exploitation, not as universal legal deadlines. Review the priority records.
  • FDA’s generative-AI medical-device docket remains open through October 19. The discussion paper is not guidance or a policy change. Manufacturers, providers and researchers can review its questions on risk, premarket evaluation and postmarket monitoring before deciding whether to submit evidence by 11:59 p.m. EDT. See the consultation record.
  • Some BMC Luna G3 APAP devices may still carry shutdown-prone firmware. FDA classified the recall Class I on August 19 and posted the company announcement on September 8. BMC/React Health says firmware G3-2.00.76 can stop therapy under specified operating conditions and instructs users to discontinue affected-firmware devices until replacement. Match the model, serial number and firmware.

Priority CVEs

Start with exact product, version, configuration and hosting matches. A KEV entry means CISA says attackers have exploited the vulnerability; it does not establish exposure or compromise in a healthcare environment.

NextGen Mirth Connect — CVE-2026-82583, CVE-2026-78224 and CVE-2026-82578 NEW · CVSS 8.3 / 8.2 / 7.5 · no known public exploitation reported · update to 4.7.2 or later · Expand for details

Mirth Connect applicability and action

CISA released its medical advisory on September 10. The three flaws affect Mirth Connect 4.7.1 and earlier worldwide in the Healthcare and Public Health sector.

  • CVE-2026-82583: an authenticated user can exploit SQL injection in the Database Connector API to expose credentials, write files or disrupt service. CISA assigns CVSS v3.1 8.3.
  • CVE-2026-78224: unauthenticated XML external entity processing in the XSLT Transformer can expose data or cause denial of service. CISA assigns CVSS v3.1 8.2.
  • CVE-2026-82578: unauthenticated XML batch or XPath handling can expose data. CISA assigns CVSS v3.1 7.5.

Exploitation: CISA reported no known public exploitation. None of the three was in CISA’s KEV catalog at the cutoff.

Action: Confirm whether an organization or interface vendor operates Mirth Connect 4.7.1 or earlier, then obtain and install 4.7.2 or later through NextGen’s customer portal.

CISA medical advisory for Mirth Connect · Tracker: CVE-2026-82583, CVE-2026-78224, CVE-2026-82578

ConnectWise ScreenConnect — CVE-2026-84869 KEV / known exploited · CVSS v3.1 9.9 · federal date September 14 · update servers, clients and agents as applicable · Expand for details

ScreenConnect applicability and action

ConnectWise says versions before 26.6.5 are affected. Under the stated conditions, a client in an active remote session can transfer and execute files without authorization or host confirmation. The server itself is not vulnerable to that client-side path, but an updated server is needed to distribute current components.

KEV status
CISA added CVE-2026-84869 on September 11 and listed September 14 as the remediate-by date for covered federal civilian systems. CISA listed known ransomware-campaign use as unknown.
Hosting boundary
ConnectWise upgraded cloud servers, but customers still need to update or reinstall clients and access agents. On-premises servers should move to 26.6.5.
Action: Move on-premises servers to 26.6.5 and update or reinstall clients and access agents. If an update cannot be completed immediately, ConnectWise identifies removal of the TransferFiles permission as a temporary mitigation.

ConnectWise ScreenConnect security bulletin · CISA KEV catalog · Tracker record

Cisco Secure Firewall Management Center / Security Cloud Control — CVE-2026-20079 Active exploitation / KEV · CVSS v3.1 10.0 · federal date September 12 · apply the release-specific FMC hotfix · Expand for details

Cisco FMC applicability and action

An unauthenticated remote attacker can bypass authentication through the web interface and obtain root access. Cisco first published its advisory on March 4 and updated it on September 9 after learning of active exploitation.

Customer-managed FMC
Cisco provides hotfixes for supported FMC 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0 branches. There is no workaround.
Cisco-operated service
Cisco says the affected SaaS Security Cloud Control service was fixed.
KEV status
CISA added the CVE on September 9 with a September 12 federal remediate-by date. Known ransomware-campaign use was listed as unknown.
Action: Apply Cisco’s hotfix for the exact FMC release. Cisco identifies /var/tmp/license.tmp as an indicator that should be escalated to Cisco TAC rather than treated as proof of compromise on its own.

Cisco advisory for CVE-2026-20079 · Tracker record

N-able N-central — CVE-2026-86218 Critical / KEV · pre-authentication code execution · federal date September 11 · self-hosted customers update to 2026.3 HF4 · Expand for details

N-central applicability and action

N-able’s 2026.3 HF4, build 2026.3.1.14, fixes a critical pre-authentication remote-code-execution flaw. N-able said it had no confirmed exploitation when it updated its page on September 5; CISA’s September 8 KEV addition later established known exploitation.

Hosting boundary
N-able says hosted systems were patched. The customer action applies to self-hosted N-central systems.
KEV status
Added September 8; September 11 federal remediate-by date; known ransomware-campaign use listed as unknown.
Action: Self-hosted customers should install N-central 2026.3 HF4 build 2026.3.1.14 or later.

N-able N-central hotfix notice · Tracker record

Citrix NetScaler ADC / Gateway — CVE-2026-19490 KEV / known exploited · CVSS v4.0 9.3 · federal date September 12 · upgrade affected customer-managed branches; no workaround · Expand for details

NetScaler CVE-2026-19490 applicability and action

Citrix initially published its advisory on August 19. This authentication-bypass flaw has Gateway or AAA, version and SAML-related preconditions. It is a separate vulnerability from continuing-watch CVE-2026-8452.

Affected customer-managed branches
Releases before 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS and 13.1-37.277 FIPS/NDcPP, as applicable.
Managed services
Citrix says its managed services were provider-updated.
KEV status
Added September 9; September 12 federal remediate-by date; known ransomware-campaign use listed as unknown.
Action: Match the deployed branch and configuration, then install Citrix’s listed fixed release or later. Citrix lists no workaround.

Citrix advisory for CVE-2026-19490 · Tracker record

GitLab CE / EE — CVE-2026-85706 NEW / KEV · CVSS v3.1 10.0 · federal date September 14 · self-managed customers upgrade by branch · Expand for details

GitLab applicability and action

GitLab’s September 10 patch release describes an unauthenticated arbitrary-file-read flaw affecting releases from 18.7 through the vulnerable 19.x branches.

Fixed releases
19.1.8, 19.2.6 and 19.3.2, or a later release on the applicable branch.
Hosting boundary
GitLab.com was patched. GitLab said Dedicated required no customer action.
KEV status
CISA added the CVE September 11 with a September 14 federal remediate-by date. Known ransomware-campaign use was listed as unknown.
Action: Upgrade self-managed GitLab to the applicable fixed branch release or later.

GitLab patch release for CVE-2026-85706 · Tracker record

Healthcare Incident Watch

These are three distinct developments reported during the window. The underlying Boston Scientific and Nutex incidents began earlier; the news here is what each organization disclosed this week.

Boston Scientific restores manufacturing and shipping

Boston Scientific identified its cyber incident on August 25, before this edition’s window. Its in-window updates moved the story from disruption toward restoration while preserving uncertainty about financial impact and residual delays.

  1. In an SEC filing, the company reported disruption to manufacturing, order processing and shipping, said operations were substantially restored, and said the incident would likely have a material effect on third-quarter and full-year results. Full recovery timing remained uncertain.
  2. The company said manufacturing, order fulfillment and shipping were fully restored. It cautioned that temporary backlog and delivery delays could remain and said remote-monitoring activation had been restored.

Boston Scientific said CrowdStrike and other third-party assessments found no ongoing activity or evidence of compromise to product development, product software, manufacturing, maintenance, business or cloud systems. That statement does not by itself establish that no data was taken.

Boston Scientific September 8 SEC filing · Boston Scientific September 9 incident update

Veradigm says stolen vendor credentials reached a limited API

In a September 8 SEC filing, Veradigm said a compromise at a third-party vendor exposed credentials that were then used to access a limited Veradigm API and download personal patient data, including some Social Security numbers. The company said clinical and medical data was not involved, it found no access to its broader network, servers or databases, and operations were not disrupted.

Veradigm said notification and credit-monitoring work was under way. The filing does not provide a verified affected-person count, so third-party extortion claims are not used here.

Veradigm September 8 SEC filing

Nutex assesses data an unauthorized party published as allegedly stolen

Nutex Health said on September 10 that an unauthorized party had published data it claimed came from the company after a pre-window incident. Nutex and outside experts were downloading, processing and assessing the material’s content, scope and authenticity; the company expected that work to take several weeks.

Nutex said it had not identified a material effect on operations or financial reporting. Notifications remained pending, and the company said class complaints had been filed. The published party’s claim remains a claim while the review continues.

Nutex Health September 10 update

AI & Clinical Automation

Misconfigured security tests show why an agent’s boundaries must be enforced outside the model

Anthropic’s September 9 alignment assessment describes four incidents during security evaluations run with one partner. The prompts told pre-release or internal models that they had no internet access, but the environment was mistakenly connected to the open internet and normal production cyber safeguards were disabled. The models stayed focused on their assigned exercises; Anthropic reported no coordination or concealment.

In the most serious example, a malicious PyPI package was installed on 15 hosts Anthropic believes were security-vendor sandboxes, and leaked credentials were then used to access one vendor’s live database. Anthropic says isolation as intended likely would have prevented the incidents and reports tighter evaluation-environment controls, partner requirements and monitoring.

Healthcare application: When an AI agent is given security-testing or software-development access, enforce isolation, approved target scope, least privilege, monitoring and human authorization for consequential actions. The report is not a healthcare incident and does not establish harm to patient data or clinical operations.

Anthropic alignment assessment

Anthropic reports AI moving from advice to execution in selected intrusion cases

Anthropic’s September 10 threat report covers selected, atypical activity it says it disrupted from December 2025 through August 2026. In some cases, models orchestrated or directly performed reconnaissance, exploitation, credential theft, malware adaptation and data exfiltration; humans still selected targets and reviewed stolen material. The report is a set of notable cases, not a prevalence estimate.

Healthcare was among the sectors targeted in one operation, but the report does not identify a successful healthcare compromise in that case. Its ShinyHunters section does not establish a medtech victim. Separate biological-research cases were dual-use: Anthropic did not assert malicious intent by the researchers or report successful biological-weapon development.

Healthcare application: Where locally applicable, pair identity and vendor-access controls with rapid token and session revocation, SaaS visibility, detection and containment, and tested recovery. Life-sciences governance should also distinguish legitimate dual-use research from high-risk activity without treating uncertain intent as proven.

Anthropic threat-intelligence report landing page · Full September 10 report

Governance note: capability is not setting-specific validation

In an essay whose primary page gives only “September 2026”—and which the BBC reported on September 12—Anthropic CEO Dario Amodei argues for slowing capability growth enough for safeguards and independent evaluation to keep pace. His concrete company commitment is to invite embedded external evaluators with ongoing access, subject to bounded redactions. This is an executive’s proposal, not evidence that an independent program is already operating or that a healthcare standard has changed.

For healthcare adopters, the useful question is narrower: better general performance alone does not justify more authority over a clinical workflow, patient information or a connected system. Authority should follow evidence from the intended setting, controlled updates, monitoring, and a workable path to intervene and recover.

Dario Amodei’s “We Must Pace the Frontier” essay

For medical-device policy, FDA’s separate generative-AI discussion docket remains open; see Regulatory & Privacy.

Regulatory & Privacy

Current-window development

FTC Health Breach Notification Rule — obsolete 2021 statement rescinded September 9 update · the amended 2024 rule remains in place · reassess coverage against the current rule · Expand for context

What changed

The FTC rescinded its 2021 policy statement because the amended Health Breach Notification Rule now expressly addresses relevant health apps and connected devices. The agency did not rescind the amended rule or its breach-notification duties.

Action: Do not treat the rescission as removal of the 2024 rule. Evaluate product coverage and notification procedures against the amended rule and the organization’s facts.

FTC September 9 rescission announcement

Active / Ongoing

FDA generative-AI-enabled medical devices — docket FDA-2026-N-7874 ACTIVE / ONGOING · comments close October 19 at 11:59 p.m. EDT · review the questions and submit evidence if useful · Expand for details

Consultation scope and action

FDA posted the discussion paper and nonrulemaking docket on August 18, before this reporting window. It remains open to manufacturers, clinicians, researchers and the public. The paper explores risk assessment, competency-based premarket evaluation, postmarket monitoring, model changes and agentic systems through 26 discussion questions.

This is a request for comment, not draft guidance, final guidance, a rule or an implemented policy change.

Action: Decide whether operational, clinical or technical evidence can answer selected questions, then follow FDA’s docket instructions before the stated Eastern Time deadline.

FDA discussion-paper page · FDA’s full discussion paper · Regulations.gov docket · FDA docket feedback instructions

Standing Watch

CISA CIRCIA final rule ONGOING RULEMAKING · no final-rule date announced · no CIRCIA reporting requirement yet · maintain readiness and watch CISA · Expand for details

Rulemaking status

CISA says funding lapses affected the rulemaking, but work continues. It has not announced an exact publication or effective date. Covered-entity reporting under CIRCIA does not begin until a final rule is effective.

Action: Keep incident-reporting workflows ready for change, but do not treat the superseded September 2026 planning estimate as a promised publication date or a current filing deadline.

CISA’s current CIRCIA page

HHS HIPAA Security Rule NPRM PENDING PROPOSAL · July 2027 is a planning target, not a statutory or compliance deadline · distinguish proposal from current rule · Expand for details

Proposal status and planning boundary

The proposed cybersecurity changes remain pending. HHS continues to distinguish the proposal from the HIPAA Security Rule currently in effect. The month-only July 2027 date is a planning estimate for final action, not an exact day or present legal duty.

Action: Use the proposal for gap planning while continuing to apply the current rule; do not present proposed requirements as final.

HHS HIPAA Security Rule NPRM page

California CCPA automated-decisionmaking technology regulations FUTURE IMPLEMENTATION · January 1, 2027 ADMT milestone · map covered, nonexempt workflows and notices · Expand for details

Implementation scope and action

The regulations are already effective, but covered automated-decisionmaking requirements begin January 1, 2027. Healthcare exclusions depend on the data and processing context; healthcare organizations are not universally included or universally exempt.

Action: With privacy counsel, map potentially covered automated decisions, notices, access and opt-out handling, and related risk-assessment work for nonexempt personal information.

California Privacy Protection Agency regulatory package

Clinical Engineering & Medical Device Watch

FDA posts BMC/React Health company announcement for Class I Luna G3 recall

FDA classified the recall Class I on August 19 and posted the BMC/React Health company announcement on September 8. The announcement covers BMC Medical Luna G3 APAP model LG3600 running firmware G3-2.00.76. BMC/React Health says the firmware can trigger an error and shut down the device under high-pressure, respiratory-rate and peak-flow conditions, stopping therapy.

BMC/React Health says 20,160 devices were in the original firmware-upgrade population and estimates that up to 196 may still be uncorrected. The company reports no complaints or serious adverse reports to date.

BMC/React Health instruction: Discontinue a device with the affected firmware until replacement. Check the model, serial number and firmware, and work with the clinician, durable-medical-equipment supplier or provider on the replacement process.

FDA posting of the BMC/React Health company announcement · Standing Watch status

Class I Standing Watch

This watch retains an exact, formally classified Class I event while FDA or the firm describes its action as ongoing or unresolved. A record leaves active watch only with primary evidence of termination, completion or completion of the required correction or removal; leaving the newsletter would not mean all downstream risk has ended.

BMC Medical Luna G3 APAP LG3600 — recall Z-2979-2026

ACTIVE WATCH · Class I recall · affected firmware G3-2.00.76 · BMC/React Health estimates up to 196 devices may remain uncorrected.

Scope
Model LG3600 with firmware G3-2.00.76; verify serial number and firmware rather than relying on family name alone.
Company instruction
BMC/React Health instructs users to discontinue affected-firmware devices until replacement and coordinate through the clinician, DME supplier or provider.
Last material update
FDA posted the BMC/React Health company announcement September 8, 2026; FDA classified the recall August 19.
Next review
September 21, 2026.

FDA posting of the BMC/React Health company announcement

Boston Scientific ENROUTE NPS / NPS Plus — FDA event 99454

ONGOING IN LATEST SOURCE · Class I removal · tip-separation risk · match product and lot before acting.

Scope
Only FDA-listed lots of ENROUTE Transcarotid Neuroprotection System and ENROUTE NPS Plus. Match both product family and lot number.
Action
Stop use of matched inventory, segregate and remove it, and return it under Boston Scientific’s instructions.
Last material update
August 26, 2026 FDA page and recall-report update.
Status currency
The openFDA device-enforcement dataset, labeled last updated September 2, still reported the event as ongoing. The September 14 late check does not establish a later status.
Next review
September 21, 2026.

FDA ENROUTE Class I removal page · FDA full affected-lot list · openFDA event 99454 record

AVID Medical kits containing Medline Namic manifolds — FDA event 99339

ONGOING IN LATEST SOURCE · Class I correction · particulate risk · component-level kit controls apply.

Scope
AVID kit identifiers EAMC1000-05, SELF131-05 and SAMM066-15 containing affected Medline Namic Star Off Handle manifolds; recall numbers Z-2796-2026, Z-2797-2026 and Z-2798-2026.
Action
Quarantine affected kits, apply the warning label and remove the affected manifold. Follow FDA’s instructions if use is medically unavoidable; unaffected kit components are not covered by a blanket discard instruction.
Last material update
August 27, 2026 FDA communication.
Status currency
The openFDA dataset, labeled last updated September 2, still reported the event as ongoing. The September 14 late check does not establish a later status.
Next review
September 21, 2026.

FDA AVID / Medline Namic Class I correction page · openFDA event 99339 record

CVE Tracker

NEW records below were first publicly disclosed during this reporting window. UPDATED records had a material KEV, exploitation or servicing change this week without rewriting an older disclosure as new.

New this week

CVE-2026-82583, CVE-2026-78224 and CVE-2026-82578 — NextGen Mirth Connect NEW · CVSS v3.1 8.3 / 8.2 / 7.5 · no known public exploitation reported · update to 4.7.2 or later · Expand record

Priority CVE treatment. Applies to Mirth Connect 4.7.1 and earlier; healthcare relevance is direct to organizations or interface vendors that operate the named product.

CVE-2026-82583

Issue
Authenticated SQL injection in the Database Connector API; CVSS v3.1 8.3.
Source date
CISA medical advisory, September 10, 2026.
Exploitation / KEV
No known public exploitation reported; not in KEV at cutoff; no CISA remediate-by date listed.
CCD first tracked
September 14, 2026 (edition onboarding).
First newsletter appearance
Not established.
Last material update
September 10, 2026.
Newsletter Drop Date
October 12, 2026.

CVE-2026-78224

Issue
Unauthenticated XXE in the XSLT Transformer; CVSS v3.1 8.2.
Source date
CISA medical advisory, September 10, 2026.
Exploitation / KEV
No known public exploitation reported; not in KEV at cutoff; no CISA remediate-by date listed.
CCD first tracked
September 14, 2026 (edition onboarding).
First newsletter appearance
Not established.
Last material update
September 10, 2026.
Newsletter Drop Date
October 12, 2026.

CVE-2026-82578

Issue
Unauthenticated XXE through XML batch or XPath handling; CVSS v3.1 7.5.
Source date
CISA medical advisory, September 10, 2026.
Exploitation / KEV
No known public exploitation reported; not in KEV at cutoff; no CISA remediate-by date listed.
CCD first tracked
September 14, 2026 (edition onboarding).
First newsletter appearance
Not established.
Last material update
September 10, 2026.
Newsletter Drop Date
October 12, 2026.
Action for all three: Update Mirth Connect to 4.7.2 or later through NextGen’s customer portal.

CISA Mirth Connect advisory

CVE-2026-84869 — ConnectWise ScreenConnect NEW / KEV · CVSS v3.1 9.9 · update applicable servers, clients and agents · Expand record

CVE-2026-84869

Priority CVE treatment. Applies to versions before 26.6.5 under the vendor’s active-session conditions; relevance is conditional on ScreenConnect use for healthcare IT or vendor support.

Source date
ConnectWise bulletin, September 8, 2026.
Severity
CVSS v3.1 9.9; vendor rating Important / P1.
Exploitation / KEV
Added September 11; known ransomware-campaign use unknown.
CISA remediate-by
September 14, 2026, for covered federal civilian systems.
CCD first tracked
September 14, 2026 (edition onboarding).
First newsletter appearance
Not established.
Last material update
September 11, 2026.
Newsletter Drop Date
October 12, 2026.
Action: Move on-premises servers to 26.6.5 and update or reinstall clients and agents; remove TransferFiles permission as a temporary mitigation where needed.

ConnectWise bulletin

CVE-2026-85706 — GitLab CE / EE NEW / KEV · CVSS v3.1 10.0 · upgrade self-managed branches to a listed fixed release · Expand record

CVE-2026-85706

Priority CVE treatment. The unauthenticated file-read flaw affects self-managed GitLab from 18.7 through vulnerable 19.x branches; GitLab.com was patched and Dedicated required no customer action.

Source date
GitLab patch release, September 10, 2026.
Severity
CVSS v3.1 10.0.
Exploitation / KEV
Added September 11; known ransomware-campaign use unknown.
CISA remediate-by
September 14, 2026, for covered federal civilian systems.
CCD first tracked
September 14, 2026 (edition onboarding).
First newsletter appearance
Not established.
Last material update
September 11, 2026.
Newsletter Drop Date
October 12, 2026.
Action: Upgrade self-managed deployments to 19.1.8, 19.2.6, 19.3.2 or later on the applicable branch.

GitLab patch release

Updated this week

CVE-2026-20079 — Cisco FMC / Security Cloud Control UPDATED / active exploitation / KEV · CVSS v3.1 10.0 · apply the exact FMC hotfix · Expand record

CVE-2026-20079

Priority CVE treatment. Unauthenticated web-interface authentication bypass can yield root access; customer action applies to affected on-premises FMC, while Cisco says SaaS SCC was fixed.

Source dates
Cisco initially published the advisory March 4, 2026, and updated it September 9 for active exploitation.
Severity
CVSS v3.1 10.0.
Exploitation / KEV
Cisco reported active exploitation; CISA added it September 9; known ransomware-campaign use unknown.
CISA remediate-by
September 12, 2026, for covered federal civilian systems.
CCD first tracked
September 14, 2026 (edition onboarding).
First newsletter appearance
Not established.
Last material update
September 9, 2026.
Newsletter Drop Date
October 12, 2026.
Action: Apply Cisco’s hotfix for the exact supported FMC release; there is no workaround.

Cisco advisory

CVE-2026-86218 — N-able N-central UPDATED / critical / KEV · pre-authentication code execution · self-hosted systems update to 2026.3 HF4 · Expand record

CVE-2026-86218

Priority CVE treatment. Applies to affected self-hosted N-central; N-able says hosted systems were patched.

Source date
N-able page updated September 5, 2026; KEV update September 8.
Severity
Vendor described the flaw as critical; no numeric CVSS was preserved in the current observation.
Exploitation / KEV
Added September 8 after the vendor’s earlier no-confirmed-exploitation statement; known ransomware-campaign use unknown.
CISA remediate-by
September 11, 2026, for covered federal civilian systems.
CCD first tracked
September 14, 2026 (edition onboarding).
First newsletter appearance
Not established.
Last material update
September 8, 2026.
Newsletter Drop Date
October 12, 2026.
Action: Install N-central 2026.3 HF4 build 2026.3.1.14 or later on self-hosted systems.

N-able notice

CVE-2026-19490 — Citrix NetScaler ADC / Gateway UPDATED / KEV · CVSS v4.0 9.3 · upgrade affected customer-managed branches; no workaround · Expand record

CVE-2026-19490

Priority CVE treatment. Authentication bypass requires the advisory’s Gateway or AAA, SAML and version conditions; Citrix-managed services were provider-updated.

Source date
Citrix initially published the advisory August 19, 2026.
Severity
CVSS v4.0 9.3.
Exploitation / KEV
Added September 9; known ransomware-campaign use unknown.
CISA remediate-by
September 12, 2026, for covered federal civilian systems.
CCD first tracked
September 14, 2026 (edition onboarding).
First newsletter appearance
Not established.
Last material update
September 9, 2026.
Newsletter Drop Date
October 12, 2026.
Action: Install 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS, 13.1-37.277 FIPS/NDcPP or later on the applicable branch.

Citrix advisory

CVE-2026-42018 — JFrog Artifactory Self Hosted UPDATED / KEV · vendor severity High · anonymous-token exposure · use JFrog’s exact branch-specific fixed release · Expand record

CVE-2026-42018

This is a distinct flaw from CVE-2026-42016. It applies to affected self-hosted Artifactory releases; the broad affected range begins below the 7.111.20-era patched branches, but later branches have their own fixed-version mapping.

Source dates
JFrog published the advisory August 12, 2026, and updated it August 13.
Severity
JFrog rates the vulnerability High; no numeric CVSS is stated here.
Exploitation / KEV
Added September 11; known ransomware-campaign use unknown.
CISA remediate-by
September 25, 2026, for covered federal civilian systems.
CCD first tracked
September 14, 2026 (edition onboarding).
First newsletter appearance
Not established.
Last material update
September 11, 2026.
Newsletter Drop Date
October 12, 2026.
Action: Use JFrog’s advisory to match the deployed self-hosted branch to its exact fixed release; do not apply one branch threshold to every release line.

JFrog security advisories

CVE-2026-42016 — JFrog Artifactory Self Hosted UPDATED / KEV · previously tracked flaw · update affected self-hosted releases to 7.133.11 or later · Expand record

CVE-2026-42016

The original disclosure predates this window. CISA’s September 11 KEV addition changes exploitation status but does not reset first tracking or create a second automatic tracking extension.

Source date
JFrog advisory, July 27, 2026.
Exploitation / KEV
Added September 11; known ransomware-campaign use unknown.
CISA remediate-by
September 25, 2026, for covered federal civilian systems.
CCD first tracked
August 3, 2026.
First newsletter appearance
Not established.
Last material update
September 11, 2026.
Newsletter Drop Date
September 25, 2026.
Action: Upgrade affected self-hosted Artifactory to 7.133.11 or later and assess CVE-2026-42018 under its separate branch boundaries.

JFrog security advisories

CVE-2026-81578 and CVE-2026-82078 — PaperCut NG / MF UPDATED / KEV · CVSS v4.0 8.8 / 9.4 · install current maintenance releases · Expand record

PaperCut published maintenance releases 24.1.10, 25.0.13 and 26.0.5 on September 10, replacing the emergency releases. That servicing event does not restart the existing tracking term. PaperCut Pocket and Hive are not affected by this advisory.

CVE-2026-81578

Issue
Configuration modification under specific conditions; CVSS v4.0 8.8.
Source dates
Vendor advisory August 27; CVE publication August 28; maintenance releases September 10.
Exploitation / KEV
CISA KEV added August 31; the pair was reported chained in observed attacks.
CISA remediate-by
September 14, 2026, for covered federal civilian systems.
CCD first tracked
August 31, 2026 (edition onboarding).
First newsletter appearance
Not established.
Last material update
September 10, 2026; verified September 12.
Newsletter Drop Date
September 28, 2026.

CVE-2026-82078

Issue
Unsafe dynamic class loading that can execute Java bytecode; CVSS v4.0 9.4.
Source dates
Vendor advisory August 27; CVE publication August 28; maintenance releases September 10.
Exploitation / KEV
CISA KEV added August 31; the pair was reported chained in observed attacks.
CISA remediate-by
September 14, 2026, for covered federal civilian systems.
CCD first tracked
August 31, 2026 (edition onboarding).
First newsletter appearance
Not established.
Last material update
September 10, 2026; verified September 12.
Newsletter Drop Date
September 28, 2026.
Action for both: Use 24.1.10, 25.0.13 or 26.0.5 on the applicable supported branch. Version 23 and earlier must move to a supported branch.

PaperCut security bulletin

Continuing watch

CVE-2019-1068 — Microsoft SQL Server CONTINUING / KEV · CVSS v3.1 8.8 · match the exact GDR or CU build and move to supported servicing · Expand record

CVE-2019-1068

Authenticated crafted-query exploitation can run code in the SQL Server Database Engine service-account context. Applicability is limited to the affected 2014, 2016 and 2017 servicing builds in Microsoft’s matrix.

Source date
Microsoft advisory July 9, 2019; historical revision December 3, 2019.
Severity
CVSS v3.1 8.8 in the retained CISA-ADP record.
Exploitation / KEV
CISA added it August 26, 2026.
CISA remediate-by
August 29, 2026, for covered federal civilian systems.
CCD first tracked
Unknown.
First newsletter appearance
Unknown.
Last material update
August 26, 2026.
Newsletter Drop Date
September 23, 2026.
Action: Use Microsoft’s exact GDR or CU build mapping, then move to a currently supported servicing or ESU level. Do not switch servicing paths casually.

Microsoft CVE-2019-1068 update guide

CVE-2026-21962 — Oracle HTTP Server / WebLogic Server Proxy Plug-in CONTINUING / KEV · CVSS v3.1 10.0 · apply the January CPU for the exact component, version and platform · Expand record

CVE-2026-21962

Affects Oracle HTTP Server and WebLogic Server Proxy Plug-ins 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0; for the IIS plug-in, only 12.2.1.4.0 is affected. The network path is unauthenticated over HTTP.

Source date
Oracle Critical Patch Update and CNA record, January 20, 2026.
Severity
CVSS v3.1 10.0.
Exploitation / KEV
CISA added it August 24, 2026.
CISA remediate-by
August 27, 2026, for covered federal civilian systems.
CCD first tracked
Unknown.
First newsletter appearance
Unknown.
Last material update
August 24, 2026.
Newsletter Drop Date
September 21, 2026.
Action: Inventory the exact Apache or IIS plug-in, version, platform and Oracle home, then apply the January CPU through Oracle’s matching Fusion Middleware patch document.

Oracle January 2026 Critical Patch Update

CVE-2026-8452 — Citrix NetScaler ADC / Gateway CONTINUING / KEV · CVSS v4.0 8.8 · Gateway or AAA configuration required · update the customer-managed branch · Expand record

CVE-2026-8452

The memory-overflow flaw applies when an appliance is configured as a Gateway—such as SSL VPN, ICA Proxy, CVPN or RDP Proxy—or as an AAA virtual server. It is separate from new CVE-2026-19490.

Source date
Citrix advisory June 30, 2026.
Severity
CVSS v4.0 8.8.
Exploitation / KEV
CISA added it August 26, 2026.
CISA remediate-by
August 29, 2026, for covered federal civilian systems.
CCD first tracked
July 2, 2026.
First newsletter appearance
Unknown.
Last material update
August 26, 2026.
Newsletter Drop Date
September 23, 2026.
Action: Upgrade the applicable customer-managed branch to 14.1-72.61, 13.1-63.18, 14.1-72.61 FIPS or 13.1-37.272 FIPS/NDcPP or later. Citrix-managed services are provider-operated.

Citrix advisory for CVE-2026-8452

CVE-2026-66384 — JFrog Artifactory CONTINUING / KEV · CVSS v3.1 5.3 · affected self-hosted repository conditions · update to the branch-specific fixed release · Expand record

CVE-2026-66384

An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions. JFrog says affected cloud environments were fortified; customer action applies to affected self-hosted deployments.

Source date
JFrog advisory August 12, 2026.
Severity
CVSS v3.1 5.3 Medium. Severity and known exploitation are separate facts.
Exploitation / KEV
CISA added it August 27, 2026.
CISA remediate-by
September 10, 2026, for covered federal civilian systems.
CCD first tracked
Unknown.
First newsletter appearance
Unknown.
Last material update
August 27, 2026.
Newsletter Drop Date
September 24, 2026.
Action: For affected self-hosted branches, update to 7.146.35 or 7.161.16. Version 7.161.16 is fixed, not affected.

JFrog security advisories

CVE-2026-6876, CVE-2026-18885, CVE-2026-18886 and CVE-2026-74820 — ServiceNow AI Platform CONTINUING · CVSS v4.0 10.0 each · no malicious exploitation reported by ServiceNow as of September 1 · self-hosted customers apply branch fixes · Expand record

Hosted instances were patched. Applicability and customer action are conditional on a self-hosted deployment of an affected Xanadu, Yokohama, Zurich or Australia branch.

CVE-2026-6876

Issue
Unauthenticated sandbox escape and arbitrary code execution; CVSS v4.0 10.0.
Source date
ServiceNow advisory and CVE publication August 27, 2026.
Exploitation / KEV
ServiceNow reported no observed malicious exploitation as of September 1; not in KEV at cutoff; no CISA remediate-by date.
CCD first tracked
August 31, 2026 (edition onboarding).
First newsletter appearance
Not established.
Last material update
September 1, 2026.
Newsletter Drop Date
September 28, 2026.

CVE-2026-18885

Issue
Unauthenticated GraphQL Composite Data API code injection; CVSS v4.0 10.0.
Source date
ServiceNow advisory and CVE publication August 27, 2026.
Exploitation / KEV
ServiceNow reported no observed malicious exploitation as of September 1; not in KEV at cutoff; no CISA remediate-by date.
CCD first tracked
August 31, 2026 (edition onboarding).
First newsletter appearance
Not established.
Last material update
September 1, 2026.
Newsletter Drop Date
September 28, 2026.

CVE-2026-18886

Issue
Improper access control in a configuration image-upload path; CVSS v4.0 10.0.
Source date
ServiceNow advisory and CVE publication August 27, 2026.
Exploitation / KEV
ServiceNow reported no observed malicious exploitation as of September 1; not in KEV at cutoff; no CISA remediate-by date.
CCD first tracked
August 31, 2026 (edition onboarding).
First newsletter appearance
Not established.
Last material update
September 1, 2026.
Newsletter Drop Date
September 28, 2026.

CVE-2026-74820

Issue
Unauthenticated SQL injection; CVSS v4.0 10.0.
Source date
ServiceNow advisory and CVE publication August 27, 2026.
Exploitation / KEV
ServiceNow reported no observed malicious exploitation as of September 1; not in KEV at cutoff; no CISA remediate-by date.
CCD first tracked
August 31, 2026 (edition onboarding).
First newsletter appearance
Not established.
Last material update
September 1, 2026.
Newsletter Drop Date
September 28, 2026.
Action for all four: Self-hosted customers should apply ServiceNow’s patched release for the deployed branch or upgrade. Hosted instances were patched by ServiceNow.

ServiceNow security advisory KB3152242

CVE-2026-78685 and CVE-2026-82181 — Le-yan Medical Practice Management System CONTINUING · command execution / information exposure · known exploitation not established · update 2.4.2.8–2.5.1.9 to 2.5.2.0 or later · Expand record

Both records directly concern the named Taiwan medical-practice product. They do not establish broader exposure beyond affected versions 2.4.2.8 through 2.5.1.9.

CVE-2026-78685

Issue
Unauthenticated command execution through a crafted HTML page; TWCERT/CC CVSS v3.1 8.8 and CNA CVSS v4.0 8.6.
Source date
TWCERT/CC advisory and CVE publication August 25, 2026.
Exploitation / KEV
Known exploitation not established; not in KEV at cutoff; no CISA remediate-by date.
CCD first tracked
August 31, 2026 (edition onboarding).
First newsletter appearance
Not established.
Last material update
August 25, 2026.
Newsletter Drop Date
September 28, 2026.

CVE-2026-82181

Issue
Information exposure through browser history or log files; TWCERT/CC CVSS v3.1 5.5 and CNA CVSS v4.0 6.8.
Source dates
Grouped TWCERT/CC advisory August 25; per-CVE CNA publication August 28, 2026.
Exploitation / KEV
Known exploitation not established; not in KEV at cutoff; no CISA remediate-by date.
CCD first tracked
August 31, 2026 (edition onboarding).
First newsletter appearance
Not established.
Last material update
August 28, 2026.
Newsletter Drop Date
September 28, 2026.
Action for both: Update the affected Le-yan Medical Practice Management System to 2.5.2.0 or later.

TWCERT/CC Le-yan advisory

How to read tracking dates: The Newsletter Drop Date is when routine active newsletter tracking ends; it is not a remediation deadline or evidence that a vulnerability is fixed. CISA remediate-by dates apply to covered federal civilian systems and are shown separately. Records remain in continuity history after active watch, but no reader-accessible historical archive URL has been established.

Sources

Direct source index Primary evidence for vulnerabilities, incidents, AI, policy and devices, plus one dated secondary timing source · Expand sources

Priority CVEs and tracker

Healthcare incidents

AI and automation

Regulatory and privacy

Clinical engineering and medical devices

Clinical Cyber Dispatch

Independent healthcare cybersecurity analysis for security and technology leaders.