14 September 2026
Boston Scientific Restores Operations; Mirth Connect Update Addresses Three Interface Flaws
Boston Scientific says manufacturing and shipping are restored; meanwhile, three Mirth Connect flaws and five urgent KEV additions sharpen this week’s healthcare security priorities.
Reporting window: September 7–13, 2026 (Eastern Time). Evidence cutoff: September 14 at 12:00 a.m. EDT. Primary pages checked shortly after the cutoff are treated as late verification and do not extend the reporting window.
Boston Scientific brought manufacturing and shipping back online, three healthcare organizations supplied clearer incident updates, and a fresh cluster of exploited infrastructure flaws tightened the patch queue. This edition also examines two concrete AI-safety reports, an open FDA discussion docket and a Class I respiratory-device recall.
CISO Quick Read
- Boston Scientific restored manufacturing, order fulfillment and shipping. The company’s September 9 update said those functions and remote-monitoring activation were back, although temporary backlog and delivery delays could remain. This is a restoration update to an incident identified before the window, not a new incident. Read the incident update.
- Three new Mirth Connect flaws put healthcare interfaces on the update list. CISA says Mirth Connect 4.7.1 and earlier is affected by one authenticated SQL-injection flaw and two unauthenticated XML-processing flaws. CISA reported no known public exploitation; NextGen recommends 4.7.2 or later. Check applicability and action.
- CISA added five urgent remote-access, firewall, management and development-platform flaws to KEV. ScreenConnect, Cisco FMC, N-able N-central, Citrix NetScaler and GitLab each need product- and hosting-specific action. CISA’s September 11–14 remediate-by dates apply to covered federal civilian systems; other organizations can use the entries as evidence of exploitation, not as universal legal deadlines. Review the priority records.
- FDA’s generative-AI medical-device docket remains open through October 19. The discussion paper is not guidance or a policy change. Manufacturers, providers and researchers can review its questions on risk, premarket evaluation and postmarket monitoring before deciding whether to submit evidence by 11:59 p.m. EDT. See the consultation record.
- Some BMC Luna G3 APAP devices may still carry shutdown-prone firmware. FDA classified the recall Class I on August 19 and posted the company announcement on September 8. BMC/React Health says firmware G3-2.00.76 can stop therapy under specified operating conditions and instructs users to discontinue affected-firmware devices until replacement. Match the model, serial number and firmware.
Priority CVEs
Start with exact product, version, configuration and hosting matches. A KEV entry means CISA says attackers have exploited the vulnerability; it does not establish exposure or compromise in a healthcare environment.
NextGen Mirth Connect — CVE-2026-82583, CVE-2026-78224 and CVE-2026-82578 NEW · CVSS 8.3 / 8.2 / 7.5 · no known public exploitation reported · update to 4.7.2 or later · Expand for details
Mirth Connect applicability and action
CISA released its medical advisory on September 10. The three flaws affect Mirth Connect 4.7.1 and earlier worldwide in the Healthcare and Public Health sector.
- CVE-2026-82583: an authenticated user can exploit SQL injection in the Database Connector API to expose credentials, write files or disrupt service. CISA assigns CVSS v3.1 8.3.
- CVE-2026-78224: unauthenticated XML external entity processing in the XSLT Transformer can expose data or cause denial of service. CISA assigns CVSS v3.1 8.2.
- CVE-2026-82578: unauthenticated XML batch or XPath handling can expose data. CISA assigns CVSS v3.1 7.5.
Exploitation: CISA reported no known public exploitation. None of the three was in CISA’s KEV catalog at the cutoff.
CISA medical advisory for Mirth Connect · Tracker: CVE-2026-82583, CVE-2026-78224, CVE-2026-82578
ConnectWise ScreenConnect — CVE-2026-84869 KEV / known exploited · CVSS v3.1 9.9 · federal date September 14 · update servers, clients and agents as applicable · Expand for details
ScreenConnect applicability and action
ConnectWise says versions before 26.6.5 are affected. Under the stated conditions, a client in an active remote session can transfer and execute files without authorization or host confirmation. The server itself is not vulnerable to that client-side path, but an updated server is needed to distribute current components.
- KEV status
- CISA added CVE-2026-84869 on September 11 and listed September 14 as the remediate-by date for covered federal civilian systems. CISA listed known ransomware-campaign use as unknown.
- Hosting boundary
- ConnectWise upgraded cloud servers, but customers still need to update or reinstall clients and access agents. On-premises servers should move to 26.6.5.
TransferFiles permission as a temporary mitigation.ConnectWise ScreenConnect security bulletin · CISA KEV catalog · Tracker record
Cisco Secure Firewall Management Center / Security Cloud Control — CVE-2026-20079 Active exploitation / KEV · CVSS v3.1 10.0 · federal date September 12 · apply the release-specific FMC hotfix · Expand for details
Cisco FMC applicability and action
An unauthenticated remote attacker can bypass authentication through the web interface and obtain root access. Cisco first published its advisory on March 4 and updated it on September 9 after learning of active exploitation.
- Customer-managed FMC
- Cisco provides hotfixes for supported FMC 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0 branches. There is no workaround.
- Cisco-operated service
- Cisco says the affected SaaS Security Cloud Control service was fixed.
- KEV status
- CISA added the CVE on September 9 with a September 12 federal remediate-by date. Known ransomware-campaign use was listed as unknown.
/var/tmp/license.tmp as an indicator that should be escalated to Cisco TAC rather than treated as proof of compromise on its own.N-able N-central — CVE-2026-86218 Critical / KEV · pre-authentication code execution · federal date September 11 · self-hosted customers update to 2026.3 HF4 · Expand for details
N-central applicability and action
N-able’s 2026.3 HF4, build 2026.3.1.14, fixes a critical pre-authentication remote-code-execution flaw. N-able said it had no confirmed exploitation when it updated its page on September 5; CISA’s September 8 KEV addition later established known exploitation.
- Hosting boundary
- N-able says hosted systems were patched. The customer action applies to self-hosted N-central systems.
- KEV status
- Added September 8; September 11 federal remediate-by date; known ransomware-campaign use listed as unknown.
Citrix NetScaler ADC / Gateway — CVE-2026-19490 KEV / known exploited · CVSS v4.0 9.3 · federal date September 12 · upgrade affected customer-managed branches; no workaround · Expand for details
NetScaler CVE-2026-19490 applicability and action
Citrix initially published its advisory on August 19. This authentication-bypass flaw has Gateway or AAA, version and SAML-related preconditions. It is a separate vulnerability from continuing-watch CVE-2026-8452.
- Affected customer-managed branches
- Releases before 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS and 13.1-37.277 FIPS/NDcPP, as applicable.
- Managed services
- Citrix says its managed services were provider-updated.
- KEV status
- Added September 9; September 12 federal remediate-by date; known ransomware-campaign use listed as unknown.
GitLab CE / EE — CVE-2026-85706 NEW / KEV · CVSS v3.1 10.0 · federal date September 14 · self-managed customers upgrade by branch · Expand for details
GitLab applicability and action
GitLab’s September 10 patch release describes an unauthenticated arbitrary-file-read flaw affecting releases from 18.7 through the vulnerable 19.x branches.
- Fixed releases
- 19.1.8, 19.2.6 and 19.3.2, or a later release on the applicable branch.
- Hosting boundary
- GitLab.com was patched. GitLab said Dedicated required no customer action.
- KEV status
- CISA added the CVE September 11 with a September 14 federal remediate-by date. Known ransomware-campaign use was listed as unknown.
Healthcare Incident Watch
These are three distinct developments reported during the window. The underlying Boston Scientific and Nutex incidents began earlier; the news here is what each organization disclosed this week.
Boston Scientific restores manufacturing and shipping
Boston Scientific identified its cyber incident on August 25, before this edition’s window. Its in-window updates moved the story from disruption toward restoration while preserving uncertainty about financial impact and residual delays.
- In an SEC filing, the company reported disruption to manufacturing, order processing and shipping, said operations were substantially restored, and said the incident would likely have a material effect on third-quarter and full-year results. Full recovery timing remained uncertain.
- The company said manufacturing, order fulfillment and shipping were fully restored. It cautioned that temporary backlog and delivery delays could remain and said remote-monitoring activation had been restored.
Boston Scientific said CrowdStrike and other third-party assessments found no ongoing activity or evidence of compromise to product development, product software, manufacturing, maintenance, business or cloud systems. That statement does not by itself establish that no data was taken.
Boston Scientific September 8 SEC filing · Boston Scientific September 9 incident update
Veradigm says stolen vendor credentials reached a limited API
In a September 8 SEC filing, Veradigm said a compromise at a third-party vendor exposed credentials that were then used to access a limited Veradigm API and download personal patient data, including some Social Security numbers. The company said clinical and medical data was not involved, it found no access to its broader network, servers or databases, and operations were not disrupted.
Veradigm said notification and credit-monitoring work was under way. The filing does not provide a verified affected-person count, so third-party extortion claims are not used here.
Nutex assesses data an unauthorized party published as allegedly stolen
Nutex Health said on September 10 that an unauthorized party had published data it claimed came from the company after a pre-window incident. Nutex and outside experts were downloading, processing and assessing the material’s content, scope and authenticity; the company expected that work to take several weeks.
Nutex said it had not identified a material effect on operations or financial reporting. Notifications remained pending, and the company said class complaints had been filed. The published party’s claim remains a claim while the review continues.
AI & Clinical Automation
Misconfigured security tests show why an agent’s boundaries must be enforced outside the model
Anthropic’s September 9 alignment assessment describes four incidents during security evaluations run with one partner. The prompts told pre-release or internal models that they had no internet access, but the environment was mistakenly connected to the open internet and normal production cyber safeguards were disabled. The models stayed focused on their assigned exercises; Anthropic reported no coordination or concealment.
In the most serious example, a malicious PyPI package was installed on 15 hosts Anthropic believes were security-vendor sandboxes, and leaked credentials were then used to access one vendor’s live database. Anthropic says isolation as intended likely would have prevented the incidents and reports tighter evaluation-environment controls, partner requirements and monitoring.
Anthropic reports AI moving from advice to execution in selected intrusion cases
Anthropic’s September 10 threat report covers selected, atypical activity it says it disrupted from December 2025 through August 2026. In some cases, models orchestrated or directly performed reconnaissance, exploitation, credential theft, malware adaptation and data exfiltration; humans still selected targets and reviewed stolen material. The report is a set of notable cases, not a prevalence estimate.
Healthcare was among the sectors targeted in one operation, but the report does not identify a successful healthcare compromise in that case. Its ShinyHunters section does not establish a medtech victim. Separate biological-research cases were dual-use: Anthropic did not assert malicious intent by the researchers or report successful biological-weapon development.
Anthropic threat-intelligence report landing page · Full September 10 report
Governance note: capability is not setting-specific validation
In an essay whose primary page gives only “September 2026”—and which the BBC reported on September 12—Anthropic CEO Dario Amodei argues for slowing capability growth enough for safeguards and independent evaluation to keep pace. His concrete company commitment is to invite embedded external evaluators with ongoing access, subject to bounded redactions. This is an executive’s proposal, not evidence that an independent program is already operating or that a healthcare standard has changed.
For healthcare adopters, the useful question is narrower: better general performance alone does not justify more authority over a clinical workflow, patient information or a connected system. Authority should follow evidence from the intended setting, controlled updates, monitoring, and a workable path to intervene and recover.
For medical-device policy, FDA’s separate generative-AI discussion docket remains open; see Regulatory & Privacy.
Regulatory & Privacy
Current-window development
FTC Health Breach Notification Rule — obsolete 2021 statement rescinded September 9 update · the amended 2024 rule remains in place · reassess coverage against the current rule · Expand for context
What changed
The FTC rescinded its 2021 policy statement because the amended Health Breach Notification Rule now expressly addresses relevant health apps and connected devices. The agency did not rescind the amended rule or its breach-notification duties.
Active / Ongoing
FDA generative-AI-enabled medical devices — docket FDA-2026-N-7874 ACTIVE / ONGOING · comments close October 19 at 11:59 p.m. EDT · review the questions and submit evidence if useful · Expand for details
Consultation scope and action
FDA posted the discussion paper and nonrulemaking docket on August 18, before this reporting window. It remains open to manufacturers, clinicians, researchers and the public. The paper explores risk assessment, competency-based premarket evaluation, postmarket monitoring, model changes and agentic systems through 26 discussion questions.
This is a request for comment, not draft guidance, final guidance, a rule or an implemented policy change.
FDA discussion-paper page · FDA’s full discussion paper · Regulations.gov docket · FDA docket feedback instructions
Standing Watch
CISA CIRCIA final rule ONGOING RULEMAKING · no final-rule date announced · no CIRCIA reporting requirement yet · maintain readiness and watch CISA · Expand for details
Rulemaking status
CISA says funding lapses affected the rulemaking, but work continues. It has not announced an exact publication or effective date. Covered-entity reporting under CIRCIA does not begin until a final rule is effective.
HHS HIPAA Security Rule NPRM PENDING PROPOSAL · July 2027 is a planning target, not a statutory or compliance deadline · distinguish proposal from current rule · Expand for details
Proposal status and planning boundary
The proposed cybersecurity changes remain pending. HHS continues to distinguish the proposal from the HIPAA Security Rule currently in effect. The month-only July 2027 date is a planning estimate for final action, not an exact day or present legal duty.
California CCPA automated-decisionmaking technology regulations FUTURE IMPLEMENTATION · January 1, 2027 ADMT milestone · map covered, nonexempt workflows and notices · Expand for details
Implementation scope and action
The regulations are already effective, but covered automated-decisionmaking requirements begin January 1, 2027. Healthcare exclusions depend on the data and processing context; healthcare organizations are not universally included or universally exempt.
Clinical Engineering & Medical Device Watch
FDA posts BMC/React Health company announcement for Class I Luna G3 recall
FDA classified the recall Class I on August 19 and posted the BMC/React Health company announcement on September 8. The announcement covers BMC Medical Luna G3 APAP model LG3600 running firmware G3-2.00.76. BMC/React Health says the firmware can trigger an error and shut down the device under high-pressure, respiratory-rate and peak-flow conditions, stopping therapy.
BMC/React Health says 20,160 devices were in the original firmware-upgrade population and estimates that up to 196 may still be uncorrected. The company reports no complaints or serious adverse reports to date.
FDA posting of the BMC/React Health company announcement · Standing Watch status
Class I Standing Watch
This watch retains an exact, formally classified Class I event while FDA or the firm describes its action as ongoing or unresolved. A record leaves active watch only with primary evidence of termination, completion or completion of the required correction or removal; leaving the newsletter would not mean all downstream risk has ended.
BMC Medical Luna G3 APAP LG3600 — recall Z-2979-2026
ACTIVE WATCH · Class I recall · affected firmware G3-2.00.76 · BMC/React Health estimates up to 196 devices may remain uncorrected.
- Scope
- Model LG3600 with firmware G3-2.00.76; verify serial number and firmware rather than relying on family name alone.
- Company instruction
- BMC/React Health instructs users to discontinue affected-firmware devices until replacement and coordinate through the clinician, DME supplier or provider.
- Last material update
- FDA posted the BMC/React Health company announcement September 8, 2026; FDA classified the recall August 19.
- Next review
- September 21, 2026.
Boston Scientific ENROUTE NPS / NPS Plus — FDA event 99454
ONGOING IN LATEST SOURCE · Class I removal · tip-separation risk · match product and lot before acting.
- Scope
- Only FDA-listed lots of ENROUTE Transcarotid Neuroprotection System and ENROUTE NPS Plus. Match both product family and lot number.
- Action
- Stop use of matched inventory, segregate and remove it, and return it under Boston Scientific’s instructions.
- Last material update
- August 26, 2026 FDA page and recall-report update.
- Status currency
- The openFDA device-enforcement dataset, labeled last updated September 2, still reported the event as ongoing. The September 14 late check does not establish a later status.
- Next review
- September 21, 2026.
FDA ENROUTE Class I removal page · FDA full affected-lot list · openFDA event 99454 record
AVID Medical kits containing Medline Namic manifolds — FDA event 99339
ONGOING IN LATEST SOURCE · Class I correction · particulate risk · component-level kit controls apply.
- Scope
- AVID kit identifiers EAMC1000-05, SELF131-05 and SAMM066-15 containing affected Medline Namic Star Off Handle manifolds; recall numbers Z-2796-2026, Z-2797-2026 and Z-2798-2026.
- Action
- Quarantine affected kits, apply the warning label and remove the affected manifold. Follow FDA’s instructions if use is medically unavoidable; unaffected kit components are not covered by a blanket discard instruction.
- Last material update
- August 27, 2026 FDA communication.
- Status currency
- The openFDA dataset, labeled last updated September 2, still reported the event as ongoing. The September 14 late check does not establish a later status.
- Next review
- September 21, 2026.
FDA AVID / Medline Namic Class I correction page · openFDA event 99339 record
CVE Tracker
NEW records below were first publicly disclosed during this reporting window. UPDATED records had a material KEV, exploitation or servicing change this week without rewriting an older disclosure as new.
New this week
CVE-2026-82583, CVE-2026-78224 and CVE-2026-82578 — NextGen Mirth Connect NEW · CVSS v3.1 8.3 / 8.2 / 7.5 · no known public exploitation reported · update to 4.7.2 or later · Expand record
Priority CVE treatment. Applies to Mirth Connect 4.7.1 and earlier; healthcare relevance is direct to organizations or interface vendors that operate the named product.
CVE-2026-82583
- Issue
- Authenticated SQL injection in the Database Connector API; CVSS v3.1 8.3.
- Source date
- CISA medical advisory, September 10, 2026.
- Exploitation / KEV
- No known public exploitation reported; not in KEV at cutoff; no CISA remediate-by date listed.
- CCD first tracked
- September 14, 2026 (edition onboarding).
- First newsletter appearance
- Not established.
- Last material update
- September 10, 2026.
- Newsletter Drop Date
- October 12, 2026.
CVE-2026-78224
- Issue
- Unauthenticated XXE in the XSLT Transformer; CVSS v3.1 8.2.
- Source date
- CISA medical advisory, September 10, 2026.
- Exploitation / KEV
- No known public exploitation reported; not in KEV at cutoff; no CISA remediate-by date listed.
- CCD first tracked
- September 14, 2026 (edition onboarding).
- First newsletter appearance
- Not established.
- Last material update
- September 10, 2026.
- Newsletter Drop Date
- October 12, 2026.
CVE-2026-82578
- Issue
- Unauthenticated XXE through XML batch or XPath handling; CVSS v3.1 7.5.
- Source date
- CISA medical advisory, September 10, 2026.
- Exploitation / KEV
- No known public exploitation reported; not in KEV at cutoff; no CISA remediate-by date listed.
- CCD first tracked
- September 14, 2026 (edition onboarding).
- First newsletter appearance
- Not established.
- Last material update
- September 10, 2026.
- Newsletter Drop Date
- October 12, 2026.
CVE-2026-84869 — ConnectWise ScreenConnect NEW / KEV · CVSS v3.1 9.9 · update applicable servers, clients and agents · Expand record
CVE-2026-84869
Priority CVE treatment. Applies to versions before 26.6.5 under the vendor’s active-session conditions; relevance is conditional on ScreenConnect use for healthcare IT or vendor support.
- Source date
- ConnectWise bulletin, September 8, 2026.
- Severity
- CVSS v3.1 9.9; vendor rating Important / P1.
- Exploitation / KEV
- Added September 11; known ransomware-campaign use unknown.
- CISA remediate-by
- September 14, 2026, for covered federal civilian systems.
- CCD first tracked
- September 14, 2026 (edition onboarding).
- First newsletter appearance
- Not established.
- Last material update
- September 11, 2026.
- Newsletter Drop Date
- October 12, 2026.
TransferFiles permission as a temporary mitigation where needed.CVE-2026-85706 — GitLab CE / EE NEW / KEV · CVSS v3.1 10.0 · upgrade self-managed branches to a listed fixed release · Expand record
CVE-2026-85706
Priority CVE treatment. The unauthenticated file-read flaw affects self-managed GitLab from 18.7 through vulnerable 19.x branches; GitLab.com was patched and Dedicated required no customer action.
- Source date
- GitLab patch release, September 10, 2026.
- Severity
- CVSS v3.1 10.0.
- Exploitation / KEV
- Added September 11; known ransomware-campaign use unknown.
- CISA remediate-by
- September 14, 2026, for covered federal civilian systems.
- CCD first tracked
- September 14, 2026 (edition onboarding).
- First newsletter appearance
- Not established.
- Last material update
- September 11, 2026.
- Newsletter Drop Date
- October 12, 2026.
Updated this week
CVE-2026-20079 — Cisco FMC / Security Cloud Control UPDATED / active exploitation / KEV · CVSS v3.1 10.0 · apply the exact FMC hotfix · Expand record
CVE-2026-20079
Priority CVE treatment. Unauthenticated web-interface authentication bypass can yield root access; customer action applies to affected on-premises FMC, while Cisco says SaaS SCC was fixed.
- Source dates
- Cisco initially published the advisory March 4, 2026, and updated it September 9 for active exploitation.
- Severity
- CVSS v3.1 10.0.
- Exploitation / KEV
- Cisco reported active exploitation; CISA added it September 9; known ransomware-campaign use unknown.
- CISA remediate-by
- September 12, 2026, for covered federal civilian systems.
- CCD first tracked
- September 14, 2026 (edition onboarding).
- First newsletter appearance
- Not established.
- Last material update
- September 9, 2026.
- Newsletter Drop Date
- October 12, 2026.
CVE-2026-86218 — N-able N-central UPDATED / critical / KEV · pre-authentication code execution · self-hosted systems update to 2026.3 HF4 · Expand record
CVE-2026-86218
Priority CVE treatment. Applies to affected self-hosted N-central; N-able says hosted systems were patched.
- Source date
- N-able page updated September 5, 2026; KEV update September 8.
- Severity
- Vendor described the flaw as critical; no numeric CVSS was preserved in the current observation.
- Exploitation / KEV
- Added September 8 after the vendor’s earlier no-confirmed-exploitation statement; known ransomware-campaign use unknown.
- CISA remediate-by
- September 11, 2026, for covered federal civilian systems.
- CCD first tracked
- September 14, 2026 (edition onboarding).
- First newsletter appearance
- Not established.
- Last material update
- September 8, 2026.
- Newsletter Drop Date
- October 12, 2026.
CVE-2026-19490 — Citrix NetScaler ADC / Gateway UPDATED / KEV · CVSS v4.0 9.3 · upgrade affected customer-managed branches; no workaround · Expand record
CVE-2026-19490
Priority CVE treatment. Authentication bypass requires the advisory’s Gateway or AAA, SAML and version conditions; Citrix-managed services were provider-updated.
- Source date
- Citrix initially published the advisory August 19, 2026.
- Severity
- CVSS v4.0 9.3.
- Exploitation / KEV
- Added September 9; known ransomware-campaign use unknown.
- CISA remediate-by
- September 12, 2026, for covered federal civilian systems.
- CCD first tracked
- September 14, 2026 (edition onboarding).
- First newsletter appearance
- Not established.
- Last material update
- September 9, 2026.
- Newsletter Drop Date
- October 12, 2026.
CVE-2026-42018 — JFrog Artifactory Self Hosted UPDATED / KEV · vendor severity High · anonymous-token exposure · use JFrog’s exact branch-specific fixed release · Expand record
CVE-2026-42018
This is a distinct flaw from CVE-2026-42016. It applies to affected self-hosted Artifactory releases; the broad affected range begins below the 7.111.20-era patched branches, but later branches have their own fixed-version mapping.
- Source dates
- JFrog published the advisory August 12, 2026, and updated it August 13.
- Severity
- JFrog rates the vulnerability High; no numeric CVSS is stated here.
- Exploitation / KEV
- Added September 11; known ransomware-campaign use unknown.
- CISA remediate-by
- September 25, 2026, for covered federal civilian systems.
- CCD first tracked
- September 14, 2026 (edition onboarding).
- First newsletter appearance
- Not established.
- Last material update
- September 11, 2026.
- Newsletter Drop Date
- October 12, 2026.
CVE-2026-42016 — JFrog Artifactory Self Hosted UPDATED / KEV · previously tracked flaw · update affected self-hosted releases to 7.133.11 or later · Expand record
CVE-2026-42016
The original disclosure predates this window. CISA’s September 11 KEV addition changes exploitation status but does not reset first tracking or create a second automatic tracking extension.
- Source date
- JFrog advisory, July 27, 2026.
- Exploitation / KEV
- Added September 11; known ransomware-campaign use unknown.
- CISA remediate-by
- September 25, 2026, for covered federal civilian systems.
- CCD first tracked
- August 3, 2026.
- First newsletter appearance
- Not established.
- Last material update
- September 11, 2026.
- Newsletter Drop Date
- September 25, 2026.
CVE-2026-81578 and CVE-2026-82078 — PaperCut NG / MF UPDATED / KEV · CVSS v4.0 8.8 / 9.4 · install current maintenance releases · Expand record
PaperCut published maintenance releases 24.1.10, 25.0.13 and 26.0.5 on September 10, replacing the emergency releases. That servicing event does not restart the existing tracking term. PaperCut Pocket and Hive are not affected by this advisory.
CVE-2026-81578
- Issue
- Configuration modification under specific conditions; CVSS v4.0 8.8.
- Source dates
- Vendor advisory August 27; CVE publication August 28; maintenance releases September 10.
- Exploitation / KEV
- CISA KEV added August 31; the pair was reported chained in observed attacks.
- CISA remediate-by
- September 14, 2026, for covered federal civilian systems.
- CCD first tracked
- August 31, 2026 (edition onboarding).
- First newsletter appearance
- Not established.
- Last material update
- September 10, 2026; verified September 12.
- Newsletter Drop Date
- September 28, 2026.
CVE-2026-82078
- Issue
- Unsafe dynamic class loading that can execute Java bytecode; CVSS v4.0 9.4.
- Source dates
- Vendor advisory August 27; CVE publication August 28; maintenance releases September 10.
- Exploitation / KEV
- CISA KEV added August 31; the pair was reported chained in observed attacks.
- CISA remediate-by
- September 14, 2026, for covered federal civilian systems.
- CCD first tracked
- August 31, 2026 (edition onboarding).
- First newsletter appearance
- Not established.
- Last material update
- September 10, 2026; verified September 12.
- Newsletter Drop Date
- September 28, 2026.
Continuing watch
CVE-2019-1068 — Microsoft SQL Server CONTINUING / KEV · CVSS v3.1 8.8 · match the exact GDR or CU build and move to supported servicing · Expand record
CVE-2019-1068
Authenticated crafted-query exploitation can run code in the SQL Server Database Engine service-account context. Applicability is limited to the affected 2014, 2016 and 2017 servicing builds in Microsoft’s matrix.
- Source date
- Microsoft advisory July 9, 2019; historical revision December 3, 2019.
- Severity
- CVSS v3.1 8.8 in the retained CISA-ADP record.
- Exploitation / KEV
- CISA added it August 26, 2026.
- CISA remediate-by
- August 29, 2026, for covered federal civilian systems.
- CCD first tracked
- Unknown.
- First newsletter appearance
- Unknown.
- Last material update
- August 26, 2026.
- Newsletter Drop Date
- September 23, 2026.
CVE-2026-21962 — Oracle HTTP Server / WebLogic Server Proxy Plug-in CONTINUING / KEV · CVSS v3.1 10.0 · apply the January CPU for the exact component, version and platform · Expand record
CVE-2026-21962
Affects Oracle HTTP Server and WebLogic Server Proxy Plug-ins 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0; for the IIS plug-in, only 12.2.1.4.0 is affected. The network path is unauthenticated over HTTP.
- Source date
- Oracle Critical Patch Update and CNA record, January 20, 2026.
- Severity
- CVSS v3.1 10.0.
- Exploitation / KEV
- CISA added it August 24, 2026.
- CISA remediate-by
- August 27, 2026, for covered federal civilian systems.
- CCD first tracked
- Unknown.
- First newsletter appearance
- Unknown.
- Last material update
- August 24, 2026.
- Newsletter Drop Date
- September 21, 2026.
CVE-2026-8452 — Citrix NetScaler ADC / Gateway CONTINUING / KEV · CVSS v4.0 8.8 · Gateway or AAA configuration required · update the customer-managed branch · Expand record
CVE-2026-8452
The memory-overflow flaw applies when an appliance is configured as a Gateway—such as SSL VPN, ICA Proxy, CVPN or RDP Proxy—or as an AAA virtual server. It is separate from new CVE-2026-19490.
- Source date
- Citrix advisory June 30, 2026.
- Severity
- CVSS v4.0 8.8.
- Exploitation / KEV
- CISA added it August 26, 2026.
- CISA remediate-by
- August 29, 2026, for covered federal civilian systems.
- CCD first tracked
- July 2, 2026.
- First newsletter appearance
- Unknown.
- Last material update
- August 26, 2026.
- Newsletter Drop Date
- September 23, 2026.
CVE-2026-66384 — JFrog Artifactory CONTINUING / KEV · CVSS v3.1 5.3 · affected self-hosted repository conditions · update to the branch-specific fixed release · Expand record
CVE-2026-66384
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions. JFrog says affected cloud environments were fortified; customer action applies to affected self-hosted deployments.
- Source date
- JFrog advisory August 12, 2026.
- Severity
- CVSS v3.1 5.3 Medium. Severity and known exploitation are separate facts.
- Exploitation / KEV
- CISA added it August 27, 2026.
- CISA remediate-by
- September 10, 2026, for covered federal civilian systems.
- CCD first tracked
- Unknown.
- First newsletter appearance
- Unknown.
- Last material update
- August 27, 2026.
- Newsletter Drop Date
- September 24, 2026.
CVE-2026-6876, CVE-2026-18885, CVE-2026-18886 and CVE-2026-74820 — ServiceNow AI Platform CONTINUING · CVSS v4.0 10.0 each · no malicious exploitation reported by ServiceNow as of September 1 · self-hosted customers apply branch fixes · Expand record
Hosted instances were patched. Applicability and customer action are conditional on a self-hosted deployment of an affected Xanadu, Yokohama, Zurich or Australia branch.
CVE-2026-6876
- Issue
- Unauthenticated sandbox escape and arbitrary code execution; CVSS v4.0 10.0.
- Source date
- ServiceNow advisory and CVE publication August 27, 2026.
- Exploitation / KEV
- ServiceNow reported no observed malicious exploitation as of September 1; not in KEV at cutoff; no CISA remediate-by date.
- CCD first tracked
- August 31, 2026 (edition onboarding).
- First newsletter appearance
- Not established.
- Last material update
- September 1, 2026.
- Newsletter Drop Date
- September 28, 2026.
CVE-2026-18885
- Issue
- Unauthenticated GraphQL Composite Data API code injection; CVSS v4.0 10.0.
- Source date
- ServiceNow advisory and CVE publication August 27, 2026.
- Exploitation / KEV
- ServiceNow reported no observed malicious exploitation as of September 1; not in KEV at cutoff; no CISA remediate-by date.
- CCD first tracked
- August 31, 2026 (edition onboarding).
- First newsletter appearance
- Not established.
- Last material update
- September 1, 2026.
- Newsletter Drop Date
- September 28, 2026.
CVE-2026-18886
- Issue
- Improper access control in a configuration image-upload path; CVSS v4.0 10.0.
- Source date
- ServiceNow advisory and CVE publication August 27, 2026.
- Exploitation / KEV
- ServiceNow reported no observed malicious exploitation as of September 1; not in KEV at cutoff; no CISA remediate-by date.
- CCD first tracked
- August 31, 2026 (edition onboarding).
- First newsletter appearance
- Not established.
- Last material update
- September 1, 2026.
- Newsletter Drop Date
- September 28, 2026.
CVE-2026-74820
- Issue
- Unauthenticated SQL injection; CVSS v4.0 10.0.
- Source date
- ServiceNow advisory and CVE publication August 27, 2026.
- Exploitation / KEV
- ServiceNow reported no observed malicious exploitation as of September 1; not in KEV at cutoff; no CISA remediate-by date.
- CCD first tracked
- August 31, 2026 (edition onboarding).
- First newsletter appearance
- Not established.
- Last material update
- September 1, 2026.
- Newsletter Drop Date
- September 28, 2026.
CVE-2026-78685 and CVE-2026-82181 — Le-yan Medical Practice Management System CONTINUING · command execution / information exposure · known exploitation not established · update 2.4.2.8–2.5.1.9 to 2.5.2.0 or later · Expand record
Both records directly concern the named Taiwan medical-practice product. They do not establish broader exposure beyond affected versions 2.4.2.8 through 2.5.1.9.
CVE-2026-78685
- Issue
- Unauthenticated command execution through a crafted HTML page; TWCERT/CC CVSS v3.1 8.8 and CNA CVSS v4.0 8.6.
- Source date
- TWCERT/CC advisory and CVE publication August 25, 2026.
- Exploitation / KEV
- Known exploitation not established; not in KEV at cutoff; no CISA remediate-by date.
- CCD first tracked
- August 31, 2026 (edition onboarding).
- First newsletter appearance
- Not established.
- Last material update
- August 25, 2026.
- Newsletter Drop Date
- September 28, 2026.
CVE-2026-82181
- Issue
- Information exposure through browser history or log files; TWCERT/CC CVSS v3.1 5.5 and CNA CVSS v4.0 6.8.
- Source dates
- Grouped TWCERT/CC advisory August 25; per-CVE CNA publication August 28, 2026.
- Exploitation / KEV
- Known exploitation not established; not in KEV at cutoff; no CISA remediate-by date.
- CCD first tracked
- August 31, 2026 (edition onboarding).
- First newsletter appearance
- Not established.
- Last material update
- August 28, 2026.
- Newsletter Drop Date
- September 28, 2026.
How to read tracking dates: The Newsletter Drop Date is when routine active newsletter tracking ends; it is not a remediation deadline or evidence that a vulnerability is fixed. CISA remediate-by dates apply to covered federal civilian systems and are shown separately. Records remain in continuity history after active watch, but no reader-accessible historical archive URL has been established.
Sources
Direct source index Primary evidence for vulnerabilities, incidents, AI, policy and devices, plus one dated secondary timing source · Expand sources
Priority CVEs and tracker
- CISA: NextGen Mirth Connect medical advisory — September 10, 2026.
- ConnectWise: ScreenConnect CVE-2026-84869 bulletin — September 8, 2026.
- Cisco: FMC / SCC CVE-2026-20079 advisory — initially published March 4; active-exploitation update September 9, 2026.
- N-able: N-central CVE-2026-86218 hotfix notice — vendor status before the September 8 KEV update.
- Citrix: NetScaler CVE-2026-19490 advisory — initially published August 19, 2026.
- GitLab: 19.3.2 patch release for CVE-2026-85706 — September 10, 2026; CVSS v3.1 10.0.
- JFrog security advisories — CVE-2026-42018 published August 12 and updated August 13; also covers CVE-2026-42016 and CVE-2026-66384.
- PaperCut NG / MF security bulletin — original August 27 advisory; maintenance releases September 10.
- Microsoft: SQL Server CVE-2019-1068 — July 9, 2019.
- Oracle January 2026 Critical Patch Update — CVE-2026-21962.
- Citrix: NetScaler CVE-2026-8452 advisory — June 30, 2026.
- ServiceNow security advisory KB3152242 — August 27, 2026.
- TWCERT/CC: Le-yan Medical Practice Management System advisory — August 25, 2026.
- CISA Known Exploited Vulnerabilities catalog — catalog version 2026.09.11 checked after cutoff.
Healthcare incidents
- Boston Scientific SEC filing — filed September 8, 2026.
- Boston Scientific cyber-incident update — September 9, 2026.
- Veradigm SEC filing — September 8, 2026.
- Nutex Health cyber-event update — September 10, 2026.
AI and automation
- Anthropic: alignment assessment of cybersecurity incidents — September 9, 2026.
- Anthropic: September 2026 threat-intelligence report landing page.
- Anthropic: full “Detecting and countering misuse of AI” report — September 10, 2026.
- Dario Amodei: “We Must Pace the Frontier” — primary page states September 2026.
- BBC timing and context for Amodei’s essay — published September 12, 2026; secondary source.
Regulatory and privacy
- FTC: withdrawal of obsolete Health Breach Notification Rule policy statement — September 9, 2026.
- FDA: generative-AI-enabled medical-device discussion-paper page — posted August 18, 2026.
- FDA: full generative-AI-enabled medical-device discussion paper.
- Regulations.gov: docket FDA-2026-N-7874 — comments close October 19, 2026 at 11:59 p.m. EDT.
- Regulations.gov: FDA feedback instructions for docket FDA-2026-N-7874.
- CISA: current CIRCIA rulemaking status.
- HHS: HIPAA Security Rule NPRM.
- California Privacy Protection Agency: CCPA regulatory package.
Clinical engineering and medical devices
- FDA posting of BMC/React Health’s Luna G3 APAP company announcement — posted September 8, 2026; FDA Class I classification August 19. Scope, complaint history and user instructions are company statements.
- FDA: Boston Scientific ENROUTE NPS / NPS Plus Class I removal.
- FDA: full affected-lot list for ENROUTE NPS / NPS Plus.
- openFDA: device-enforcement event 99454 — dataset currency September 2, 2026.
- FDA: AVID kits containing Medline Namic manifolds Class I correction.
- openFDA: device-enforcement event 99339 — dataset currency September 2, 2026.