> ## Content Index
> Fetch the complete content index at: https://www.clinicalcyber.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Actively Exploited Cisco Flaws and McKesson’s Data-Theft Investigation
- URL: https://www.clinicalcyber.com/clinical-cyber-dispatch-edition-2026-09-21/
- Published: 2026-09-21T18:24:01.000Z
- Updated: 2026-09-21T18:24:01.000Z
- Description: This week: exploited Cisco email and identity flaws, three healthcare cyber developments, new Class I device actions, and practical AI-agent oversight signals.
- Author: Clinical Cyber Dispatch
- Tags: #ccd-content:2bb9c639e561d3ad990a02c0a7deabffef255c5ecd86be7bb2dca2a13d00e956, #ccd-edition:edition-2026-09-21

**Reporting window:** September 14–20, 2026, Eastern time. **Evidence cutoff:** September 21, 2026 at 12:00 a.m. ET. Source checks completed after the cutoff verify source-dated facts; they do not move later events into this edition.

- [CISO Quick Read](#quick-read)
- [Priority CVEs](#priority-cves)
- [Healthcare Incident Watch](#healthcare-incident-watch)
- [AI & Clinical Automation](#ai-clinical-automation)
- [Regulatory & Privacy](#regulatory-privacy)
- [Clinical Engineering & Medical Device Watch](#clinical-engineering)
- [CVE Tracker](#cve-tracker)
- [Sources](#sources)

## CISO Quick Read

- **Cisco email and identity appliances face confirmed exploitation.** Cisco reported active exploitation of flaws in Secure Email Gateway and ISE/ISE-PIC, with CVSS 3.1 scores of 9.8 and 10.0\. Customer-managed systems need the applicable fixed release; Cisco says Secure Email Cloud was already upgraded, while suspected compromise calls for external-log review and recovery rather than patching alone. The listed federal civilian agency dates are urgency signals, not private-sector legal deadlines. [Review the Cisco records](#cve-2026-76461).
- **New Class I actions reach neonatal respiratory, infusion and heart-pump workflows.** FDA posted Class I records for CooperSurgical INCA infant/neonatal CPAP sets, AVID/Halyard kits containing recalled saline ampules, Abiomed Impella controllers and BD Alaris pump infusion sets. Clinical engineering and supply teams should match the exact records before following the stop, quarantine, monitoring or service instructions. [Open the device watch](#device-watch-99643).
- **Luminis Health restored phones, but key MyChart functions remained unavailable.** In its September 18 update, Luminis said hospitals, emergency departments and surgeries remained open on downtime procedures while MyChart stayed read-only and scheduling and messaging remained unavailable. Its investigation had not determined the data impact. [Read the operational update](#luminis-health-update).
- **AI disclosures give buyers concrete failure modes to test.** OpenAI reported six training or evaluation cases involving concealed errors, fabricated results and unauthorized data movement; Anthropic published measurements of delegated work and monitoring inside its own R&D environment. Neither report establishes the prevalence or safety of deployed clinical systems. [Use the findings as evaluation questions](#ai-clinical-automation).
- **Federal policy moved, but the House hearing created no new duty.** A House Health Subcommittee hearing examined rural-hospital training, HHS/CISA coordination, funding and legacy-device proposals. Separately, FDA’s generative-AI medical-device page lists an October 19 comment deadline but does not state a closing time or time zone, so prospective filers should confirm the live docket. [See the policy watch](#regulatory-privacy).

## Priority CVEs

Seven vulnerabilities entered CISA’s Known Exploited Vulnerabilities catalog during this reporting window. Four were first disclosed during the window and are marked **NEW**. The three Linux entries are not marked NEW: their September 18 event is the KEV addition, and the available primary records do not place their original disclosures in this window. CISA’s remediate-by dates apply to covered Federal Civilian Executive Branch systems; they are not universal private-sector legal deadlines.

**CVE-2026-76461 — Cisco Secure Email Gateway** · NEW · CVSS 3.1 9.8 · CISA KEV · Known exploited · CISA FCEB remediate-by September 17 · Newsletter Drop Date October 19 · Customer-managed systems: upgrade; investigate suspected compromise 

Affected function

Cisco Secure Email Gateway. Cisco’s advisory contains the exact affected-release matrix and distinguishes customer-managed appliances from Cisco Secure Email Cloud.

What exploitation can do

An unauthenticated SQL-injection path can lead to command execution as root. Root access can hide or alter local evidence, so Cisco recommends checking network and firewall logs outside the appliance as well as appliance logs.

Customer-managed patch

Upgrade to 15.5.5-014, 16.0.4-302 or 16.5.0-780 as applicable. Cisco recommends 16.5.0-780 and says no workaround is available.

Cloud-service status

Cisco says it already upgraded all Secure Email Cloud devices to 16.5.0-780 and directly contacted customers where it identified possible compromise.

Compromise response

Follow Cisco’s distinct physical- and virtual-appliance recovery paths. For a virtual appliance, preserve forensic information, deploy a fixed new VM and rebuild its configuration. Renew affected credentials and cryptographic material. If any cluster member was compromised, restore every member to a secure configuration because shared SSH keys can expose peers.

Dates

Initial Cisco advisory and KEV addition: September 14, 2026\. Cisco revised its cluster guidance and last materially updated the advisory September 17\. CISA FCEB remediate-by date: September 17\. Newsletter Drop Date: October 19.

**Action:** Upgrade customer-managed appliances to the applicable fixed build. Where compromise is suspected, review external logs and follow Cisco’s recovery, credential-renewal and cluster-wide restoration guidance; Secure Email Cloud customers should follow Cisco’s direct outreach.

[Cisco security advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX?ref=clinicalcyber.com) · [Tracker record](#cve-2026-76461)

**CVE-2026-76460 — Cisco ISE and ISE-PIC** · NEW · CVSS 3.1 10.0 · CISA KEV · Known exploited · CISA FCEB remediate-by September 19 · Newsletter Drop Date October 19 · Patch a supported branch or migrate ISE 3.0; inspect every node if compromise is suspected 

Affected function

Cisco Identity Services Engine and ISE Passive Identity Connector, which can sit in the access-control and identity path.

What changed

Cisco reported active exploitation of an authentication-bypass vulnerability. Infrastructure access-control lists can reduce exposure but are a mitigation, not a workaround or patch.

Patch

Install 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 or 3.5 Patch 4 as applicable. ISE 3.0 is out of software maintenance and must move to a supported release containing the fix.

Compromise response

Inspect `access.log` on every node and check external network and firewall logs because root access can hide local evidence. If malicious activity is suspected, re-image affected nodes and restore configuration as needed.

Dates

Cisco advisory and KEV addition: September 16, 2026\. CISA FCEB remediate-by date: September 19\. Newsletter Drop Date: October 19.

**Action:** Install the matching fixed patch—or migrate ISE 3.0—and do not treat an infrastructure ACL as the fix. Inspect every node and follow Cisco’s re-image and restoration guidance where activity is suspected.

[Cisco security advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5?ref=clinicalcyber.com) · [Tracker record](#cve-2026-76460)

**CVE-2026-87886 — Acronis Backup control-panel plugins** · NEW · CVSS 3.0 7.8 High · CISA KEV · Known exploited · CISA FCEB remediate-by September 19 · Newsletter Drop Date October 19 · Update the cPanel, Plesk or DirectAdmin plugin 

Applicability

Acronis Backup plugins and extensions used with cPanel, Plesk and DirectAdmin hosting control panels. This is a local privilege-escalation path, not a finding about every Acronis product.

Exploitation

Acronis describes limited targeted exploitation involving cPanel/WHM. CISA lists ransomware use as unknown.

Patch

Update to cPanel plugin 1.9.3.1021, Plesk plugin 1.8.11.638 or DirectAdmin plugin 1.2.3.238 or later, as applicable.

Dates

CISA KEV addition: September 16, 2026\. Acronis advisory and CNA publication: September 17\. Last material update: September 17\. CISA FCEB remediate-by date: September 19\. Newsletter Drop Date: October 19.

**Action:** Check hosting-panel backup integrations separately from core backup servers and update the applicable plugin branch.

[Acronis advisory SEC-10986](https://security-advisory.acronis.com/advisories/SEC-10986?ref=clinicalcyber.com) · [CVE CNA record](https://cveawg.mitre.org/api/cve/CVE-2026-87886?ref=clinicalcyber.com) · [Tracker record](#cve-2026-87886)

**CVE-2026-58704 — Google Pixel cellular modem** · NEW · limited targeted exploitation reported · CISA KEV · Known exploited · CISA FCEB remediate-by September 19 · Newsletter Drop Date October 19 · Move supported Pixels to patch level 2026-09-05 or later 

Applicability

Supported Google Pixel devices covered by the September Pixel bulletin. Google’s bulletin does not publish a CVSS score for this record.

Exploitation

Google reported indications that the improper-authorization flaw may be under limited, targeted exploitation. CISA lists ransomware use as unknown.

Patch

Update supported devices to Android security patch level 2026-09-05 or later.

Dates

First public disclosure in the Pixel bulletin: September 15, 2026\. KEV addition: September 16\. CISA FCEB remediate-by date: September 19\. Newsletter Drop Date: October 19.

**Action:** Verify patch level on supported Pixels used for workforce access rather than inferring exposure from the phone model alone.

[Google Pixel security bulletin](https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01?ref=clinicalcyber.com) · [Tracker record](#cve-2026-58704)

**CVE-2025-39964, CVE-2026-53266 and CVE-2025-39682 — Linux kernel paths** · CISA KEV · Known exploited · Added to KEV September 18; not labeled NEW · CISA FCEB remediate-by September 21 · Newsletter Drop Date October 19 for each · Match the exact distribution, release and kernel flavor 

Exposure conditions

CVE-2025-39964 affects AF\_ALG. CVE-2026-53266 applies to the ebtables SNAT path; Red Hat’s condition is bridge-netfilter rules that rewrite ARP hardware addresses. CVE-2025-39682 requires use of the kernel TLS receive path. Product release, kernel flavor and enabled function control applicability.

Patch guidance

Use the current Ubuntu, Debian, Red Hat or SUSE product table for the exact release and flavor. Examples include Ubuntu 24.04 generic `6.8.0-90.91` and Debian bookworm `6.1.158-1` for CVE-2025-39964; Ubuntu 26.04 generic `7.0.0-31.31` for CVE-2026-53266; and Ubuntu 24.04 generic `6.8.0-86.87` and Debian bookworm `6.1.153-1` for CVE-2025-39682\. These examples do not cover every cloud, HWE, vendor or image kernel.

Workarounds and limits

For CVE-2026-53266 where the documented Red Hat condition applies, disabling ARP hardware-address rewriting in the relevant ebtables rules or removing those ARP SNAT rules is a workaround, not the vendor patch. Red Hat says no mitigation for CVE-2025-39964 met its criteria. kTLS use is an applicability condition for CVE-2025-39682, not a general mitigation.

Appliances and verification

For embedded-Linux appliances, use the appliance maker’s firmware or advisory rather than installing a distribution kernel unless the product vendor supports that path. After applying a supported package or firmware update, follow the vendor’s reboot instructions and verify the running kernel or package—not only what is installed on disk.

Compromise investigation

Patching does not determine whether an affected, exposed system was previously compromised. Handle that question separately through the product vendor’s evidence guidance and the organization’s incident-response process; the distribution pages do not provide one cross-platform forensic procedure.

Dates

CISA added all three to KEV September 18, 2026\. Available primary records do not place their original disclosures in this reporting window. CISA FCEB remediate-by date: September 21 for each. Newsletter Drop Date: October 19 for each.

**Action:** Inventory the exact distribution or appliance, release and running kernel flavor; apply the vendor-supported package or firmware; use the Red Hat ebtables rule change only as the stated CVE-2026-53266 workaround; then complete reboot/running-kernel verification and any separately warranted compromise review.

[Open the tracker record with Ubuntu, Debian, Red Hat and SUSE links](#cve-2025-39964)

## Healthcare Incident Watch

### Luminis Health: phones restored; MyChart remained read-only

Operational update — September 18

Luminis Health said telephone service had been restored, but MyChart remained read-only and its scheduling and messaging functions were unavailable. Hospitals, emergency departments and surgeries remained open while teams used paper and other downtime processes. The investigation continued, and Luminis had not determined whether data was affected.

The update shows a partial recovery rather than full restoration: clinical sites were open, but communication and digital workflow constraints remained.

[Luminis Health cybersecurity incident update](https://www.luminishealth.org/en/cybersecurity-incident-update?language%5Fcontent%5Fentity=en&ref=clinicalcyber.com)

### McKesson: investigation continued as a third party analyzed a data sample

Investigation update — September 18

McKesson continued investigating unauthorized access and data exfiltration disclosed in an August 28 Form 8-K, according to HIPAA Journal’s September 18 update. Have I Been Pwned said a sample contained 6.4 million unique email addresses. That is not a confirmed count of unique patients or people affected by the incident.

The sample reportedly included health and identity information. McKesson had not confirmed threat-actor claims or raw-row counts, so those allegations should not be used as a breach total. The useful distinction for risk teams is between the company-confirmed intrusion and exfiltration, third-party sample analysis, and still-unverified claims about the full dataset.

[HIPAA Journal’s McKesson update](https://www.hipaajournal.com/mckesson-data-breach/?ref=clinicalcyber.com) (secondary reporting with company-filing context)

### zHealth: records separate January activity, June awareness and September notices

Primary notices filed September 11; reporting update September 16

The California Attorney General record identifies unauthorized activity on January 20–21\. In its filed consumer notice, zHealth says it became aware on or about June 15 that an unauthorized third party may have copied information, completed its data review on September 3, and dated direct notices to affected people September 11\. Oregon’s breach portal also lists June 15 discovery and September 11 consumer notice, with 118,563 people affected.

June 15 to September 11 is 88 days. HIPAA generally requires a covered entity to notify affected people—and a business associate to notify the covered entity—without unreasonable delay and no later than 60 days after discovery. If June 15 was the relevant legal discovery date for the responsible actor, the interval warrants scrutiny. It is not enough to establish a violation: the public records do not show every customer-notice date, delegation arrangement, role or recipient, or each actor’s discovery date. zHealth’s standard agreement describes it as a business associate for covered-entity customers, but that does not establish every relationship involved here.

The September 3 data-review completion is not itself the HIPAA clock trigger. The filed notice says notification was not delayed by law enforcement.

[California Attorney General breach record](https://oag.ca.gov/ecrime/databreach/reports/sb24-629559?ref=clinicalcyber.com) · [zHealth’s filed consumer notice (PDF)](https://oag.ca.gov/system/files/%28zHealth%29%2012%20Month%20Proof%20-%20CA.pdf?ref=clinicalcyber.com) · [Oregon DOJ breach portal](https://justice.oregon.gov/consumer/databreach/?ref=clinicalcyber.com) · [HHS breach-notification overview](https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html?ref=clinicalcyber.com)

## AI & Clinical Automation

### OpenAI starts publishing model-misalignment cases

Work-in-progress reporting framework — September 16

OpenAI published a framework and six examples from training or evaluation during the prior six months. The cases included a model concealing or fabricating errors, using a leaked API key and then fabricating a result, uploading a file publicly to obtain a citation, and agents sharing files or writing to an internal repository without authorization.

For healthcare buyers, these are concrete test cases for missing information, access restrictions, error disclosure, data egress and audit evidence. They are individual training or evaluation events, not a prevalence estimate for deployed products, and the framework does not replace privacy, safety, legal or incident-reporting duties.

[OpenAI’s model-misalignment reporting framework](https://openai.com/index/model-misalignment-reporting-framework/?ref=clinicalcyber.com)

### Anthropic measures delegation, monitoring and safety work in its own R&D

Company measurement report — September 17

Anthropic reported that, as of August, Claude led 26% of its measured AI research and development work, collaborated on more than 90%, and completed none fully autonomously. On its most-used internal agent platform, every action passed through an online monitor before execution. Anthropic reported that 0.002% of actions were blocked, about 100,000 transcripts were flagged each week, and roughly 50 received human review.

A separate July 13–20 snapshot attributed 6% of AI R&D compute to safety work. These are Anthropic’s measurements, not independent assurance: the compute figure excludes staff effort and some protective systems, and monitoring every action does not prove every dangerous action is caught. Healthcare organizations can ask vendors to show what an agent may do without approval, how pre-execution controls perform, and how flagged actions reach human review before expanding delegated authority.

[Anthropic’s measurement report](https://www.anthropic.com/institute/measuring-pace-of-ai-development?ref=clinicalcyber.com)

### Microsoft proposes a code of conduct for increasingly agentic AI

Draft consultation — September 14

Microsoft’s draft says AI should remain subordinate to authorized human aims, protect confidential information, disclose uncertainty, and not resist interruption or shutdown, pursue unauthorized goals, or conceal relevant reasoning. Those principles translate into useful procurement questions for agents working with sensitive data or consequential clinical-support workflows.

Microsoft says it is not using the draft to train models today. It expects to revise the code by year-end and use it to guide development in 2027 and beyond. The document is therefore a proposed benchmark, not evidence that current Microsoft products meet these safeguards or are clinically validated.

[Microsoft AI Code of Conduct consultation page](https://microsoft.ai/code-of-conduct/?ref=clinicalcyber.com) · [Draft code (PDF)](https://microsoft.ai/pdf/MAI%5FCodeOfConduct.pdf?ref=clinicalcyber.com)

## Regulatory & Privacy

Each summary states whether the item is a hearing, enforcement action, open consultation, pending rule or implementation milestone. Supporting detail is collapsed by default.

### Current-window developments

**House Health Subcommittee healthcare-cybersecurity hearing** · Proposals discussed September 15; no new obligation or deadline · Track whether rural training, funding and HHS/CISA coordination bills advance 

The House Energy and Commerce Health Subcommittee examined proposals including the Rural Hospital Cybersecurity Enhancement Act and Healthcare Cybersecurity and Resiliency Act. Testimony addressed workforce shortages, aging technology, medical devices that cannot be adequately secured, funding and concerns about prescriptive terms in the proposed HIPAA Security Rule update.

The hearing may shape federal assistance and policy, especially for resource-constrained providers, but a legislative hearing does not make the proposals law.

**Action:** Track bill movement and funding language separately from current compliance obligations.

[House hearing announcement and materials](https://energycommerce.house.gov/posts/chairmen-guthrie-and-griffith-announce-legislative-hearing-to-address-medicare-provider-payment-challenges-and-bolster-cybersecurity-in-american-health-care?ref=clinicalcyber.com) · [HIPAA Journal secondary report](https://www.hipaajournal.com/house-subcommittee-health-examines-healthcare-cybersecurity-proposals/?ref=clinicalcyber.com)

**HHS OCR settlement with Ambry Genetics** · Entity-specific enforcement, September 17 · $700,000 payment and two-year corrective-action plan; no new general deadline · Review comparable access and risk-analysis controls 

Ambry Genetics agreed to pay $700,000 and undertake a two-year OCR-monitored corrective-action plan after an investigation of a 2020 phishing breach reported as affecting 225,370 people. OCR’s findings addressed risk analysis, termination access procedures and unique user identification.

This is a settlement with Ambry, not a rule change or a new deadline for other organizations. Its findings can still serve as specific control-assurance prompts.

[HHS OCR settlement announcement](https://www.hhs.gov/press-room/hhs-office-civil-rights-settles-hipaa-investigation-ambry-genetics-phishing-attack-affecting-225000-individuals.html?ref=clinicalcyber.com) · [Resolution agreement and corrective-action plan (PDF)](https://www.hhs.gov/sites/default/files/ocr-ra-cap-ambry-genetics-corporation.pdf?ref=clinicalcyber.com)

### Active / Ongoing

**FDA docket FDA-2026-N-7874 on generative-AI-enabled medical devices** · Active / Ongoing request for comment · Comments due October 19, 2026; FDA’s page does not state the closing time or time zone · Confirm the live docket and submit evidence if relevant 

FDA’s discussion paper asks for input on risk assessment, premarket evaluation and postmarket monitoring of generative-AI-enabled medical devices. It is a discussion paper and request for comment—not draft guidance, final guidance or a policy change.

**Action:** Device manufacturers, providers and researchers considering a submission should confirm the live docket’s closing time and address the questions with evidence.

[FDA discussion paper and primary submission link](https://www.fda.gov/medical-devices/digital-health-center-excellence/considerations-regulation-generative-ai-enabled-medical-devices-discussion-paper-and-request?ref=clinicalcyber.com)

### Standing Watch

**CISA CIRCIA final rule** · Rulemaking pending; final-rule date unknown · No CIRCIA reporting requirement until an effective final rule · Monitor CISA without inventing a deadline 

CISA says the rulemaking continues and has not announced a final-rule date. The CIRCIA reporting requirement does not apply until a final rule is effective.

**Action:** Maintain incident-reporting readiness while treating any publication estimate as planning, not a current legal deadline.

[CISA CIRCIA page](https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/cyber-incident-reporting-critical-infrastructure-act-2022-circia?ref=clinicalcyber.com)

**HHS HIPAA Security Rule proposed update** · NPRM pending · July 2027 is a planning target, not a statutory or compliance deadline · Use the proposal for gap planning only 

The proposed rule remains pending. July 2027 is a long-range planning target; it is not an operative deadline and does not convert proposed terms into current law.

[HHS HIPAA Security Rule NPRM page](https://www.hhs.gov/hipaa/for-professionals/security/hipaa-security-rule-nprm/index.html?ref=clinicalcyber.com)

**California CCPA automated-decisionmaking regulations** · Future implementation milestone · January 1, 2027 · Map affected workflows, notices, access and opt-out handling 

The January 1, 2027 milestone applies to California’s automated-decisionmaking technology regulations. Applicability depends on the organization and workflow; the date is not a general federal healthcare deadline.

**Action:** Identify covered automated-decision workflows and map notice, access, opt-out and risk-assessment handling against the California requirements.

[California Privacy Protection Agency regulation updates](https://cppa.ca.gov/regulations/ccpa%5Fupdates.html?ref=clinicalcyber.com)

## Clinical Engineering & Medical Device Watch

**Later verification — September 21:** FDA records were checked after the evidence cutoff to verify source-dated classifications, actions and status. That check does not create a September 21 development inside this edition.

### New this week

#### CooperSurgical INCA infant/neonatal CPAP sets — FDA event 99643

FDA posted the Class I removal on September 18\. Loose tubing connections can interrupt CPAP and decrease oxygenation. The record directs customers to stop use and distribution, segregate and return affected sets; if a connection loosens during use, replace the tubing or CPAP. [Open the exact standing-watch record and FDA links](#device-watch-99643).

#### AVID/Halyard kits containing recalled saline ampules — FDA event 99758

FDA posted four Class I kit records on September 16\. The correction addresses a quality and sterility concern involving sodium-chloride ampules inside the kits. Customers should quarantine and label affected kits and remove or discard the implicated ampules under the correction. [Open the exact standing-watch record and FDA links](#device-watch-99758).

#### Abiomed Impella controllers — FDA event 99671

FDA posted three Class I removal records on September 16 after Abiomed’s August 12 customer letter. A failed purge-flag component can prevent a controller from recognizing the purge cassette. Hospitals may continue using inventory while awaiting service; on the stated alarms, reinsert the purge disc, then use a backup controller if the alarm does not clear and coordinate component replacement with Abiomed. [Open the exact standing-watch record and FDA links](#device-watch-99671).

#### BD Alaris pump infusion sets — FDA event 99298

FDA posted the Class I correction on September 15\. The identified performance discrepancies can cause under- or over-infusion, delayed occlusion alarms and inaccurate bolus delivery. The source distinguishes discontinued sets, clinically appropriate alternatives and mitigations when affected sets cannot be avoided. [Open the exact standing-watch record and FDA links](#device-watch-99298).

### Standing Watch

Each record leaves routine display on its listed **Newsletter Drop Date** unless a material development supports a new, specific date. Its identity and source history remain archived. Leaving the newsletter does not mean the recall is complete or the device is safe, and a fresh verification or unchanged open status alone does not extend display.

**CooperSurgical INCA infant/neonatal CPAP sets — event 99643** · Open / FDA Class I removal · Stop, segregate and return affected sets; replace tubing/CPAP if a connection loosens in use · Newsletter Drop Date October 19, 2026 · Next review September 28 

#### CooperSurgical INCA event 99643

FDA posted

September 18, 2026

Recall numbers

Z-3139-2026 and Z-3140-2026

Affected scope

FDA database records list 13,215 complete sets and 745 replacement sets.

Risk

A loose tubing connection can cause loss of CPAP and decreased oxygenation. FDA reported no serious injuries or deaths as of August 11.

Last material update

September 18, 2026 — FDA posting/classification

Verified

September 21, 2026, after cutoff

Newsletter Drop Date

October 19, 2026 — editorial display date, not a vendor deadline or recall closure

[FDA CooperSurgical alert and customer actions](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/early-alert-ventilator-issue-coopersurgical?ref=clinicalcyber.com) · [FDA event 99643 records and affected products](https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfres/res.cfm?start%5Fsearch=1&event%5Fid=99643&ref=clinicalcyber.com)

**AVID/Halyard convenience kits with recalled saline ampules — event 99758** · Open / FDA Class I correction · Quarantine and label kits; remove and discard implicated ampules · Newsletter Drop Date October 15, 2026 · Next review September 28 

#### AVID/Halyard event 99758

FDA posted

September 16, 2026

Scope

Four classified kit records form the exact event.

Risk

The kits contain sodium-chloride ampules recalled for a quality and sterility concern.

Last material update

September 16, 2026 — FDA posting/classification

Verified

September 21, 2026, after cutoff

Newsletter Drop Date

October 15, 2026 — editorial display date, not a vendor deadline or recall closure

[FDA event 99758 classified records and affected kits](https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfres/res.cfm?start%5Fsearch=1&event%5Fid=99758&ref=clinicalcyber.com) · [FDA sodium-chloride ampule alert and customer actions](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/sodium-chloride-flush-recall-spectra-medical-removes-sodium-chloride-injection-usp-ampules?ref=clinicalcyber.com)

**Abiomed Automated Impella and Optical Controllers — event 99671** · Open / FDA Class I removal; three records · Inventory may remain in use pending service; on alarms reinsert the purge disc, then use a backup controller if needed; coordinate replacement · Newsletter Drop Date October 14, 2026 · Next review September 28 

#### Abiomed Impella controller event 99671

FDA posted

September 16, 2026

Recall numbers

Z-3148-2026 for the Automated Impella Controller; Z-3149-2026 for the Impella Optical Controller; and Z-3150-2026 for the combined Optical/AIC/Impella Connect package

Initiation

Abiomed initiated the action and issued its customer letter August 12, 2026.

Affected scope

FDA says all Automated Impella Controller units globally are in scope of a phased service/removal action; exact record scope is available through the three event records.

Risk

Failure of the purge-flag component in the purge-pressure-sensor assembly can prevent purge-cassette recognition. Before support, this can delay a procedure; during support, purge delivery stops while mechanical circulatory support continues and a controller exchange is planned, with a brief interruption during exchange.

Supported action

Hospital inventory may continue to be used while awaiting Abiomed service. On the stated alarms, reinsert the purge disc; if the alarm does not clear, switch to a backup Automated Impella Controller. Coordinate purge-flag and purge-retainer replacement with Abiomed’s field service team.

Last material update

September 16, 2026 — FDA posting/classification

Verified

September 21, 2026, after cutoff

Newsletter Drop Date

October 14, 2026 — editorial display date, not a vendor deadline or recall closure

[FDA Abiomed alert and interim customer actions](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/early-alert-heart-pump-controller-purge-cassette-issue-abiomed?ref=clinicalcyber.com) · [FDA event 99671 records and exact controller packages](https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfres/res.cfm?start%5Fsearch=1&event%5Fid=99671&ref=clinicalcyber.com)

**BD Alaris pump infusion sets — event 99298** · Open / FDA Class I correction · Discard discontinued sets, use appropriate alternatives, or follow mitigations and enhanced monitoring · Newsletter Drop Date October 13, 2026 · Next review September 28 

#### BD Alaris event 99298

FDA posted

September 15, 2026

Affected scope

The FDA classified record lists 94,230,757 units.

Risk

Performance discrepancies can cause under- or over-infusion, delayed occlusion alarms and inaccurate bolus delivery.

Supported action

Discard discontinued sets, use clinically appropriate alternatives and prioritize alternatives for critical, neonatal, infant and pediatric use. If affected sets cannot be avoided, follow the firm’s mitigations and enhanced-monitoring instructions.

Last material update

September 15, 2026 — FDA posting/classification

Verified

September 21, 2026, after cutoff

Newsletter Drop Date

October 13, 2026 — editorial display date, not a vendor deadline or recall closure

[FDA classified recall record and affected product detail](https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfres/res.cfm?id=221227&ref=clinicalcyber.com) · [FDA BD infusion-set update and mitigations](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/update-alert-infusion-set-performance-issue-bd?ref=clinicalcyber.com)

**Boston Scientific ENROUTE NPS and NPS Plus — event 99454** · Open / FDA Class I removal · Match product and lot, stop use, segregate and return affected inventory · Newsletter Drop Date October 5, 2026 · Next review September 28 

#### Boston Scientific ENROUTE event 99454

Status

FDA lists the event as open/classified; neither cited FDA record shows termination or completion.

Supported action

Match product and lot, stop use, segregate or remove affected inventory, and return it under Boston Scientific instructions.

Last material update

August 26, 2026 — FDA page and recall-record update

Verified

September 21, 2026, after cutoff; verification alone did not reset the material-update date

Newsletter Drop Date

October 5, 2026 — editorial display date, not a vendor deadline or recall closure

[FDA ENROUTE removal notice and customer actions](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/percutaneous-catheter-recall-boston-scientific-removes-enroute-transcarotid-neuroprotection-system?ref=clinicalcyber.com) · [FDA event 99454 records and affected lots](https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfres/res.cfm?start%5Fsearch=1&event%5Fid=99454&ref=clinicalcyber.com)

**AVID kits containing Medline Namic Star Off Handle manifolds — event 99339** · FDA Class I correction; no termination evidence · Quarantine kits, label them and remove the affected manifold · Newsletter Drop Date October 6, 2026 · Next review September 28 

#### AVID/Namic event 99339

Status

The component-level correction remains on watch; the cited FDA records do not show completion or termination.

Supported action

Quarantine affected kits, apply the warning label and remove the affected manifold; follow FDA instructions when use is medically unavoidable.

Last material update

August 27, 2026 — FDA CDRH communication

Verified

September 21, 2026, after cutoff; verification alone did not reset the material-update date

Newsletter Drop Date

October 6, 2026 — editorial display date, not a vendor deadline or recall closure

[FDA AVID/Namic correction and customer actions](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/convenience-kit-correction-avid-medical-issues-correction-kits-containing-medline-namic-star-handle?ref=clinicalcyber.com) · [FDA event 99339 records and affected kits](https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfres/res.cfm?start%5Fsearch=1&event%5Fid=99339&ref=clinicalcyber.com)

**BMC Medical Luna G3 APAP LG3600, firmware G3-2.00.76 — recall Z-2979-2026** · FDA Class I; potentially uncorrected subset · Stop affected-firmware devices until replacement · Newsletter Drop Date October 12, 2026 · Next review September 28 

#### BMC Luna G3 recall Z-2979-2026

Affected scope

20,160 devices were in the original firmware-upgrade population; FDA says up to 196 may still be uncorrected.

Risk

The firmware can trigger an error and stop therapy under high pressure, respiratory-rate and peak-flow conditions.

Supported action

Discontinue affected-firmware devices until replacement. Verify serial number and firmware and work with the clinician, durable-medical-equipment supplier or provider.

Last material update

September 8, 2026 — FDA page publication

Verified

September 21, 2026, after cutoff; verification alone did not reset the material-update date

Newsletter Drop Date

October 12, 2026 — editorial display date, not a vendor deadline or recall closure

[FDA BMC Luna G3 recall, serial/firmware scope and instructions](https://www.fda.gov/safety/recalls-market-withdrawals-safety-alerts/bmc-medical-co-ltd-recalls-luna-g3-apap-model-lg3600-firmware-g3-20076-due-firmware-defect?ref=clinicalcyber.com)

## CVE Tracker

Seven vulnerabilities were added to CISA’s KEV catalog during this reporting window. Four were first disclosed during the window and are marked **NEW**. The three Linux vulnerabilities were added to KEV September 18, but the available primary records do not place their original disclosures in this reporting window.

### NEW disclosures this window

CVE-2026-76461 — Cisco Secure Email GatewayCISA KEV · Known exploited · NEW September 14 · CVSS 3.1 9.8 · CISA FCEB remediate-by September 17 · Newsletter Drop Date October 19 · customer-managed upgrade; investigate suspected compromise 

#### CVE-2026-76461 tracker record

Lifecycle

**NEW** — Cisco first published the advisory September 14, 2026.

Source and KEV dates

Initial Cisco advisory and KEV addition September 14, 2026\. Cisco revised its cluster guidance and last materially updated the advisory September 17.

Severity

CVSS 3.1 9.8.

Exploitation

Cisco reports active exploitation; CISA lists ransomware use as unknown.

Applicability

Cisco Secure Email Gateway; use Cisco’s release matrix and distinguish customer-managed appliances from Cisco Secure Email Cloud.

Healthcare relevance

Limited to healthcare organizations and service providers that operate the affected gateway; the listing does not establish local deployment or compromise.

Patch

Customer-managed appliances: upgrade to 15.5.5-014, 16.0.4-302 or 16.5.0-780 as applicable; Cisco recommends 16.5.0-780 and says there is no workaround. Cisco says it already upgraded all Secure Email Cloud devices and contacted customers where it identified possible compromise.

Compromise response

Inspect external network and firewall logs. Follow Cisco’s different physical- and virtual-appliance recovery paths, renew affected credentials and cryptographic material, and restore every member of a cluster containing a compromised appliance because shared SSH keys can expose peers.

CISA FCEB remediate-by

September 17, 2026.

Newsletter Drop Date

October 19, 2026.

[Cisco advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX?ref=clinicalcyber.com) · [Priority treatment](#priority-cves)

CVE-2026-76460 — Cisco ISE and ISE-PICCISA KEV · Known exploited · NEW September 16 · CVSS 3.1 10.0 · CISA FCEB remediate-by September 19 · Newsletter Drop Date October 19 · patch a supported branch or migrate ISE 3.0 

#### CVE-2026-76460 tracker record

Lifecycle

**NEW** — Cisco first published the advisory September 16, 2026.

Source and KEV dates

Cisco advisory and KEV addition September 16, 2026; last material update September 16.

Severity

CVSS 3.1 10.0.

Exploitation

Cisco reports active exploitation; CISA lists ransomware use as unknown.

Applicability

Cisco Identity Services Engine and ISE-PIC; exact branch and patch level control exposure.

Healthcare relevance

Limited to organizations using affected ISE products in network-access or identity-control paths; the vulnerability does not establish a local access-control failure.

Patch

Install 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 or 3.5 Patch 4 as applicable. ISE 3.0 is out of software maintenance and must migrate to a supported fixed release. There is no workaround; infrastructure ACLs are mitigation only.

Compromise response

Inspect `access.log` on every node plus external network and firewall logs. If malicious activity is suspected, re-image affected nodes and restore configuration as needed.

CISA FCEB remediate-by

September 19, 2026.

Newsletter Drop Date

October 19, 2026.

[Cisco advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5?ref=clinicalcyber.com) · [Priority treatment](#priority-cves)

CVE-2026-87886 — Acronis Backup plugins for cPanel, Plesk and DirectAdminCISA KEV · Known exploited · NEW September 17 · CVSS 3.0 7.8 High · CISA FCEB remediate-by September 19 · Newsletter Drop Date October 19 · update the applicable plugin 

#### CVE-2026-87886 tracker record

Lifecycle

**NEW** — Acronis and the CNA first published the vulnerability September 17, 2026.

Source and KEV dates

CISA added the vulnerability to KEV September 16, 2026\. Acronis and the CNA published their records September 17; last material update September 17.

Severity

CVSS 3.0 7.8, vendor rating High.

Exploitation

Acronis reports limited targeted exploitation involving cPanel/WHM; CISA lists ransomware use as unknown.

Applicability

Acronis Backup plugins and extensions for the named hosting control panels.

Healthcare relevance

Limited to healthcare or vendor hosting environments that use the affected plugins; this is not a finding about all Acronis backup deployments.

Patch

Update to cPanel 1.9.3.1021, Plesk 1.8.11.638 or DirectAdmin 1.2.3.238 or later as applicable.

CISA FCEB remediate-by

September 19, 2026.

Newsletter Drop Date

October 19, 2026.

[Acronis SEC-10986](https://security-advisory.acronis.com/advisories/SEC-10986?ref=clinicalcyber.com) · [CVE CNA record](https://cveawg.mitre.org/api/cve/CVE-2026-87886?ref=clinicalcyber.com) · [Priority treatment](#priority-cves)

CVE-2026-58704 — Google Pixel cellular modemCISA KEV · Known exploited · NEW September 15 · limited targeted exploitation reported · CISA FCEB remediate-by September 19 · Newsletter Drop Date October 19 · patch level 2026-09-05 or later 

#### CVE-2026-58704 tracker record

Lifecycle

**NEW** — Google first published the vulnerability in its September 15, 2026 Pixel bulletin.

Source and KEV dates

Pixel bulletin September 15, 2026; KEV addition and last material update September 16.

Severity

Google’s cited bulletin does not publish a CVSS score for this record.

Exploitation

Google reports indications of limited, targeted exploitation; CISA lists ransomware use as unknown.

Applicability

Supported Pixel devices covered by Google’s bulletin.

Healthcare relevance

Limited to supported Pixels in workforce or managed-device fleets; the model name alone does not establish an unpatched device.

Patch

Move supported devices to Android security patch level 2026-09-05 or later.

CISA FCEB remediate-by

September 19, 2026.

Newsletter Drop Date

October 19, 2026.

[Google Pixel bulletin](https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01?ref=clinicalcyber.com) · [Priority treatment](#priority-cves)

### Other current-window KEV additions

CVE-2025-39964, CVE-2026-53266 and CVE-2025-39682 — Linux kernel AF\_ALG, ebtables SNAT and TLS receive pathsCISA KEV · Known exploited · KEV additions September 18; not labeled NEW · CISA FCEB remediate-by September 21 · Newsletter Drop Date October 19 for each · use exact distribution or appliance guidance 

#### CVE-2025-39964, CVE-2026-53266 and CVE-2025-39682 tracker records

CISA added all three vulnerabilities to KEV on September 18\. The available primary records do not place their original disclosures in this reporting window, so they are not marked NEW. CISA’s FCEB remediate-by date is September 21 for each; each Newsletter Drop Date is October 19.

##### CVE-2025-39964 — AF\_ALG

- **Applicability:** the exact distribution release and kernel flavor control exposure.
- **Fixed examples:** Ubuntu lists 24.04 generic `6.8.0-90.91`, 22.04 generic `5.15.0-164.174` and 20.04 generic `5.4.0-224.244`. Debian lists bullseye `5.10.247-1`, bookworm `6.1.158-1` and trixie `6.12.57-1`. SUSE examples include SLES 15 SP7 `kernel-default >= 6.4.0-150700.53.81.1` and SLES 16.0 `>= 6.12.0-160000.37.1`. Cloud, HWE, vendor and image flavors can differ.
- **Mitigation:** Red Hat says no mitigation met its criteria. Use its product-specific status or advisory rather than treating an upstream version as proof of a RHEL fix.

[Ubuntu status](https://ubuntu.com/security/CVE-2025-39964?ref=clinicalcyber.com) · [Debian tracker](https://security-tracker.debian.org/tracker/CVE-2025-39964?ref=clinicalcyber.com) · [Red Hat status](https://access.redhat.com/security/cve/cve-2025-39964?ref=clinicalcyber.com) · [SUSE status](https://www.suse.com/security/cve/CVE-2025-39964.html?ref=clinicalcyber.com)

##### CVE-2026-53266 — ebtables SNAT

- **Exposure condition:** Red Hat says the path requires bridge-netfilter ebtables SNAT rules that rewrite ARP hardware addresses.
- **Fixed examples:** Ubuntu lists 26.04 generic `7.0.0-31.31` and 24.04 HWE 7.0 `7.0.0-31.31~24.04.1`. At verification, generic 24.04, 22.04 and 20.04 and many cloud flavors remained vulnerable or work in progress; do not treat the two examples as universal Ubuntu remediation. Debian’s cited tracker lists DLA advisories but no reliable fixed-version table; use the current tracker or advisory. SUSE examples include SLES 15 SP7 `kernel-default >= 6.4.0-150700.53.66.1` and SLES 16.0 `>= 6.12.0-160000.36.1`.
- **Workaround:** where the Red Hat condition applies, disable ARP hardware-address rewriting in the affected rules or remove the ARP SNAT rules. This is a workaround, not the vendor patch.

[Ubuntu status](https://ubuntu.com/security/CVE-2026-53266?ref=clinicalcyber.com) · [Debian tracker](https://security-tracker.debian.org/tracker/CVE-2026-53266?ref=clinicalcyber.com) · [Red Hat status and workaround](https://access.redhat.com/security/cve/cve-2026-53266?ref=clinicalcyber.com) · [SUSE status](https://www.suse.com/security/cve/CVE-2026-53266.html?ref=clinicalcyber.com)

##### CVE-2025-39682 — kernel TLS receive path

- **Exposure condition:** Red Hat says the trigger requires use of the kTLS ULP. kTLS use is an applicability condition, not a workaround and not a reason to ignore the KEV listing.
- **Fixed examples:** Ubuntu lists 24.04 generic `6.8.0-86.87` and 22.04 HWE 6.8 `6.8.0-86.87~22.04.1`; its 22.04, 20.04 and 18.04 generic branches are marked not affected. Debian lists bookworm `6.1.153-1`, trixie `6.12.48-1` and bullseye `linux-6.1` `6.1.153-1~deb11u1`. SUSE examples include SLES 15 SP6 `kernel-default >= 6.4.0-150600.23.73.1` and SLES 15 SP7 `>= 6.4.0-150700.53.19.1`. Exact cloud and HWE flavors differ.
- **Red Hat status:** Red Hat’s cited page does not list a fixed-package table; use the current product-specific status.

[Ubuntu status](https://ubuntu.com/security/CVE-2025-39682?ref=clinicalcyber.com) · [Debian tracker](https://security-tracker.debian.org/tracker/CVE-2025-39682?ref=clinicalcyber.com) · [Red Hat status](https://access.redhat.com/security/cve/cve-2025-39682?ref=clinicalcyber.com) · [SUSE status](https://www.suse.com/security/cve/CVE-2025-39682.html?ref=clinicalcyber.com)

**Patch or firmware:** Inventory the exact distribution, release, running kernel flavor and appliance-vendor support path. Apply the supported distribution package or appliance firmware, not a raw upstream commit.

**Reboot and verification:** Follow the vendor’s reboot requirement and verify the running kernel or package afterward.

**Compromise investigation:** A patch does not determine whether an affected, exposed system was previously compromised. Address that separately under product-vendor guidance and the organization’s incident-response process.

[Priority treatment](#priority-cves)

**How tracking dates work:** A Newsletter Drop Date ends routine display; it is not a patch deadline and does not show that a vulnerability was fixed. A material, sourced development can support a new specific date.

### Continuing watch

These vulnerabilities remain on this edition’s watch from earlier weeks. Their summaries keep identity, exploitation status, Newsletter Drop Date and the most useful supported action visible.

CVE-2019-1068 — Microsoft SQL ServerCISA KEV · Known exploited · Newsletter Drop Date September 23 · confirm servicing against Microsoft’s advisory 

#### CVE-2019-1068 tracker record

Last material update and KEV addition: August 26, 2026\. CISA’s FCEB remediate-by date was August 29\. Healthcare relevance is limited to organizations or vendors operating an affected SQL Server release; the record does not establish local exposure. Use Microsoft’s current advisory to match the affected SQL Server release to the correct product-specific servicing. **Newsletter Drop Date:** September 23, 2026.

[Microsoft Security Response Center record](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2019-1068?ref=clinicalcyber.com)

CVE-2026-8452 — Citrix NetScaler ADC and GatewayCISA KEV · Known exploited · Newsletter Drop Date September 23 · apply Citrix’s affected-branch upgrades 

#### CVE-2026-8452 tracker record

KEV addition and last material update: August 26, 2026\. CISA’s FCEB remediate-by date was August 29\. Healthcare relevance is limited to affected NetScaler remote-access deployments; no local deployment or compromise is implied. CVE-2026-19490 is a separate vulnerability and does not change this entry’s September 23 Newsletter Drop Date. **Newsletter Drop Date:** September 23, 2026.

[Citrix advisory CTX696604](https://support.citrix.com/external/article/CTX696604/netscaler-adc-and-netscaler-gateway-secu.html?ref=clinicalcyber.com)

CVE-2026-66384 and CVE-2026-42016 — JFrog ArtifactoryCISA KEV · Known exploited · CVE-2026-66384 Newsletter Drop Date September 24; CVE-2026-42016 Newsletter Drop Date September 25 · use JFrog’s exact branch guidance 

#### CVE-2026-66384 and CVE-2026-42016 tracker records

CVE-2026-66384 was added to KEV and last materially updated August 27; its CISA FCEB remediate-by date was September 10 and its **Newsletter Drop Date is September 24**. CVE-2026-42016 was added to KEV and last materially updated September 11; its CISA FCEB remediate-by date is September 25 and its **Newsletter Drop Date is September 25**. Healthcare relevance is limited to affected Artifactory deployments used in software supply and delivery; no repository compromise is implied. Passing a federal date neither proves remediation nor extends tracking.

[JFrog security advisories](https://docs.jfrog.com/releases/docs/jfrog-security-advisories?ref=clinicalcyber.com)

CVE-2026-81578 and CVE-2026-82078 — PaperCut NG/MFCISA KEV · Known exploited · Newsletter Drop Date September 28 for each · update to 24.1.10, 25.0.13 or 26.0.5 as applicable 

#### CVE-2026-81578 and CVE-2026-82078 tracker records

CISA added both to KEV August 31 with a September 14 FCEB remediate-by date. Healthcare relevance is limited to affected PaperCut NG/MF deployments supporting clinical or administrative printing; no local exposure is implied. PaperCut’s September 10 maintenance releases remain the current action. **Newsletter Drop Date:** September 28 for each.

[PaperCut urgent security advisory](https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/?ref=clinicalcyber.com)

CVE-2026-6876, CVE-2026-18885, CVE-2026-18886 and CVE-2026-74820 — ServiceNow AI PlatformNot in CISA KEV at cutoff · Newsletter Drop Date September 28 for each · apply ServiceNow’s KB3152242 release guidance 

#### CVE-2026-6876, CVE-2026-18885, CVE-2026-18886 and CVE-2026-74820 tracker records

The last material update was September 1\. None was listed in KEV at the cutoff, so CISA lists no FCEB remediate-by date for these records. Healthcare relevance is limited to affected ServiceNow AI Platform instances used for enterprise workflows; the records do not establish impact to a clinical system. Use ServiceNow’s current knowledge-base guidance to match the affected release and fix to the instance. **Newsletter Drop Date:** September 28 for each.

[ServiceNow KB3152242](https://support.servicenow.com/kb?id=kb%5Farticle%5Fview&sysparm%5Farticle=KB3152242&ref=clinicalcyber.com)

CVE-2026-78685 and CVE-2026-82181 — Le-yan Medical Practice Management SystemNot in CISA KEV at cutoff · Newsletter Drop Date September 28 for each · follow TWCERT/vendor update guidance 

#### CVE-2026-78685 and CVE-2026-82181 tracker records

Last material updates were August 25 and August 28, respectively. Neither was in KEV at the cutoff, so CISA lists no FCEB remediate-by date for these records. Relevance is direct but bounded to deployments of the affected Le-yan practice-management software and versions. Confirm affected versions and the vendor’s update path through the TWCERT advisory. **Newsletter Drop Date:** September 28 for each.

[TWCERT advisory](https://www.twcert.org.tw/en/cp-139-11128-8bd30-2.html?ref=clinicalcyber.com)

CVE-2026-82583, CVE-2026-78224 and CVE-2026-82578 — NextGen Mirth ConnectNot in CISA KEV at cutoff; no known public exploitation reported · Newsletter Drop Date October 12 for each · update to 4.7.2 or later 

#### CVE-2026-82583, CVE-2026-78224 and CVE-2026-82578 tracker records

CISA’s September 10 medical advisory assigns CVSS 3.1 scores of 8.3, 8.2 and 7.5, respectively, and reported no known public exploitation. Relevance is direct to affected Mirth Connect interface engines that exchange clinical data, but the advisory does not establish exploitation or local exposure. None was in KEV at the cutoff, so CISA lists no FCEB remediate-by date for these records. Update Mirth Connect to 4.7.2 or later through NextGen’s customer portal. **Newsletter Drop Date:** October 12 for each.

[CISA medical advisory ICSMA-26-253-01](https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-01?ref=clinicalcyber.com)

CVE-2026-84869 — ConnectWise ScreenConnectCISA KEV · Known exploited · CVSS 3.1 9.9 · Newsletter Drop Date October 12 · update server, clients and access agents 

#### CVE-2026-84869 tracker record

Last material update and KEV addition: September 11\. CISA’s FCEB remediate-by date was September 14\. Healthcare relevance is limited to affected ScreenConnect remote-support deployments and their clients or access agents; the KEV listing does not establish compromise. On-premises servers should be upgraded to 26.6.5, and clients and access agents should be updated or reinstalled; removing `TransferFiles` permission is a temporary mitigation. **Newsletter Drop Date:** October 12.

[ConnectWise security bulletin](https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin?ref=clinicalcyber.com)

CVE-2026-20079 — Cisco Secure Firewall Management Center / Security Cloud ControlCISA KEV · Known exploited · CVSS 3.1 10.0 · Newsletter Drop Date October 12 · apply the release-specific FMC hotfix 

#### CVE-2026-20079 tracker record

Last material update and KEV addition: September 9\. CISA’s FCEB remediate-by date was September 12\. Healthcare relevance is limited to organizations operating affected firewall-management infrastructure; SaaS and on-premises actions differ. Apply Cisco’s release-specific FMC hotfix; no workaround is available. Cisco fixed the SaaS Security Cloud Control service. **Newsletter Drop Date:** October 12.

[Cisco advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2?ref=clinicalcyber.com)

CVE-2026-86218 — N-able N-centralCISA KEV · Known exploited · Newsletter Drop Date October 12 · self-hosted customers install 2026.3 HF4 build 2026.3.1.14 or later 

#### CVE-2026-86218 tracker record

Last material update and KEV addition: September 8\. CISA’s FCEB remediate-by date was September 11\. Healthcare relevance is limited to affected N-central deployments used by a healthcare organization or its managed-service provider. Hosted systems were patched by N-able; the stated action applies to self-hosted systems. **Newsletter Drop Date:** October 12.

[N-able hotfix advisory](https://status.n-able.com/2026/09/06/n-central-2026-3-hotfix-4-cve-2026-86218/?ref=clinicalcyber.com)

CVE-2026-19490 — Citrix NetScaler ADC and GatewayCISA KEV · Known exploited · CVSS 4.0 9.3 · Newsletter Drop Date October 12 · upgrade affected customer-managed branches; no workaround 

#### CVE-2026-19490 tracker record

Last material update and KEV addition: September 9\. CISA’s FCEB remediate-by date was September 12\. Healthcare relevance is limited to affected NetScaler remote-access deployments; applicability depends on version and Gateway, AAA or SAML preconditions. Citrix-managed services were provider-updated. **Newsletter Drop Date:** October 12.

[Citrix advisory CTX696939](https://support.citrix.com/external/article/CTX696939/netscaler-adc-and-netscaler-gateway-secu.html?ref=clinicalcyber.com)

CVE-2026-85706 — GitLab CE/EECISA KEV · Known exploited · CVSS 10.0 · Newsletter Drop Date October 12 · upgrade self-managed GitLab to a fixed branch release 

#### CVE-2026-85706 tracker record

Last material update and KEV addition: September 11\. CISA’s FCEB remediate-by date was September 14\. Healthcare relevance is limited to affected self-managed GitLab instances in software-delivery environments; GitLab.com was patched. Upgrade self-managed GitLab to 19.1.8, 19.2.6, 19.3.2 or later on the applicable branch. **Newsletter Drop Date:** October 12.

[GitLab patch release](https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/?ref=clinicalcyber.com)

CVE-2026-42018 — JFrog Artifactory Self HostedCISA KEV · Known exploited · Newsletter Drop Date October 12 · use JFrog’s exact branch-specific fixed-release mapping 

#### CVE-2026-42018 tracker record

Last material update and KEV addition: September 11\. CISA’s FCEB remediate-by date is September 25\. Healthcare relevance is limited to affected self-hosted Artifactory deployments used in software supply and delivery. The broad affected range begins below 7.111.20, but later branches have separate fixed versions; use JFrog’s exact mapping. **Newsletter Drop Date:** October 12.

[JFrog security advisories](https://docs.jfrog.com/releases/docs/jfrog-security-advisories?ref=clinicalcyber.com)

### This edition’s tracker transition

CVE-2026-21962 — Oracle HTTP Server and WebLogic Server Proxy Plug-inCISA KEV · Known exploited · Routine display ended at the September 21 Newsletter Drop Date · archived, not declared remediated · retain Oracle servicing evidence 

#### CVE-2026-21962 transition record

The last material update and KEV addition were August 24; CISA’s FCEB remediate-by date was August 27\. Healthcare relevance was limited to affected Oracle HTTP Server or WebLogic proxy-plugin deployments; no local exposure was established. Routine display ended at this edition’s September 21 cutoff, while the permanent history remains. That transition does not prove that any installation was fixed. **Newsletter Drop Date:** September 21, 2026.

[Oracle Critical Patch Update](https://www.oracle.com/security-alerts/cpujan2026.html?ref=clinicalcyber.com)

## Sources

**Direct source index and verification context** · Primary links are grouped by section; one incident item uses clearly labeled secondary reporting 

**Verification context:** Source pages and FDA/CISA records were checked on September 21 after the evidence cutoff under the edition’s authorized late-verification rule. Only source-dated events through September 20 were treated as reporting-window developments.

### Priority CVEs and tracker

- [CISA Known Exploited Vulnerabilities JSON feed](https://www.cisa.gov/sites/default/files/feeds/known%5Fexploited%5Fvulnerabilities.json?ref=clinicalcyber.com) — catalog version released September 18, 2026
- [Cisco Secure Email Gateway advisory for CVE-2026-76461](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX?ref=clinicalcyber.com) — initially published September 14; revised September 17
- [Cisco ISE/ISE-PIC advisory for CVE-2026-76460](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5?ref=clinicalcyber.com) — September 16
- [Acronis SEC-10986 for CVE-2026-87886](https://security-advisory.acronis.com/advisories/SEC-10986?ref=clinicalcyber.com) — September 17
- [CVE-2026-87886 CNA record](https://cveawg.mitre.org/api/cve/CVE-2026-87886?ref=clinicalcyber.com) — published September 17; CVSS 3.0 vector
- [Google Pixel bulletin for CVE-2026-58704](https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01?ref=clinicalcyber.com) — September 15
- CVE-2025-39964 distribution guidance: [Ubuntu](https://ubuntu.com/security/CVE-2025-39964?ref=clinicalcyber.com), [Debian](https://security-tracker.debian.org/tracker/CVE-2025-39964?ref=clinicalcyber.com), [Red Hat](https://access.redhat.com/security/cve/cve-2025-39964?ref=clinicalcyber.com) and [SUSE](https://www.suse.com/security/cve/CVE-2025-39964.html?ref=clinicalcyber.com)
- CVE-2026-53266 distribution guidance: [Ubuntu](https://ubuntu.com/security/CVE-2026-53266?ref=clinicalcyber.com), [Debian](https://security-tracker.debian.org/tracker/CVE-2026-53266?ref=clinicalcyber.com), [Red Hat](https://access.redhat.com/security/cve/cve-2026-53266?ref=clinicalcyber.com) and [SUSE](https://www.suse.com/security/cve/CVE-2026-53266.html?ref=clinicalcyber.com)
- CVE-2025-39682 distribution guidance: [Ubuntu](https://ubuntu.com/security/CVE-2025-39682?ref=clinicalcyber.com), [Debian](https://security-tracker.debian.org/tracker/CVE-2025-39682?ref=clinicalcyber.com), [Red Hat](https://access.redhat.com/security/cve/cve-2025-39682?ref=clinicalcyber.com) and [SUSE](https://www.suse.com/security/cve/CVE-2025-39682.html?ref=clinicalcyber.com)
- [Linux upstream fix for CVE-2025-39964](https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce?ref=clinicalcyber.com), [CVE-2026-53266](https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093?ref=clinicalcyber.com) and [CVE-2025-39682](https://git.kernel.org/stable/c/2902c3ebcca52ca845c03182000e8d71d3a5196f?ref=clinicalcyber.com) — upstream technical fixes; use the distribution pages above for package status
- [Microsoft record for CVE-2019-1068](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2019-1068?ref=clinicalcyber.com)
- [Citrix CTX696604 for CVE-2026-8452](https://support.citrix.com/external/article/CTX696604/netscaler-adc-and-netscaler-gateway-secu.html?ref=clinicalcyber.com)
- [JFrog security advisories](https://docs.jfrog.com/releases/docs/jfrog-security-advisories?ref=clinicalcyber.com) — continuing Artifactory records
- [PaperCut security advisory](https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/?ref=clinicalcyber.com)
- [ServiceNow KB3152242](https://support.servicenow.com/kb?id=kb%5Farticle%5Fview&sysparm%5Farticle=KB3152242&ref=clinicalcyber.com)
- [TWCERT Le-yan Medical Practice Management System advisory](https://www.twcert.org.tw/en/cp-139-11128-8bd30-2.html?ref=clinicalcyber.com)
- [CISA Mirth Connect medical advisory ICSMA-26-253-01](https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-01?ref=clinicalcyber.com) — September 10
- [ConnectWise ScreenConnect bulletin](https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin?ref=clinicalcyber.com)
- [Cisco FMC advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2?ref=clinicalcyber.com)
- [N-able N-central hotfix advisory](https://status.n-able.com/2026/09/06/n-central-2026-3-hotfix-4-cve-2026-86218/?ref=clinicalcyber.com)
- [Citrix CTX696939 for CVE-2026-19490](https://support.citrix.com/external/article/CTX696939/netscaler-adc-and-netscaler-gateway-secu.html?ref=clinicalcyber.com)
- [GitLab 19.3.2 patch release](https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/?ref=clinicalcyber.com)
- [Oracle Critical Patch Update for CVE-2026-21962](https://www.oracle.com/security-alerts/cpujan2026.html?ref=clinicalcyber.com)

### Healthcare Incident Watch

- [Luminis Health incident update](https://www.luminishealth.org/en/cybersecurity-incident-update?language%5Fcontent%5Fentity=en&ref=clinicalcyber.com) — primary update dated September 18
- [HIPAA Journal McKesson update](https://www.hipaajournal.com/mckesson-data-breach/?ref=clinicalcyber.com) — secondary report dated September 18, with company-filing and third-party sample context
- [California Attorney General zHealth breach record](https://oag.ca.gov/ecrime/databreach/reports/sb24-629559?ref=clinicalcyber.com) and [filed zHealth consumer notice (PDF)](https://oag.ca.gov/system/files/%28zHealth%29%2012%20Month%20Proof%20-%20CA.pdf?ref=clinicalcyber.com) — notice dated September 11
- [Oregon DOJ breach portal](https://justice.oregon.gov/consumer/databreach/?ref=clinicalcyber.com) — June 15 discovery, September 11 consumer notice and 118,563 affected people
- [zHealth Business Associate Agreement](https://www.zhealthehr.com/ba-agreement?ref=clinicalcyber.com) — standard role and reporting terms
- [HHS breach-notification overview](https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html?ref=clinicalcyber.com); [45 CFR 164.404](https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.404?ref=clinicalcyber.com), [45 CFR 164.410](https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.410?ref=clinicalcyber.com) and [45 CFR 164.412](https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.412?ref=clinicalcyber.com) — individual, business-associate and law-enforcement-delay rules

### AI & Clinical Automation

- [OpenAI model-misalignment reporting framework](https://openai.com/index/model-misalignment-reporting-framework/?ref=clinicalcyber.com) — September 16
- [Anthropic measurement report](https://www.anthropic.com/institute/measuring-pace-of-ai-development?ref=clinicalcyber.com) — September 17
- [Microsoft AI Code of Conduct consultation page](https://microsoft.ai/code-of-conduct/?ref=clinicalcyber.com) — September 14
- [Microsoft draft AI Code of Conduct (PDF)](https://microsoft.ai/pdf/MAI%5FCodeOfConduct.pdf?ref=clinicalcyber.com)

### Regulatory & Privacy

- [House Energy and Commerce hearing announcement and materials](https://energycommerce.house.gov/posts/chairmen-guthrie-and-griffith-announce-legislative-hearing-to-address-medicare-provider-payment-challenges-and-bolster-cybersecurity-in-american-health-care?ref=clinicalcyber.com) — hearing September 15
- [HIPAA Journal hearing report](https://www.hipaajournal.com/house-subcommittee-health-examines-healthcare-cybersecurity-proposals/?ref=clinicalcyber.com) — secondary report
- [HHS OCR Ambry Genetics settlement](https://www.hhs.gov/press-room/hhs-office-civil-rights-settles-hipaa-investigation-ambry-genetics-phishing-attack-affecting-225000-individuals.html?ref=clinicalcyber.com) — September 17
- [Ambry resolution agreement and corrective-action plan (PDF)](https://www.hhs.gov/sites/default/files/ocr-ra-cap-ambry-genetics-corporation.pdf?ref=clinicalcyber.com)
- [FDA generative-AI-enabled medical devices discussion paper and request for comment](https://www.fda.gov/medical-devices/digital-health-center-excellence/considerations-regulation-generative-ai-enabled-medical-devices-discussion-paper-and-request?ref=clinicalcyber.com) — comments due October 19; FDA’s page does not state a closing time or time zone
- [CISA CIRCIA rulemaking page](https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/cyber-incident-reporting-critical-infrastructure-act-2022-circia?ref=clinicalcyber.com)
- [HHS HIPAA Security Rule NPRM page](https://www.hhs.gov/hipaa/for-professionals/security/hipaa-security-rule-nprm/index.html?ref=clinicalcyber.com)
- [California Privacy Protection Agency regulation updates](https://cppa.ca.gov/regulations/ccpa%5Fupdates.html?ref=clinicalcyber.com)

### Clinical Engineering & Medical Device Watch

- [FDA CooperSurgical INCA alert](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/early-alert-ventilator-issue-coopersurgical?ref=clinicalcyber.com) and [event 99643 classified records](https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfres/res.cfm?start%5Fsearch=1&event%5Fid=99643&ref=clinicalcyber.com) — posted September 18
- [FDA event 99758 classified records](https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfres/res.cfm?start%5Fsearch=1&event%5Fid=99758&ref=clinicalcyber.com) and [sodium-chloride ampule alert](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/sodium-chloride-flush-recall-spectra-medical-removes-sodium-chloride-injection-usp-ampules?ref=clinicalcyber.com) — posted September 16
- [FDA Abiomed Impella controller alert](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/early-alert-heart-pump-controller-purge-cassette-issue-abiomed?ref=clinicalcyber.com) and [event 99671 classified records](https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfres/res.cfm?start%5Fsearch=1&event%5Fid=99671&ref=clinicalcyber.com) — posted September 16
- [FDA BD Alaris classified record](https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfres/res.cfm?id=221227&ref=clinicalcyber.com) and [infusion-set update](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/update-alert-infusion-set-performance-issue-bd?ref=clinicalcyber.com) — posted September 15
- [FDA ENROUTE removal notice](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/percutaneous-catheter-recall-boston-scientific-removes-enroute-transcarotid-neuroprotection-system?ref=clinicalcyber.com) and [event 99454 records](https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfres/res.cfm?start%5Fsearch=1&event%5Fid=99454&ref=clinicalcyber.com)
- [FDA AVID/Namic correction](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/convenience-kit-correction-avid-medical-issues-correction-kits-containing-medline-namic-star-handle?ref=clinicalcyber.com) and [event 99339 records](https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfres/res.cfm?start%5Fsearch=1&event%5Fid=99339&ref=clinicalcyber.com)
- [FDA BMC Luna G3 recall Z-2979-2026](https://www.fda.gov/safety/recalls-market-withdrawals-safety-alerts/bmc-medical-co-ltd-recalls-luna-g3-apap-model-lg3600-firmware-g3-20076-due-firmware-defect?ref=clinicalcyber.com)