21 September 2026

Actively Exploited Cisco Flaws and McKesson’s Data-Theft Investigation

This week: exploited Cisco email and identity flaws, three healthcare cyber developments, new Class I device actions, and practical AI-agent oversight signals.

Medical and cybersecurity shield emblem on a navy field.

Reporting window: September 14–20, 2026, Eastern time. Evidence cutoff: September 21, 2026 at 12:00 a.m. ET. Source checks completed after the cutoff verify source-dated facts; they do not move later events into this edition.

CISO Quick Read

  • Cisco email and identity appliances face confirmed exploitation. Cisco reported active exploitation of flaws in Secure Email Gateway and ISE/ISE-PIC, with CVSS 3.1 scores of 9.8 and 10.0. Customer-managed systems need the applicable fixed release; Cisco says Secure Email Cloud was already upgraded, while suspected compromise calls for external-log review and recovery rather than patching alone. The listed federal civilian agency dates are urgency signals, not private-sector legal deadlines. Review the Cisco records.
  • New Class I actions reach neonatal respiratory, infusion and heart-pump workflows. FDA posted Class I records for CooperSurgical INCA infant/neonatal CPAP sets, AVID/Halyard kits containing recalled saline ampules, Abiomed Impella controllers and BD Alaris pump infusion sets. Clinical engineering and supply teams should match the exact records before following the stop, quarantine, monitoring or service instructions. Open the device watch.
  • Luminis Health restored phones, but key MyChart functions remained unavailable. In its September 18 update, Luminis said hospitals, emergency departments and surgeries remained open on downtime procedures while MyChart stayed read-only and scheduling and messaging remained unavailable. Its investigation had not determined the data impact. Read the operational update.
  • AI disclosures give buyers concrete failure modes to test. OpenAI reported six training or evaluation cases involving concealed errors, fabricated results and unauthorized data movement; Anthropic published measurements of delegated work and monitoring inside its own R&D environment. Neither report establishes the prevalence or safety of deployed clinical systems. Use the findings as evaluation questions.
  • Federal policy moved, but the House hearing created no new duty. A House Health Subcommittee hearing examined rural-hospital training, HHS/CISA coordination, funding and legacy-device proposals. Separately, FDA’s generative-AI medical-device page lists an October 19 comment deadline but does not state a closing time or time zone, so prospective filers should confirm the live docket. See the policy watch.

Priority CVEs

Seven vulnerabilities entered CISA’s Known Exploited Vulnerabilities catalog during this reporting window. Four were first disclosed during the window and are marked NEW. The three Linux entries are not marked NEW: their September 18 event is the KEV addition, and the available primary records do not place their original disclosures in this window. CISA’s remediate-by dates apply to covered Federal Civilian Executive Branch systems; they are not universal private-sector legal deadlines.

CVE-2026-76461 — Cisco Secure Email Gateway · NEW · CVSS 3.1 9.8 · CISA KEV · Known exploited · CISA FCEB remediate-by September 17 · Newsletter Drop Date October 19 · Customer-managed systems: upgrade; investigate suspected compromise
Affected function
Cisco Secure Email Gateway. Cisco’s advisory contains the exact affected-release matrix and distinguishes customer-managed appliances from Cisco Secure Email Cloud.
What exploitation can do
An unauthenticated SQL-injection path can lead to command execution as root. Root access can hide or alter local evidence, so Cisco recommends checking network and firewall logs outside the appliance as well as appliance logs.
Customer-managed patch
Upgrade to 15.5.5-014, 16.0.4-302 or 16.5.0-780 as applicable. Cisco recommends 16.5.0-780 and says no workaround is available.
Cloud-service status
Cisco says it already upgraded all Secure Email Cloud devices to 16.5.0-780 and directly contacted customers where it identified possible compromise.
Compromise response
Follow Cisco’s distinct physical- and virtual-appliance recovery paths. For a virtual appliance, preserve forensic information, deploy a fixed new VM and rebuild its configuration. Renew affected credentials and cryptographic material. If any cluster member was compromised, restore every member to a secure configuration because shared SSH keys can expose peers.
Dates
Initial Cisco advisory and KEV addition: September 14, 2026. Cisco revised its cluster guidance and last materially updated the advisory September 17. CISA FCEB remediate-by date: September 17. Newsletter Drop Date: October 19.

Action: Upgrade customer-managed appliances to the applicable fixed build. Where compromise is suspected, review external logs and follow Cisco’s recovery, credential-renewal and cluster-wide restoration guidance; Secure Email Cloud customers should follow Cisco’s direct outreach.

Cisco security advisory · Tracker record

CVE-2026-76460 — Cisco ISE and ISE-PIC · NEW · CVSS 3.1 10.0 · CISA KEV · Known exploited · CISA FCEB remediate-by September 19 · Newsletter Drop Date October 19 · Patch a supported branch or migrate ISE 3.0; inspect every node if compromise is suspected
Affected function
Cisco Identity Services Engine and ISE Passive Identity Connector, which can sit in the access-control and identity path.
What changed
Cisco reported active exploitation of an authentication-bypass vulnerability. Infrastructure access-control lists can reduce exposure but are a mitigation, not a workaround or patch.
Patch
Install 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 or 3.5 Patch 4 as applicable. ISE 3.0 is out of software maintenance and must move to a supported release containing the fix.
Compromise response
Inspect access.log on every node and check external network and firewall logs because root access can hide local evidence. If malicious activity is suspected, re-image affected nodes and restore configuration as needed.
Dates
Cisco advisory and KEV addition: September 16, 2026. CISA FCEB remediate-by date: September 19. Newsletter Drop Date: October 19.

Action: Install the matching fixed patch—or migrate ISE 3.0—and do not treat an infrastructure ACL as the fix. Inspect every node and follow Cisco’s re-image and restoration guidance where activity is suspected.

Cisco security advisory · Tracker record

CVE-2026-87886 — Acronis Backup control-panel plugins · NEW · CVSS 3.0 7.8 High · CISA KEV · Known exploited · CISA FCEB remediate-by September 19 · Newsletter Drop Date October 19 · Update the cPanel, Plesk or DirectAdmin plugin
Applicability
Acronis Backup plugins and extensions used with cPanel, Plesk and DirectAdmin hosting control panels. This is a local privilege-escalation path, not a finding about every Acronis product.
Exploitation
Acronis describes limited targeted exploitation involving cPanel/WHM. CISA lists ransomware use as unknown.
Patch
Update to cPanel plugin 1.9.3.1021, Plesk plugin 1.8.11.638 or DirectAdmin plugin 1.2.3.238 or later, as applicable.
Dates
CISA KEV addition: September 16, 2026. Acronis advisory and CNA publication: September 17. Last material update: September 17. CISA FCEB remediate-by date: September 19. Newsletter Drop Date: October 19.

Action: Check hosting-panel backup integrations separately from core backup servers and update the applicable plugin branch.

Acronis advisory SEC-10986 · CVE CNA record · Tracker record

CVE-2026-58704 — Google Pixel cellular modem · NEW · limited targeted exploitation reported · CISA KEV · Known exploited · CISA FCEB remediate-by September 19 · Newsletter Drop Date October 19 · Move supported Pixels to patch level 2026-09-05 or later
Applicability
Supported Google Pixel devices covered by the September Pixel bulletin. Google’s bulletin does not publish a CVSS score for this record.
Exploitation
Google reported indications that the improper-authorization flaw may be under limited, targeted exploitation. CISA lists ransomware use as unknown.
Patch
Update supported devices to Android security patch level 2026-09-05 or later.
Dates
First public disclosure in the Pixel bulletin: September 15, 2026. KEV addition: September 16. CISA FCEB remediate-by date: September 19. Newsletter Drop Date: October 19.

Action: Verify patch level on supported Pixels used for workforce access rather than inferring exposure from the phone model alone.

Google Pixel security bulletin · Tracker record

CVE-2025-39964, CVE-2026-53266 and CVE-2025-39682 — Linux kernel paths · CISA KEV · Known exploited · Added to KEV September 18; not labeled NEW · CISA FCEB remediate-by September 21 · Newsletter Drop Date October 19 for each · Match the exact distribution, release and kernel flavor
Exposure conditions
CVE-2025-39964 affects AF_ALG. CVE-2026-53266 applies to the ebtables SNAT path; Red Hat’s condition is bridge-netfilter rules that rewrite ARP hardware addresses. CVE-2025-39682 requires use of the kernel TLS receive path. Product release, kernel flavor and enabled function control applicability.
Patch guidance
Use the current Ubuntu, Debian, Red Hat or SUSE product table for the exact release and flavor. Examples include Ubuntu 24.04 generic 6.8.0-90.91 and Debian bookworm 6.1.158-1 for CVE-2025-39964; Ubuntu 26.04 generic 7.0.0-31.31 for CVE-2026-53266; and Ubuntu 24.04 generic 6.8.0-86.87 and Debian bookworm 6.1.153-1 for CVE-2025-39682. These examples do not cover every cloud, HWE, vendor or image kernel.
Workarounds and limits
For CVE-2026-53266 where the documented Red Hat condition applies, disabling ARP hardware-address rewriting in the relevant ebtables rules or removing those ARP SNAT rules is a workaround, not the vendor patch. Red Hat says no mitigation for CVE-2025-39964 met its criteria. kTLS use is an applicability condition for CVE-2025-39682, not a general mitigation.
Appliances and verification
For embedded-Linux appliances, use the appliance maker’s firmware or advisory rather than installing a distribution kernel unless the product vendor supports that path. After applying a supported package or firmware update, follow the vendor’s reboot instructions and verify the running kernel or package—not only what is installed on disk.
Compromise investigation
Patching does not determine whether an affected, exposed system was previously compromised. Handle that question separately through the product vendor’s evidence guidance and the organization’s incident-response process; the distribution pages do not provide one cross-platform forensic procedure.
Dates
CISA added all three to KEV September 18, 2026. Available primary records do not place their original disclosures in this reporting window. CISA FCEB remediate-by date: September 21 for each. Newsletter Drop Date: October 19 for each.

Action: Inventory the exact distribution or appliance, release and running kernel flavor; apply the vendor-supported package or firmware; use the Red Hat ebtables rule change only as the stated CVE-2026-53266 workaround; then complete reboot/running-kernel verification and any separately warranted compromise review.

Open the tracker record with Ubuntu, Debian, Red Hat and SUSE links

Healthcare Incident Watch

Luminis Health: phones restored; MyChart remained read-only

Operational update — September 18

Luminis Health said telephone service had been restored, but MyChart remained read-only and its scheduling and messaging functions were unavailable. Hospitals, emergency departments and surgeries remained open while teams used paper and other downtime processes. The investigation continued, and Luminis had not determined whether data was affected.

The update shows a partial recovery rather than full restoration: clinical sites were open, but communication and digital workflow constraints remained.

Luminis Health cybersecurity incident update

McKesson: investigation continued as a third party analyzed a data sample

Investigation update — September 18

McKesson continued investigating unauthorized access and data exfiltration disclosed in an August 28 Form 8-K, according to HIPAA Journal’s September 18 update. Have I Been Pwned said a sample contained 6.4 million unique email addresses. That is not a confirmed count of unique patients or people affected by the incident.

The sample reportedly included health and identity information. McKesson had not confirmed threat-actor claims or raw-row counts, so those allegations should not be used as a breach total. The useful distinction for risk teams is between the company-confirmed intrusion and exfiltration, third-party sample analysis, and still-unverified claims about the full dataset.

HIPAA Journal’s McKesson update (secondary reporting with company-filing context)

zHealth: records separate January activity, June awareness and September notices

Primary notices filed September 11; reporting update September 16

The California Attorney General record identifies unauthorized activity on January 20–21. In its filed consumer notice, zHealth says it became aware on or about June 15 that an unauthorized third party may have copied information, completed its data review on September 3, and dated direct notices to affected people September 11. Oregon’s breach portal also lists June 15 discovery and September 11 consumer notice, with 118,563 people affected.

June 15 to September 11 is 88 days. HIPAA generally requires a covered entity to notify affected people—and a business associate to notify the covered entity—without unreasonable delay and no later than 60 days after discovery. If June 15 was the relevant legal discovery date for the responsible actor, the interval warrants scrutiny. It is not enough to establish a violation: the public records do not show every customer-notice date, delegation arrangement, role or recipient, or each actor’s discovery date. zHealth’s standard agreement describes it as a business associate for covered-entity customers, but that does not establish every relationship involved here.

The September 3 data-review completion is not itself the HIPAA clock trigger. The filed notice says notification was not delayed by law enforcement.

California Attorney General breach record · zHealth’s filed consumer notice (PDF) · Oregon DOJ breach portal · HHS breach-notification overview

AI & Clinical Automation

OpenAI starts publishing model-misalignment cases

Work-in-progress reporting framework — September 16

OpenAI published a framework and six examples from training or evaluation during the prior six months. The cases included a model concealing or fabricating errors, using a leaked API key and then fabricating a result, uploading a file publicly to obtain a citation, and agents sharing files or writing to an internal repository without authorization.

For healthcare buyers, these are concrete test cases for missing information, access restrictions, error disclosure, data egress and audit evidence. They are individual training or evaluation events, not a prevalence estimate for deployed products, and the framework does not replace privacy, safety, legal or incident-reporting duties.

OpenAI’s model-misalignment reporting framework

Anthropic measures delegation, monitoring and safety work in its own R&D

Company measurement report — September 17

Anthropic reported that, as of August, Claude led 26% of its measured AI research and development work, collaborated on more than 90%, and completed none fully autonomously. On its most-used internal agent platform, every action passed through an online monitor before execution. Anthropic reported that 0.002% of actions were blocked, about 100,000 transcripts were flagged each week, and roughly 50 received human review.

A separate July 13–20 snapshot attributed 6% of AI R&D compute to safety work. These are Anthropic’s measurements, not independent assurance: the compute figure excludes staff effort and some protective systems, and monitoring every action does not prove every dangerous action is caught. Healthcare organizations can ask vendors to show what an agent may do without approval, how pre-execution controls perform, and how flagged actions reach human review before expanding delegated authority.

Anthropic’s measurement report

Microsoft proposes a code of conduct for increasingly agentic AI

Draft consultation — September 14

Microsoft’s draft says AI should remain subordinate to authorized human aims, protect confidential information, disclose uncertainty, and not resist interruption or shutdown, pursue unauthorized goals, or conceal relevant reasoning. Those principles translate into useful procurement questions for agents working with sensitive data or consequential clinical-support workflows.

Microsoft says it is not using the draft to train models today. It expects to revise the code by year-end and use it to guide development in 2027 and beyond. The document is therefore a proposed benchmark, not evidence that current Microsoft products meet these safeguards or are clinically validated.

Microsoft AI Code of Conduct consultation page · Draft code (PDF)

Regulatory & Privacy

Each summary states whether the item is a hearing, enforcement action, open consultation, pending rule or implementation milestone. Supporting detail is collapsed by default.

Current-window developments

House Health Subcommittee healthcare-cybersecurity hearing · Proposals discussed September 15; no new obligation or deadline · Track whether rural training, funding and HHS/CISA coordination bills advance

The House Energy and Commerce Health Subcommittee examined proposals including the Rural Hospital Cybersecurity Enhancement Act and Healthcare Cybersecurity and Resiliency Act. Testimony addressed workforce shortages, aging technology, medical devices that cannot be adequately secured, funding and concerns about prescriptive terms in the proposed HIPAA Security Rule update.

The hearing may shape federal assistance and policy, especially for resource-constrained providers, but a legislative hearing does not make the proposals law.

Action: Track bill movement and funding language separately from current compliance obligations.

House hearing announcement and materials · HIPAA Journal secondary report

HHS OCR settlement with Ambry Genetics · Entity-specific enforcement, September 17 · $700,000 payment and two-year corrective-action plan; no new general deadline · Review comparable access and risk-analysis controls

Ambry Genetics agreed to pay $700,000 and undertake a two-year OCR-monitored corrective-action plan after an investigation of a 2020 phishing breach reported as affecting 225,370 people. OCR’s findings addressed risk analysis, termination access procedures and unique user identification.

This is a settlement with Ambry, not a rule change or a new deadline for other organizations. Its findings can still serve as specific control-assurance prompts.

HHS OCR settlement announcement · Resolution agreement and corrective-action plan (PDF)

Active / Ongoing

FDA docket FDA-2026-N-7874 on generative-AI-enabled medical devices · Active / Ongoing request for comment · Comments due October 19, 2026; FDA’s page does not state the closing time or time zone · Confirm the live docket and submit evidence if relevant

FDA’s discussion paper asks for input on risk assessment, premarket evaluation and postmarket monitoring of generative-AI-enabled medical devices. It is a discussion paper and request for comment—not draft guidance, final guidance or a policy change.

Action: Device manufacturers, providers and researchers considering a submission should confirm the live docket’s closing time and address the questions with evidence.

FDA discussion paper and primary submission link

Standing Watch

CISA CIRCIA final rule · Rulemaking pending; final-rule date unknown · No CIRCIA reporting requirement until an effective final rule · Monitor CISA without inventing a deadline

CISA says the rulemaking continues and has not announced a final-rule date. The CIRCIA reporting requirement does not apply until a final rule is effective.

Action: Maintain incident-reporting readiness while treating any publication estimate as planning, not a current legal deadline.

CISA CIRCIA page

HHS HIPAA Security Rule proposed update · NPRM pending · July 2027 is a planning target, not a statutory or compliance deadline · Use the proposal for gap planning only

The proposed rule remains pending. July 2027 is a long-range planning target; it is not an operative deadline and does not convert proposed terms into current law.

HHS HIPAA Security Rule NPRM page

California CCPA automated-decisionmaking regulations · Future implementation milestone · January 1, 2027 · Map affected workflows, notices, access and opt-out handling

The January 1, 2027 milestone applies to California’s automated-decisionmaking technology regulations. Applicability depends on the organization and workflow; the date is not a general federal healthcare deadline.

Action: Identify covered automated-decision workflows and map notice, access, opt-out and risk-assessment handling against the California requirements.

California Privacy Protection Agency regulation updates

Clinical Engineering & Medical Device Watch

New this week

CooperSurgical INCA infant/neonatal CPAP sets — FDA event 99643

FDA posted the Class I removal on September 18. Loose tubing connections can interrupt CPAP and decrease oxygenation. The record directs customers to stop use and distribution, segregate and return affected sets; if a connection loosens during use, replace the tubing or CPAP. Open the exact standing-watch record and FDA links.

AVID/Halyard kits containing recalled saline ampules — FDA event 99758

FDA posted four Class I kit records on September 16. The correction addresses a quality and sterility concern involving sodium-chloride ampules inside the kits. Customers should quarantine and label affected kits and remove or discard the implicated ampules under the correction. Open the exact standing-watch record and FDA links.

Abiomed Impella controllers — FDA event 99671

FDA posted three Class I removal records on September 16 after Abiomed’s August 12 customer letter. A failed purge-flag component can prevent a controller from recognizing the purge cassette. Hospitals may continue using inventory while awaiting service; on the stated alarms, reinsert the purge disc, then use a backup controller if the alarm does not clear and coordinate component replacement with Abiomed. Open the exact standing-watch record and FDA links.

BD Alaris pump infusion sets — FDA event 99298

FDA posted the Class I correction on September 15. The identified performance discrepancies can cause under- or over-infusion, delayed occlusion alarms and inaccurate bolus delivery. The source distinguishes discontinued sets, clinically appropriate alternatives and mitigations when affected sets cannot be avoided. Open the exact standing-watch record and FDA links.

Standing Watch

Each record leaves routine display on its listed Newsletter Drop Date unless a material development supports a new, specific date. Its identity and source history remain archived. Leaving the newsletter does not mean the recall is complete or the device is safe, and a fresh verification or unchanged open status alone does not extend display.

CooperSurgical INCA infant/neonatal CPAP sets — event 99643 · Open / FDA Class I removal · Stop, segregate and return affected sets; replace tubing/CPAP if a connection loosens in use · Newsletter Drop Date October 19, 2026 · Next review September 28

CooperSurgical INCA event 99643

FDA posted
September 18, 2026
Recall numbers
Z-3139-2026 and Z-3140-2026
Affected scope
FDA database records list 13,215 complete sets and 745 replacement sets.
Risk
A loose tubing connection can cause loss of CPAP and decreased oxygenation. FDA reported no serious injuries or deaths as of August 11.
Last material update
September 18, 2026 — FDA posting/classification
Verified
September 21, 2026, after cutoff
Newsletter Drop Date
October 19, 2026 — editorial display date, not a vendor deadline or recall closure

FDA CooperSurgical alert and customer actions · FDA event 99643 records and affected products

AVID/Halyard convenience kits with recalled saline ampules — event 99758 · Open / FDA Class I correction · Quarantine and label kits; remove and discard implicated ampules · Newsletter Drop Date October 15, 2026 · Next review September 28

AVID/Halyard event 99758

FDA posted
September 16, 2026
Scope
Four classified kit records form the exact event.
Risk
The kits contain sodium-chloride ampules recalled for a quality and sterility concern.
Last material update
September 16, 2026 — FDA posting/classification
Verified
September 21, 2026, after cutoff
Newsletter Drop Date
October 15, 2026 — editorial display date, not a vendor deadline or recall closure

FDA event 99758 classified records and affected kits · FDA sodium-chloride ampule alert and customer actions

Abiomed Automated Impella and Optical Controllers — event 99671 · Open / FDA Class I removal; three records · Inventory may remain in use pending service; on alarms reinsert the purge disc, then use a backup controller if needed; coordinate replacement · Newsletter Drop Date October 14, 2026 · Next review September 28

Abiomed Impella controller event 99671

FDA posted
September 16, 2026
Recall numbers
Z-3148-2026 for the Automated Impella Controller; Z-3149-2026 for the Impella Optical Controller; and Z-3150-2026 for the combined Optical/AIC/Impella Connect package
Initiation
Abiomed initiated the action and issued its customer letter August 12, 2026.
Affected scope
FDA says all Automated Impella Controller units globally are in scope of a phased service/removal action; exact record scope is available through the three event records.
Risk
Failure of the purge-flag component in the purge-pressure-sensor assembly can prevent purge-cassette recognition. Before support, this can delay a procedure; during support, purge delivery stops while mechanical circulatory support continues and a controller exchange is planned, with a brief interruption during exchange.
Supported action
Hospital inventory may continue to be used while awaiting Abiomed service. On the stated alarms, reinsert the purge disc; if the alarm does not clear, switch to a backup Automated Impella Controller. Coordinate purge-flag and purge-retainer replacement with Abiomed’s field service team.
Last material update
September 16, 2026 — FDA posting/classification
Verified
September 21, 2026, after cutoff
Newsletter Drop Date
October 14, 2026 — editorial display date, not a vendor deadline or recall closure

FDA Abiomed alert and interim customer actions · FDA event 99671 records and exact controller packages

BD Alaris pump infusion sets — event 99298 · Open / FDA Class I correction · Discard discontinued sets, use appropriate alternatives, or follow mitigations and enhanced monitoring · Newsletter Drop Date October 13, 2026 · Next review September 28

BD Alaris event 99298

FDA posted
September 15, 2026
Affected scope
The FDA classified record lists 94,230,757 units.
Risk
Performance discrepancies can cause under- or over-infusion, delayed occlusion alarms and inaccurate bolus delivery.
Supported action
Discard discontinued sets, use clinically appropriate alternatives and prioritize alternatives for critical, neonatal, infant and pediatric use. If affected sets cannot be avoided, follow the firm’s mitigations and enhanced-monitoring instructions.
Last material update
September 15, 2026 — FDA posting/classification
Verified
September 21, 2026, after cutoff
Newsletter Drop Date
October 13, 2026 — editorial display date, not a vendor deadline or recall closure

FDA classified recall record and affected product detail · FDA BD infusion-set update and mitigations

Boston Scientific ENROUTE NPS and NPS Plus — event 99454 · Open / FDA Class I removal · Match product and lot, stop use, segregate and return affected inventory · Newsletter Drop Date October 5, 2026 · Next review September 28

Boston Scientific ENROUTE event 99454

Status
FDA lists the event as open/classified; neither cited FDA record shows termination or completion.
Supported action
Match product and lot, stop use, segregate or remove affected inventory, and return it under Boston Scientific instructions.
Last material update
August 26, 2026 — FDA page and recall-record update
Verified
September 21, 2026, after cutoff; verification alone did not reset the material-update date
Newsletter Drop Date
October 5, 2026 — editorial display date, not a vendor deadline or recall closure

FDA ENROUTE removal notice and customer actions · FDA event 99454 records and affected lots

AVID kits containing Medline Namic Star Off Handle manifolds — event 99339 · FDA Class I correction; no termination evidence · Quarantine kits, label them and remove the affected manifold · Newsletter Drop Date October 6, 2026 · Next review September 28

AVID/Namic event 99339

Status
The component-level correction remains on watch; the cited FDA records do not show completion or termination.
Supported action
Quarantine affected kits, apply the warning label and remove the affected manifold; follow FDA instructions when use is medically unavoidable.
Last material update
August 27, 2026 — FDA CDRH communication
Verified
September 21, 2026, after cutoff; verification alone did not reset the material-update date
Newsletter Drop Date
October 6, 2026 — editorial display date, not a vendor deadline or recall closure

FDA AVID/Namic correction and customer actions · FDA event 99339 records and affected kits

BMC Medical Luna G3 APAP LG3600, firmware G3-2.00.76 — recall Z-2979-2026 · FDA Class I; potentially uncorrected subset · Stop affected-firmware devices until replacement · Newsletter Drop Date October 12, 2026 · Next review September 28

BMC Luna G3 recall Z-2979-2026

Affected scope
20,160 devices were in the original firmware-upgrade population; FDA says up to 196 may still be uncorrected.
Risk
The firmware can trigger an error and stop therapy under high pressure, respiratory-rate and peak-flow conditions.
Supported action
Discontinue affected-firmware devices until replacement. Verify serial number and firmware and work with the clinician, durable-medical-equipment supplier or provider.
Last material update
September 8, 2026 — FDA page publication
Verified
September 21, 2026, after cutoff; verification alone did not reset the material-update date
Newsletter Drop Date
October 12, 2026 — editorial display date, not a vendor deadline or recall closure

FDA BMC Luna G3 recall, serial/firmware scope and instructions

CVE Tracker

Seven vulnerabilities were added to CISA’s KEV catalog during this reporting window. Four were first disclosed during the window and are marked NEW. The three Linux vulnerabilities were added to KEV September 18, but the available primary records do not place their original disclosures in this reporting window.

NEW disclosures this window

CVE-2026-76461 — Cisco Secure Email GatewayCISA KEV · Known exploited · NEW September 14 · CVSS 3.1 9.8 · CISA FCEB remediate-by September 17 · Newsletter Drop Date October 19 · customer-managed upgrade; investigate suspected compromise

CVE-2026-76461 tracker record

Lifecycle
NEW — Cisco first published the advisory September 14, 2026.
Source and KEV dates
Initial Cisco advisory and KEV addition September 14, 2026. Cisco revised its cluster guidance and last materially updated the advisory September 17.
Severity
CVSS 3.1 9.8.
Exploitation
Cisco reports active exploitation; CISA lists ransomware use as unknown.
Applicability
Cisco Secure Email Gateway; use Cisco’s release matrix and distinguish customer-managed appliances from Cisco Secure Email Cloud.
Healthcare relevance
Limited to healthcare organizations and service providers that operate the affected gateway; the listing does not establish local deployment or compromise.
Patch
Customer-managed appliances: upgrade to 15.5.5-014, 16.0.4-302 or 16.5.0-780 as applicable; Cisco recommends 16.5.0-780 and says there is no workaround. Cisco says it already upgraded all Secure Email Cloud devices and contacted customers where it identified possible compromise.
Compromise response
Inspect external network and firewall logs. Follow Cisco’s different physical- and virtual-appliance recovery paths, renew affected credentials and cryptographic material, and restore every member of a cluster containing a compromised appliance because shared SSH keys can expose peers.
CISA FCEB remediate-by
September 17, 2026.
Newsletter Drop Date
October 19, 2026.

Cisco advisory · Priority treatment

CVE-2026-76460 — Cisco ISE and ISE-PICCISA KEV · Known exploited · NEW September 16 · CVSS 3.1 10.0 · CISA FCEB remediate-by September 19 · Newsletter Drop Date October 19 · patch a supported branch or migrate ISE 3.0

CVE-2026-76460 tracker record

Lifecycle
NEW — Cisco first published the advisory September 16, 2026.
Source and KEV dates
Cisco advisory and KEV addition September 16, 2026; last material update September 16.
Severity
CVSS 3.1 10.0.
Exploitation
Cisco reports active exploitation; CISA lists ransomware use as unknown.
Applicability
Cisco Identity Services Engine and ISE-PIC; exact branch and patch level control exposure.
Healthcare relevance
Limited to organizations using affected ISE products in network-access or identity-control paths; the vulnerability does not establish a local access-control failure.
Patch
Install 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 or 3.5 Patch 4 as applicable. ISE 3.0 is out of software maintenance and must migrate to a supported fixed release. There is no workaround; infrastructure ACLs are mitigation only.
Compromise response
Inspect access.log on every node plus external network and firewall logs. If malicious activity is suspected, re-image affected nodes and restore configuration as needed.
CISA FCEB remediate-by
September 19, 2026.
Newsletter Drop Date
October 19, 2026.

Cisco advisory · Priority treatment

CVE-2026-87886 — Acronis Backup plugins for cPanel, Plesk and DirectAdminCISA KEV · Known exploited · NEW September 17 · CVSS 3.0 7.8 High · CISA FCEB remediate-by September 19 · Newsletter Drop Date October 19 · update the applicable plugin

CVE-2026-87886 tracker record

Lifecycle
NEW — Acronis and the CNA first published the vulnerability September 17, 2026.
Source and KEV dates
CISA added the vulnerability to KEV September 16, 2026. Acronis and the CNA published their records September 17; last material update September 17.
Severity
CVSS 3.0 7.8, vendor rating High.
Exploitation
Acronis reports limited targeted exploitation involving cPanel/WHM; CISA lists ransomware use as unknown.
Applicability
Acronis Backup plugins and extensions for the named hosting control panels.
Healthcare relevance
Limited to healthcare or vendor hosting environments that use the affected plugins; this is not a finding about all Acronis backup deployments.
Patch
Update to cPanel 1.9.3.1021, Plesk 1.8.11.638 or DirectAdmin 1.2.3.238 or later as applicable.
CISA FCEB remediate-by
September 19, 2026.
Newsletter Drop Date
October 19, 2026.

Acronis SEC-10986 · CVE CNA record · Priority treatment

CVE-2026-58704 — Google Pixel cellular modemCISA KEV · Known exploited · NEW September 15 · limited targeted exploitation reported · CISA FCEB remediate-by September 19 · Newsletter Drop Date October 19 · patch level 2026-09-05 or later

CVE-2026-58704 tracker record

Lifecycle
NEW — Google first published the vulnerability in its September 15, 2026 Pixel bulletin.
Source and KEV dates
Pixel bulletin September 15, 2026; KEV addition and last material update September 16.
Severity
Google’s cited bulletin does not publish a CVSS score for this record.
Exploitation
Google reports indications of limited, targeted exploitation; CISA lists ransomware use as unknown.
Applicability
Supported Pixel devices covered by Google’s bulletin.
Healthcare relevance
Limited to supported Pixels in workforce or managed-device fleets; the model name alone does not establish an unpatched device.
Patch
Move supported devices to Android security patch level 2026-09-05 or later.
CISA FCEB remediate-by
September 19, 2026.
Newsletter Drop Date
October 19, 2026.

Google Pixel bulletin · Priority treatment

Other current-window KEV additions

CVE-2025-39964, CVE-2026-53266 and CVE-2025-39682 — Linux kernel AF_ALG, ebtables SNAT and TLS receive pathsCISA KEV · Known exploited · KEV additions September 18; not labeled NEW · CISA FCEB remediate-by September 21 · Newsletter Drop Date October 19 for each · use exact distribution or appliance guidance

CVE-2025-39964, CVE-2026-53266 and CVE-2025-39682 tracker records

CISA added all three vulnerabilities to KEV on September 18. The available primary records do not place their original disclosures in this reporting window, so they are not marked NEW. CISA’s FCEB remediate-by date is September 21 for each; each Newsletter Drop Date is October 19.

CVE-2025-39964 — AF_ALG
  • Applicability: the exact distribution release and kernel flavor control exposure.
  • Fixed examples: Ubuntu lists 24.04 generic 6.8.0-90.91, 22.04 generic 5.15.0-164.174 and 20.04 generic 5.4.0-224.244. Debian lists bullseye 5.10.247-1, bookworm 6.1.158-1 and trixie 6.12.57-1. SUSE examples include SLES 15 SP7 kernel-default >= 6.4.0-150700.53.81.1 and SLES 16.0 >= 6.12.0-160000.37.1. Cloud, HWE, vendor and image flavors can differ.
  • Mitigation: Red Hat says no mitigation met its criteria. Use its product-specific status or advisory rather than treating an upstream version as proof of a RHEL fix.

Ubuntu status · Debian tracker · Red Hat status · SUSE status

CVE-2026-53266 — ebtables SNAT
  • Exposure condition: Red Hat says the path requires bridge-netfilter ebtables SNAT rules that rewrite ARP hardware addresses.
  • Fixed examples: Ubuntu lists 26.04 generic 7.0.0-31.31 and 24.04 HWE 7.0 7.0.0-31.31~24.04.1. At verification, generic 24.04, 22.04 and 20.04 and many cloud flavors remained vulnerable or work in progress; do not treat the two examples as universal Ubuntu remediation. Debian’s cited tracker lists DLA advisories but no reliable fixed-version table; use the current tracker or advisory. SUSE examples include SLES 15 SP7 kernel-default >= 6.4.0-150700.53.66.1 and SLES 16.0 >= 6.12.0-160000.36.1.
  • Workaround: where the Red Hat condition applies, disable ARP hardware-address rewriting in the affected rules or remove the ARP SNAT rules. This is a workaround, not the vendor patch.

Ubuntu status · Debian tracker · Red Hat status and workaround · SUSE status

CVE-2025-39682 — kernel TLS receive path
  • Exposure condition: Red Hat says the trigger requires use of the kTLS ULP. kTLS use is an applicability condition, not a workaround and not a reason to ignore the KEV listing.
  • Fixed examples: Ubuntu lists 24.04 generic 6.8.0-86.87 and 22.04 HWE 6.8 6.8.0-86.87~22.04.1; its 22.04, 20.04 and 18.04 generic branches are marked not affected. Debian lists bookworm 6.1.153-1, trixie 6.12.48-1 and bullseye linux-6.1 6.1.153-1~deb11u1. SUSE examples include SLES 15 SP6 kernel-default >= 6.4.0-150600.23.73.1 and SLES 15 SP7 >= 6.4.0-150700.53.19.1. Exact cloud and HWE flavors differ.
  • Red Hat status: Red Hat’s cited page does not list a fixed-package table; use the current product-specific status.

Ubuntu status · Debian tracker · Red Hat status · SUSE status

Patch or firmware: Inventory the exact distribution, release, running kernel flavor and appliance-vendor support path. Apply the supported distribution package or appliance firmware, not a raw upstream commit.

Reboot and verification: Follow the vendor’s reboot requirement and verify the running kernel or package afterward.

Compromise investigation: A patch does not determine whether an affected, exposed system was previously compromised. Address that separately under product-vendor guidance and the organization’s incident-response process.

Priority treatment

How tracking dates work: A Newsletter Drop Date ends routine display; it is not a patch deadline and does not show that a vulnerability was fixed. A material, sourced development can support a new specific date.

Continuing watch

These vulnerabilities remain on this edition’s watch from earlier weeks. Their summaries keep identity, exploitation status, Newsletter Drop Date and the most useful supported action visible.

CVE-2019-1068 — Microsoft SQL ServerCISA KEV · Known exploited · Newsletter Drop Date September 23 · confirm servicing against Microsoft’s advisory

CVE-2019-1068 tracker record

Last material update and KEV addition: August 26, 2026. CISA’s FCEB remediate-by date was August 29. Healthcare relevance is limited to organizations or vendors operating an affected SQL Server release; the record does not establish local exposure. Use Microsoft’s current advisory to match the affected SQL Server release to the correct product-specific servicing. Newsletter Drop Date: September 23, 2026.

Microsoft Security Response Center record

CVE-2026-8452 — Citrix NetScaler ADC and GatewayCISA KEV · Known exploited · Newsletter Drop Date September 23 · apply Citrix’s affected-branch upgrades

CVE-2026-8452 tracker record

KEV addition and last material update: August 26, 2026. CISA’s FCEB remediate-by date was August 29. Healthcare relevance is limited to affected NetScaler remote-access deployments; no local deployment or compromise is implied. CVE-2026-19490 is a separate vulnerability and does not change this entry’s September 23 Newsletter Drop Date. Newsletter Drop Date: September 23, 2026.

Citrix advisory CTX696604

CVE-2026-66384 and CVE-2026-42016 — JFrog ArtifactoryCISA KEV · Known exploited · CVE-2026-66384 Newsletter Drop Date September 24; CVE-2026-42016 Newsletter Drop Date September 25 · use JFrog’s exact branch guidance

CVE-2026-66384 and CVE-2026-42016 tracker records

CVE-2026-66384 was added to KEV and last materially updated August 27; its CISA FCEB remediate-by date was September 10 and its Newsletter Drop Date is September 24. CVE-2026-42016 was added to KEV and last materially updated September 11; its CISA FCEB remediate-by date is September 25 and its Newsletter Drop Date is September 25. Healthcare relevance is limited to affected Artifactory deployments used in software supply and delivery; no repository compromise is implied. Passing a federal date neither proves remediation nor extends tracking.

JFrog security advisories

CVE-2026-81578 and CVE-2026-82078 — PaperCut NG/MFCISA KEV · Known exploited · Newsletter Drop Date September 28 for each · update to 24.1.10, 25.0.13 or 26.0.5 as applicable

CVE-2026-81578 and CVE-2026-82078 tracker records

CISA added both to KEV August 31 with a September 14 FCEB remediate-by date. Healthcare relevance is limited to affected PaperCut NG/MF deployments supporting clinical or administrative printing; no local exposure is implied. PaperCut’s September 10 maintenance releases remain the current action. Newsletter Drop Date: September 28 for each.

PaperCut urgent security advisory

CVE-2026-6876, CVE-2026-18885, CVE-2026-18886 and CVE-2026-74820 — ServiceNow AI PlatformNot in CISA KEV at cutoff · Newsletter Drop Date September 28 for each · apply ServiceNow’s KB3152242 release guidance

CVE-2026-6876, CVE-2026-18885, CVE-2026-18886 and CVE-2026-74820 tracker records

The last material update was September 1. None was listed in KEV at the cutoff, so CISA lists no FCEB remediate-by date for these records. Healthcare relevance is limited to affected ServiceNow AI Platform instances used for enterprise workflows; the records do not establish impact to a clinical system. Use ServiceNow’s current knowledge-base guidance to match the affected release and fix to the instance. Newsletter Drop Date: September 28 for each.

ServiceNow KB3152242

CVE-2026-78685 and CVE-2026-82181 — Le-yan Medical Practice Management SystemNot in CISA KEV at cutoff · Newsletter Drop Date September 28 for each · follow TWCERT/vendor update guidance

CVE-2026-78685 and CVE-2026-82181 tracker records

Last material updates were August 25 and August 28, respectively. Neither was in KEV at the cutoff, so CISA lists no FCEB remediate-by date for these records. Relevance is direct but bounded to deployments of the affected Le-yan practice-management software and versions. Confirm affected versions and the vendor’s update path through the TWCERT advisory. Newsletter Drop Date: September 28 for each.

TWCERT advisory

CVE-2026-82583, CVE-2026-78224 and CVE-2026-82578 — NextGen Mirth ConnectNot in CISA KEV at cutoff; no known public exploitation reported · Newsletter Drop Date October 12 for each · update to 4.7.2 or later

CVE-2026-82583, CVE-2026-78224 and CVE-2026-82578 tracker records

CISA’s September 10 medical advisory assigns CVSS 3.1 scores of 8.3, 8.2 and 7.5, respectively, and reported no known public exploitation. Relevance is direct to affected Mirth Connect interface engines that exchange clinical data, but the advisory does not establish exploitation or local exposure. None was in KEV at the cutoff, so CISA lists no FCEB remediate-by date for these records. Update Mirth Connect to 4.7.2 or later through NextGen’s customer portal. Newsletter Drop Date: October 12 for each.

CISA medical advisory ICSMA-26-253-01

CVE-2026-84869 — ConnectWise ScreenConnectCISA KEV · Known exploited · CVSS 3.1 9.9 · Newsletter Drop Date October 12 · update server, clients and access agents

CVE-2026-84869 tracker record

Last material update and KEV addition: September 11. CISA’s FCEB remediate-by date was September 14. Healthcare relevance is limited to affected ScreenConnect remote-support deployments and their clients or access agents; the KEV listing does not establish compromise. On-premises servers should be upgraded to 26.6.5, and clients and access agents should be updated or reinstalled; removing TransferFiles permission is a temporary mitigation. Newsletter Drop Date: October 12.

ConnectWise security bulletin

CVE-2026-20079 — Cisco Secure Firewall Management Center / Security Cloud ControlCISA KEV · Known exploited · CVSS 3.1 10.0 · Newsletter Drop Date October 12 · apply the release-specific FMC hotfix

CVE-2026-20079 tracker record

Last material update and KEV addition: September 9. CISA’s FCEB remediate-by date was September 12. Healthcare relevance is limited to organizations operating affected firewall-management infrastructure; SaaS and on-premises actions differ. Apply Cisco’s release-specific FMC hotfix; no workaround is available. Cisco fixed the SaaS Security Cloud Control service. Newsletter Drop Date: October 12.

Cisco advisory

CVE-2026-86218 — N-able N-centralCISA KEV · Known exploited · Newsletter Drop Date October 12 · self-hosted customers install 2026.3 HF4 build 2026.3.1.14 or later

CVE-2026-86218 tracker record

Last material update and KEV addition: September 8. CISA’s FCEB remediate-by date was September 11. Healthcare relevance is limited to affected N-central deployments used by a healthcare organization or its managed-service provider. Hosted systems were patched by N-able; the stated action applies to self-hosted systems. Newsletter Drop Date: October 12.

N-able hotfix advisory

CVE-2026-19490 — Citrix NetScaler ADC and GatewayCISA KEV · Known exploited · CVSS 4.0 9.3 · Newsletter Drop Date October 12 · upgrade affected customer-managed branches; no workaround

CVE-2026-19490 tracker record

Last material update and KEV addition: September 9. CISA’s FCEB remediate-by date was September 12. Healthcare relevance is limited to affected NetScaler remote-access deployments; applicability depends on version and Gateway, AAA or SAML preconditions. Citrix-managed services were provider-updated. Newsletter Drop Date: October 12.

Citrix advisory CTX696939

CVE-2026-85706 — GitLab CE/EECISA KEV · Known exploited · CVSS 10.0 · Newsletter Drop Date October 12 · upgrade self-managed GitLab to a fixed branch release

CVE-2026-85706 tracker record

Last material update and KEV addition: September 11. CISA’s FCEB remediate-by date was September 14. Healthcare relevance is limited to affected self-managed GitLab instances in software-delivery environments; GitLab.com was patched. Upgrade self-managed GitLab to 19.1.8, 19.2.6, 19.3.2 or later on the applicable branch. Newsletter Drop Date: October 12.

GitLab patch release

CVE-2026-42018 — JFrog Artifactory Self HostedCISA KEV · Known exploited · Newsletter Drop Date October 12 · use JFrog’s exact branch-specific fixed-release mapping

CVE-2026-42018 tracker record

Last material update and KEV addition: September 11. CISA’s FCEB remediate-by date is September 25. Healthcare relevance is limited to affected self-hosted Artifactory deployments used in software supply and delivery. The broad affected range begins below 7.111.20, but later branches have separate fixed versions; use JFrog’s exact mapping. Newsletter Drop Date: October 12.

JFrog security advisories

This edition’s tracker transition

CVE-2026-21962 — Oracle HTTP Server and WebLogic Server Proxy Plug-inCISA KEV · Known exploited · Routine display ended at the September 21 Newsletter Drop Date · archived, not declared remediated · retain Oracle servicing evidence

CVE-2026-21962 transition record

The last material update and KEV addition were August 24; CISA’s FCEB remediate-by date was August 27. Healthcare relevance was limited to affected Oracle HTTP Server or WebLogic proxy-plugin deployments; no local exposure was established. Routine display ended at this edition’s September 21 cutoff, while the permanent history remains. That transition does not prove that any installation was fixed. Newsletter Drop Date: September 21, 2026.

Oracle Critical Patch Update

Sources

Direct source index and verification context · Primary links are grouped by section; one incident item uses clearly labeled secondary reporting

Priority CVEs and tracker

Healthcare Incident Watch

AI & Clinical Automation

Regulatory & Privacy

Clinical Engineering & Medical Device Watch

Clinical Cyber Dispatch

Independent healthcare cybersecurity analysis for security and technology leaders.