28 September 2026

Exploited NetScaler flaws demand upgrades; Astrana Health details a spoofing-led intrusion

Citrix disclosed two exploited NetScaler flaws with fixed builds and compromise checks, while Astrana Health described an impersonation campaign that spoofed its main phone number.

Medical and cybersecurity shield emblem on a navy field.

Reporting window: September 21–27, 2026, America/New_York. Evidence cutoff: September 28, 2026, 12:00 a.m. ET.

CISO Quick Read

  • Citrix NetScaler: two newly disclosed flaws are being exploited. Customer-managed ADC and Gateway appliances need the fixed build for their branch; the DTLS flaw applies when DTLS is enabled, including its default use on VPN virtual servers. Run Citrix’s indicator checks, but do not treat a clean result as conclusive. See fixes and applicability.
  • Astrana Health says impersonators spoofed its main phone number. The company detected attempts to obtain unauthorized access, reset affected credentials and restricted remote-access tools. Use out-of-band approval for remote-access and credential changes rather than trusting caller ID. Read the incident scope.
  • SharePoint exploitation status changed. Microsoft updated its August vulnerability record on September 25 to report observed exploitation. On-premises SharePoint 2016 and 2019 each require two listed updates; verify the resulting build rather than the presence of only one package. Match the supported build.
  • Boston Scientific Imager II catheters entered FDA’s Class I watch. FDA classified the removal on September 25 after reporting two serious injuries and no deaths as of July 16. Stop use and distribution, segregate affected product, verify both inner and outer UPN/lot markings against FDA’s full affected-device list, and follow the return instructions. Check the record.
  • Two U.S. FDA participation dates now matter. Comments on FDA’s generative-AI medical-device discussion paper are due October 19, 2026 at 11:59 p.m. EDT. Its separate robotic-device workshop is December 2–3; in-person registration closes November 23 or earlier at capacity, while virtual registration remains available. See both proceedings.

Priority CVEs

These records combine active exploitation with exposed infrastructure or a consequential access path. CISA remediate-by dates are federal operational deadlines, not universal private-sector legal deadlines.

CVE-2026-88771 — CISA KEV · Known exploited; CVE-2026-88772 — CISA KEV · Known exploited · Citrix NetScaler ADC/Gateway · upgrade to a fixed branch and investigate exposure · CISA date: September 30

Citrix NetScaler CVE-2026-88771 and CVE-2026-88772

Citrix disclosed both vulnerabilities on September 27 and reports observed exploitation. Each has a CVSS v4.0 score of 9.5.

Applicability
CVE-2026-88771 is an unauthenticated arbitrary-command condition affecting default deployments. CVE-2026-88772 can cause remote code execution or denial of service when DTLS is enabled, including the default DTLS behavior on VPN virtual servers.
Fixed releases
Upgrade customer-managed systems to 14.1-73.37 or later, 13.1-64.24 or later, FIPS 14.1-73.37 or later, or 13.1-FIPS/NDcPP 13.1-37.279 or later, as applicable. Citrix warns that 13.1-64.23 can enter a cyclic reboot under a documented configuration. Citrix-managed cloud services were patched.
Response
Verify the running build after the upgrade. Run Citrix’s indicator checks and independently scope possible compromise; a clean scan is not conclusive.
Dates
First disclosure, KEV addition and last material update: September 27. CISA remediate-by: September 30. Newsletter Drop Date: October 26.

Action: Prioritize internet-reachable customer-managed appliances, choose the fixed build for the installed branch and keep patch verification separate from compromise investigation.

Citrix security bulletin · Tracker: CVE-2026-88771 and CVE-2026-88772

CVE-2026-65660 — CISA KEV · Known exploited · Microsoft SharePoint Server · install every required update and verify the build · CISA date: September 28

Microsoft SharePoint Server CVE-2026-65660

This authenticated, low-privilege remote-code-execution vulnerability has a CVSS v3.1 score of 8.8. Microsoft first disclosed it on August 11 and updated the record on September 25 to report observed exploitation, so the exploitation and KEV status are current; the disclosure is not NEW this week.

Subscription Edition
KB5002893; fixed build 16.0.19725.20522.
SharePoint Server 2019
Install both KB5002894 and KB5002896; fixed build 16.0.10417.20198.
SharePoint Server 2016
Install both KB5002905 and KB5002906; fixed build 16.0.5565.1001.
Dates
KEV addition and last material update: September 25. CISA remediate-by: September 28. Newsletter Drop Date: October 26.

Action: Confirm the installed edition, apply the complete update set, verify the resulting build and investigate exposed servers separately from patch validation.

Microsoft Security Response Center record · Tracker record

CVE-2026-93952 — CISA KEV · Known exploited · Arista VeloCloud Orchestrator · patch affected on-premises VCO or restrict web access · CISA date: September 25

Arista VeloCloud Orchestrator CVE-2026-93952

This newly disclosed, pre-authentication vulnerability has a CVSS v3.1 score of 10.0. Arista reports active exploitation. It affects on-premises VeloCloud Orchestrator when certificate authentication is configured and web access is reachable; the hosted service was patched.

Fixed releases: 5.2.3.16 or later and 6.4.2.8 or later, as applicable. Fixes for the 6.1 and 7.0 branches were still forthcoming at verification.

Dates: First disclosure, KEV addition and last material update: September 22. CISA remediate-by: September 25. Newsletter Drop Date: October 26.

Action: Hosted customers do not have a customer patch to apply. On-premises customers should restrict web administration to trusted networks while moving to a supported fixed release.

Arista advisory 0183 · Tracker record

CVE-2026-85102 — CISA KEV · Known exploited; CVE-2026-93616 — CISA KEV · Known exploited · Check Point gateways/Spark and management · apply the exact branch-matched vendor fix and review exposed systems · CISA date: September 25

Check Point CVE-2026-85102 and CVE-2026-93616

Both pre-authentication vulnerabilities have CVSS v3.1 scores of 9.8, but their timing and affected roles differ.

  • CVE-2026-85102: VPN certificate validation can lead to remote code execution on Security Gateways and Spark appliances. Check Point says fixes were available September 9 and attacks were observed from September 12, especially against Spark appliances. The September 22 KEV and advisory update is current; the original disclosure predates this window.
  • CVE-2026-93616: Path traversal can permit script upload and execution on Security Management. Check Point disclosed and fixed it September 22 and says it observed a handful of targeted attacks on July 23. This is a NEW disclosure in this window.

Remediation: Use Check Point’s advisory table to select the exact supported-branch update for the deployed gateway, Spark appliance or management server. Do not substitute a fix for one product role for the other.

Dates: KEV addition and last material update: September 22. CISA remediate-by: September 25. Newsletter Drop Date: October 26.

Action: Apply the product- and branch-specific fix, verify completion and review internet exposure and logs separately because Check Point reports attacks before the September 22 disclosure of the management flaw.

Check Point advisory and branch table · Tracker: CVE-2026-85102 and CVE-2026-93616

Healthcare Incident Watch

Astrana Health: impersonation, caller-ID spoofing and unauthorized access

In a September 22 SEC filing, Astrana Health said subsidiary Astrana Health Management detected unusual activity involving actors who impersonated personnel and spoofed the company’s main telephone number while contacting employees to seek unauthorized access. Astrana says it detected and responded to the activity, retained forensic specialists, notified law enforcement, reset affected credentials, restricted remote-access tools, restored some systems from clean backups and enhanced monitoring, logging and detection.

The company determined on September 22 that the incident was material. It says certain private and confidential information was accessed and acquired, but it was still evaluating whether patient, employee, provider, business, financial or intellectual-property information was involved. Astrana had not announced specific patient notifications; it said it would make notices required by law and was notifying regulators and payer partners. It did not then expect a material effect on its financial condition or results, while noting that the investigation continued.

For healthcare defenders: Do not use caller ID as proof of identity. Require out-of-band approval for remote-access or credential changes, log remote-support activity and rehearse credential reset, clean restoration and payer/regulator communications. The filing does not establish confirmed patient-data exposure or a notification-law violation.

Astrana Health September 22 Form 8-K

Boston Scientific: final update narrows the affected environment

Boston Scientific published its final investigation update on September 22. The company says CrowdStrike concluded that an actor accessed an external-facing network device and then a limited portion of its on-premises IT environment. It reports no evidence of ongoing activity after containment on August 25.

Boston Scientific says it found no evidence of compromise of Microsoft 365, other cloud applications, manufacturing maintenance, product or software development, medical-device maintenance, HR and benefits, or SCADA. It also reports no evidence that customer or patient data was accessed, staged or exfiltrated from those scoped systems, and says customers and partners may continue normal business and system connections. Those are scoped “no evidence” findings, not proof that no data or system was affected anywhere.

For healthcare partners: Keep external-facing network devices inventoried separately from cloud and operational environments, retain segmented logs and define the evidence needed before restoring partner connectivity.

Boston Scientific incident update

McKesson: third-party application scope becomes clearer

McKesson’s September 21 customer information-center update confirms unauthorized access and data exfiltration limited to certain third-party applications. The company says the incident affects a subset of Oncology & Multispecialty customers and primarily business contact and order data for Medical-Surgical.

McKesson says it has no indication that other business units, including North American Pharmaceutical Distribution or CoverMyMeds, were affected, and that all business lines continue operating. It says affected people will be notified as required by applicable law. The primary update does not provide a verified affected-person count, so attacker claims and unverified record totals are not treated as facts here.

For healthcare customers: Maintain application-level third-party inventories and data-flow maps so incident scope can be tied to each application, customer population and data class. Preserve the evidence behind delegated notification decisions.

McKesson Customer Cybersecurity Information Center

AI & Clinical Automation

Anthropic reports an early autonomous genomic search, not an autonomous wet lab

Anthropic describes a Claude-agent project that, under high-level human direction, searched roughly 200,000 reverse transcriptases, narrowed the field to about 3,500 candidates and then 20, and proposed a previously uncharacterized enzyme system it calls ART. Anthropic reports using about 950 agents, 210 million tokens and 21 hours of computation.

The boundary matters. The biological function of ART remains unknown, the work is early and presented as a preprint, and humans performed all wet-lab experiments. Anthropic says that work was limited to BSL-1 and BSL-2 settings and involved no human pathogens. The report does not establish autonomous end-to-end biological discovery, clinical readiness or a security incident.

Reader implication: Biomedical organizations that let agents select targets should record data lineage and scoring, require reproducible results and explicit human authorization before physical experimentation, isolate execution, use least privilege, log tool activity and obtain independent review before a model-generated candidate becomes a wet-lab or clinical workflow instruction. These controls address plausible integrity, intellectual-property and dual-use concerns; Anthropic did not report model theft, data poisoning, wet-lab infrastructure compromise or biological-threat use.

Anthropic: Claude discovers a novel enzyme system

Regulatory & Privacy

Active / Ongoing

FDA robotic-medical-device workshop · Active hybrid workshop December 2–3, 10:00 a.m.–4:00 p.m. ET · in-person registration closes November 23 or earlier at capacity; virtual registration remains available

FDA says the workshop will consider terminology, benefit-risk evaluation and possible future policy for robotic medical devices with autonomous functions or remote teleoperation. The agenda was forthcoming at verification.

Boundary: This is a workshop and future-policy discussion, not a new rule or compliance obligation. FDA’s page does not announce cybersecurity as an agenda topic.

Action: Device makers, providers and security teams can review the agenda when posted and prepare evidence on autonomous or remote-operation risk, human oversight, connectivity and assurance. Those are reader considerations, not FDA-announced cybersecurity topics. Register for in-person or virtual attendance through FDA’s linked federal form; November 23 is the in-person limit, while virtual registration remains available.

FDA workshop page · FDA-linked workshop registration form

U.S. FDA generative-AI-enabled medical devices, docket FDA-2026-N-7874 · Active request for comment · comments due October 19, 2026 at 11:59 p.m. EDT · evaluate whether to submit evidence

U.S. FDA’s publication is a discussion paper and request for comment, not draft guidance, final guidance or a policy change. It asks for input relevant to risk assessment, premarket evaluation and postmarket monitoring of generative-AI-enabled medical devices.

Action: Device manufacturers, providers and researchers should assess whether they have evidence responsive to the paper and submit comments directly to docket FDA-2026-N-7874 by October 19, 2026 at 11:59 p.m. EDT.

FDA discussion paper and request for comment · Regulations.gov docket document FDA-2026-N-7874-0001 · Direct comment form

CISA CIRCIA final rule · Ongoing rulemaking; no announced final-rule date · reporting requirement does not apply until a final rule is effective · maintain readiness and watch CISA

CISA’s rulemaking under the Cyber Incident Reporting for Critical Infrastructure Act continues. The CIRCIA reporting requirement does not apply until a final rule becomes effective.

Action: Maintain incident-reporting readiness and follow CISA’s primary page without treating an estimated publication date as a deadline.

CISA CIRCIA rulemaking page

Standing Watch

HHS HIPAA Security Rule NPRM · Pending rulemaking · OMB projects final action in July 2027 and lists no legal deadline · use the proposal for gap planning, not as a compliance deadline

The proposed rule remains pending. OMB’s Unified Agenda lists July 2027 as projected final action and “None” for the legal deadline. July 2027 is therefore a planning projection, not a legal or compliance deadline. Current obligations remain in force unless and until a final rule changes them.

Action: Use the proposal to plan and test gaps, while keeping proposed requirements distinct from current law.

HHS HIPAA Security Rule NPRM page · OMB/Reginfo RIN 0945-AA22 projected action record

California CCPA automated-decisionmaking technology regulations · Regulations effective January 1, 2026; ADMT compliance begins January 1, 2027 for businesses using it for significant decisions · map affected workflows and rights handling

California’s regulations took effect January 1, 2026. The narrower January 1, 2027 milestone is when businesses using automated decisionmaking technology for significant decisions must begin complying with the ADMT requirements.

Action: Map affected automated-decision workflows, notices, access and opt-out handling, and risk-assessment obligations.

California Privacy Protection Agency announcement on effective and ADMT compliance dates · CPPA regulatory updates

Clinical Engineering & Medical Device Watch

Boston Scientific removes Imager II angiographic catheters

FDA classified Boston Scientific’s removal as Class I on September 25 (event 99687; recall Z-3214-2026), after the database posting on September 23. The customer letter was dated August 24 and FDA’s early alert August 28.

Reduced stabilizing agents can allow the catheter tip to degrade and detach. FDA says the most likely consequence is a procedural delay while the catheter is exchanged; a remote worst case includes embolism and organ failure. As of July 16, FDA reported two serious injuries and no deaths.

Action: Stop use and distribution, segregate affected product, verify both inner and outer UPN and lot markings against FDA’s full affected-device UPN/lot spreadsheet, and return affected product under Boston Scientific’s instructions. Open the Standing Watch record.

Standing Watch

Standing Watch includes formally classified Class I events with an active, source-supported inventory or workflow action. Each record shows a finite Newsletter Drop Date. That date is not recall closure, a vendor deadline or a safety determination.

Boston Scientific Imager II angiographic catheters · FDA Class I removal; open/classified · stop, segregate, verify UPN/lot and return · Newsletter Drop Date: October 23

Boston Scientific Imager II angiographic catheters

Identity: Event 99687; recall Z-3214-2026.

Status and dates: Customer letter August 24; FDA early alert August 28; database posted September 23; Class I classification and last material update September 25.

Action: Stop use and distribution, segregate affected product, verify both inner and outer UPN and lot markings against FDA’s full affected-device UPN/lot spreadsheet, and return affected product under the manufacturer’s instructions.

Vendor action deadline: None stated. Newsletter Drop Date: October 23.

FDA Imager II safety communication · FDA full affected UPN/lot spreadsheet · FDA event 99687 and affected product record

Boston Scientific ENROUTE Transcarotid Neuroprotection System / NPS Plus · FDA Class I removal; open/classified · stop, segregate and return affected lots · Newsletter Drop Date: October 5

Identity: Event 99454.

Status: Open/Classified. Last material update: August 26.

Action: Match product and lot, stop use, segregate or remove affected inventory and return it under Boston Scientific’s instructions.

Vendor action deadline: None stated. Newsletter Drop Date: October 5.

FDA ENROUTE safety communication · FDA event 99454 and affected lots

AVID Medical kits containing Medline Namic Star Off Handle manifolds · FDA Class I correction · quarantine, label and remove the manifold · Newsletter Drop Date: October 6

Identity: Event 99339.

Status: No termination evidence established. Last material update: August 27.

Action: Quarantine affected kits, apply the warning label and remove the affected manifold. Follow FDA’s instructions if use is medically unavoidable.

Vendor action deadline: None stated. Newsletter Drop Date: October 6.

FDA AVID/Namic correction · FDA event 99339 and affected kits

BMC Medical Luna G3 APAP LG3600, firmware G3-2.00.76 · FDA Class I; potentially uncorrected subset · discontinue affected firmware pending replacement · Newsletter Drop Date: October 12

Identity: Recall Z-2979-2026. FDA says 20,160 devices were in the original firmware-upgrade population and up to 196 may remain uncorrected.

Risk and dates: The firmware may trigger an error and stop therapy under high pressure, respiratory-rate and peak-flow conditions. FDA classified the event August 19; the company announcement was September 7 and the FDA page September 8, the last material update.

Action: Discontinue devices with the affected firmware until replacement. Verify serial number and firmware and work with the clinician, DME supplier or provider.

Vendor action deadline: None stated. Newsletter Drop Date: October 12.

FDA BMC Luna G3 recall notice

CooperSurgical INCA infant/neonatal nasal CPAP sets · FDA Class I removal; open/classified · stop, segregate and return affected sets · Newsletter Drop Date: October 19

Identity: Event 99643; recalls Z-3139-2026 and Z-3140-2026. FDA records list 13,215 complete sets and 745 replacement sets.

Risk and status: A loose tubing connection can cause loss of CPAP and decreased oxygenation. FDA reported no serious injuries or deaths as of August 11. FDA posted and classified the record September 18, the last material update.

Action: Stop use and distribution, segregate and return affected sets. If a connection becomes loose during use, replace the tubing or CPAP.

Vendor action deadline: None stated. Newsletter Drop Date: October 19.

FDA CooperSurgical early alert · FDA event 99643 and affected sets

AVID/Halyard kits containing recalled sodium chloride ampules · FDA Class I correction; open/classified · quarantine, label and remove ampules · Newsletter Drop Date: October 15

Identity: Event 99758.

Risk and status: The kits contain sodium chloride ampules recalled over a quality and sterility concern. FDA posted and classified the record September 16, the last material update.

Action: Quarantine and label affected kits, then remove and discard the implicated ampules under the firm/FDA correction.

Vendor action deadline: None stated. Newsletter Drop Date: October 15.

FDA event 99758 and affected kits · FDA sodium chloride ampule notice

Abiomed Impella controllers and combined controller/Connect package · FDA Class I removal; phased service action · follow alarm response and coordinate service · Newsletter Drop Date: October 14

Identity: Event 99671; recalls Z-3148-2026, Z-3149-2026 and Z-3150-2026. FDA says all Automated Impella Controller units globally are in scope of a phased removal/service action.

Risk and dates: Purge-cassette recognition can fail when the purge-flag component fails; controller exchange briefly interrupts support. The firm initiated the action and sent its letter August 12. FDA posted and classified the three records September 16, the last material update.

Action: Hospital inventory may continue while awaiting service. On the stated alarms, reinsert the purge disc; if the alarm does not clear, use a backup controller. Coordinate service with Abiomed.

Vendor action deadline: None stated. Newsletter Drop Date: October 14.

FDA Abiomed controller alert · FDA event 99671 and affected controller records

BD Alaris pump infusion sets · FDA Class I correction; open/classified · discard discontinued sets or use firm mitigations with enhanced monitoring · Newsletter Drop Date: October 13

Identity: Event 99298. The classified record lists 94,230,757 units.

Risk and status: Performance discrepancies can cause under- or over-infusion, delayed occlusion alarms and inaccurate bolus delivery. FDA posted and classified the record September 15, the last material update.

Action: Discard discontinued sets, use clinically appropriate alternatives, prioritize critical, neonatal, infant and pediatric patients, and use the firm’s mitigations plus enhanced monitoring if affected sets cannot be avoided.

Vendor action deadline: None stated. Newsletter Drop Date: October 13.

FDA classified BD Alaris record and scope · FDA BD infusion-set update

CVE Tracker

Start with vulnerabilities whose first public disclosure was verified inside this edition’s reporting window. Priority records are concise here and link back to the fuller treatment above.

NEW

CVE-2026-88771 — CISA KEV · Known exploited; CVE-2026-88772 — CISA KEV · Known exploited · Citrix NetScaler ADC/Gateway NEW September 27 · fixed branches available; investigate exposure · CISA date September 30 · Newsletter Drop Date October 26

CVE-2026-88771 — CISA KEV · Known exploited

Unauthenticated arbitrary-command remote code execution affects default deployments. CVSS v4.0: 9.5.

CVE-2026-88772 — CISA KEV · Known exploited

Memory-overflow remote code execution or denial of service applies when DTLS is enabled, including default behavior on VPN virtual servers. CVSS v4.0: 9.5.

Action and dates: Upgrade to 14.1-73.37+, 13.1-64.24+, FIPS 14.1-73.37+, or 13.1-FIPS/NDcPP 13.1-37.279+ as applicable; avoid 13.1-64.23 where Citrix’s documented cyclic-reboot condition applies. Managed cloud was patched. Run indicator checks and scope compromise separately. First disclosure, KEV addition and last material update: September 27. First CCD tracking: September 28; prior newsletter appearance not established. CISA remediate-by: September 30. Newsletter Drop Date: October 26.

Full Priority CVE treatment · Citrix bulletin

CVE-2026-93616 — CISA KEV · Known exploited; CVE-2026-85102 — CISA KEV · Known exploited · Check Point management, gateways and Spark CVE-2026-93616 NEW; CVE-2026-85102 current exploitation update · install exact branch fixes · CISA date September 25 · Newsletter Drop Date October 26

CVE-2026-93616 — CISA KEV · Known exploited

NEW September 22. Pre-authentication path traversal can lead to script upload and execution on Security Management. CVSS v3.1: 9.8. Check Point says it observed a handful of targeted attacks on July 23.

CVE-2026-85102 — CISA KEV · Known exploited

VPN certificate validation can lead to pre-authentication remote code execution on Security Gateways and Spark appliances. CVSS v3.1: 9.8. Fixes were available September 9, and Check Point says attacks began September 12, especially against Spark; this is not a NEW disclosure.

Action and dates: Apply the exact supported-branch fix for each deployed product role and review exposure and logs separately. KEV addition and last material update: September 22. First CCD tracking: September 28; prior newsletter appearance not established. CISA remediate-by: September 25. Newsletter Drop Date: October 26.

Full Priority CVE treatment · Check Point advisory and branch table

CVE-2026-93952 — CISA KEV · Known exploited · Arista VeloCloud Orchestrator NEW September 22 · patch affected on-premises VCO; hosted service patched · CISA date September 25 · Newsletter Drop Date October 26

CVE-2026-93952 — CISA KEV · Known exploited

Pre-authentication remote code execution affects on-premises VCO when certificate authentication is configured and web access is reachable. CVSS v3.1: 10.0.

Action and dates: Apply 5.2.3.16+ or 6.4.2.8+ as applicable; fixes for 6.1/7.0 were forthcoming at verification. Restrict web administration while applying a supported fix. First disclosure, KEV addition and last material update: September 22. First CCD tracking: September 28; prior newsletter appearance not established. CISA remediate-by: September 25. Newsletter Drop Date: October 26.

Full Priority CVE treatment · Arista advisory

CVE-2026-87902 — CISA KEV · Known exploited · WordPress Core NEW September 25 · update to 7.1.2 or a patched branch backport; exposure is conditional · CISA date September 28 · Newsletter Drop Date October 26

CVE-2026-87902 — CISA KEV · Known exploited

The unauthenticated path traversal and conditional remote-code-execution path requires a readable top-level theme directory whose name begins page-. The additional PEAR route also requires register_argc_argv to be enabled, so not every default installation is equally exposed.

Action and dates: Update to WordPress 7.1.2 or the patched backport for the installed supported branch; backports extend through 4.7. First disclosure, KEV addition and last material update: September 25. First CCD tracking: September 28; prior newsletter appearance not established. CISA remediate-by: September 28. Newsletter Drop Date: October 26.

WordPress/GitHub security advisory

CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859 and CVE-2026-86860 · ServiceNow AI Platform NEW September 24 · not in CISA KEV at cutoff; ServiceNow reports no known malicious exploitation · hosted instances updated; self-hosted customers map the exact family/build · Newsletter Drop Date October 26

CVE-2026-86857

Authenticated low-privilege authentication bypass; CVSS v4.0: 8.4.

CVE-2026-86858

Unauthenticated improper access control can create, modify or delete instance data in certain circumstances; CVSS v4.0: 8.7.

CVE-2026-13016

Unauthenticated SQL injection can access or modify database content; CVSS v4.0: 9.3.

CVE-2026-86859

Unauthenticated authorization bypass can disclose arbitrary records; CVSS v4.0: 8.7.

CVE-2026-86860

Unauthenticated missing authorization can expose unintended instance data and cause privilege escalation; CVSS v4.0: 9.3.

Fixed floors: Hosted instances were updated. Self-hosted customers and partners should map the deployed family and build to ServiceNow’s table: Yokohama Patch 13 Hot Fix 5a; Zurich Patch 10 Hot Fix 3b; Zurich Patch 10 Hot Fix 4a W32; Zurich Patch 11 Hot Fix 3; Australia Patch 2 Hot Fix 4b W32; Australia Patch 4 Hot Fix 3; or Australia Patch 5. These are alternative release-family floors, not packages to combine.

Dates: First disclosure and last material update: September 24. First CCD tracking: September 28; prior newsletter appearance not established. CISA remediate-by: none listed because these records were not in KEV at cutoff. Newsletter Drop Date: October 26.

ServiceNow security knowledge-base article and release mapping · CNA records: 86857, 86858, 13016, 86859, 86860

How to read the remaining dates: A KEV addition or exploitation update does not make an older disclosure NEW. “First CCD tracking” is an onboarding date, not proof of a prior public appearance. Each active record has a finite Newsletter Drop Date; leaving the routine tracker does not mean a system was patched. CISA remediate-by dates are shown separately and are not universal private-sector deadlines.

Current KEV additions and material status updates

CVE-2026-65660 — CISA KEV · Known exploited · Microsoft SharePoint Server Exploitation update September 25; disclosure predates window · install complete KB sets and verify build · CISA date September 28 · Newsletter Drop Date October 26

CVE-2026-65660 — CISA KEV · Known exploited

Authenticated low-privilege remote code execution; CVSS v3.1: 8.8. Microsoft first disclosed the flaw August 11 and reported observed exploitation September 25.

Action: Subscription Edition: KB5002893 / build 16.0.19725.20522. SharePoint 2019: both KB5002894 and KB5002896 / build 16.0.10417.20198. SharePoint 2016: both KB5002905 and KB5002906 / build 16.0.5565.1001. Verify the running build and investigate exposed servers separately.

Dates: KEV addition and last material update: September 25. First CCD tracking: September 28; prior newsletter appearance not established. CISA remediate-by: September 28. Newsletter Drop Date: October 26.

Full Priority CVE treatment · Microsoft record

CVE-2026-7273 — CISA KEV · Known exploited · Zyxel GS1900 switches KEV added September 21; June disclosure · install model-specific 2.90(...2)C0 firmware · CISA date September 24 · Newsletter Drop Date October 26

CVE-2026-7273 — CISA KEV · Known exploited

A LAN-reachable, unauthenticated crafted HTTP request can cause command execution on affected GS1900 models.

Action and dates: Use Zyxel’s model table; the ten listed models each have a model-specific 2.90(...2)C0 fixed release. Restrict management to trusted LANs until upgraded. First disclosure: June 16. KEV addition and last material update: September 21. First CCD tracking: September 28; prior newsletter appearance not established. CISA remediate-by: September 24. Newsletter Drop Date: October 26.

Zyxel advisory and model-specific firmware table

CVE-2026-94127 — CISA KEV · Known exploited · F5 BIG-IP APM KEV added September 22; first-disclosure date not established · apply the branch-specific fixed/hardened release; iRule is not the patch · CISA date September 25 · Newsletter Drop Date October 26

CVE-2026-94127 — CISA KEV · Known exploited

The unauthenticated remote-code-execution condition requires an access policy and an OAuth profile on a virtual server.

Action and dates: Apply F5’s exact fixed or hardened release for the installed branch. The vendor iRule is temporary detection and forensic support, not the final patch. First-publication timing was not established in the saved primary record, so this is not labeled NEW. KEV addition and last material update: September 22. First CCD tracking: September 28; prior newsletter appearance not established. CISA remediate-by: September 25. Newsletter Drop Date: October 26.

F5 record K000162605 and fixed-release table

CVE-2026-5430 — CISA KEV · Known exploited · WSO2 products KEV added September 24; May disclosure · use WSO2’s exact product/update-level table · CISA date September 27 · Newsletter Drop Date October 26

CVE-2026-5430 — CISA KEV · Known exploited

WSO2 describes an unsupported JWT algorithm condition that can allow authentication bypass and account takeover. That vendor description is used rather than the catalog’s conflicting generic taxonomy.

Action and dates: Apply the exact product/update level in WSO2’s advisory. First disclosure: May 3. KEV addition and last material update: September 24. First CCD tracking: September 28; prior newsletter appearance not established. CISA remediate-by: September 27. Newsletter Drop Date: October 26.

WSO2-2026-5328 advisory and update table

CVE-2026-71362 — CISA KEV · Known exploited · Adobe Commerce / Magento Open Source KEV added September 24; August disclosure · install Adobe’s fixed 2.4.x branch release · CISA date September 27 · Newsletter Drop Date October 26

CVE-2026-71362 — CISA KEV · Known exploited

Improper authorization can permit privilege escalation without credentials or user interaction.

Action and dates: Apply Adobe’s fixed release for the applicable 2.4.x branch in APSB26-92. First disclosure: August 11. KEV addition and last material update: September 24. First CCD tracking: September 28; prior newsletter appearance not established. CISA remediate-by: September 27. Newsletter Drop Date: October 26.

Adobe APSB26-92 and fixed-version table

CVE-2026-67279 — CISA KEV · Known exploited · MikroTik RouterOS KEV added September 25 · upgrade to a listed fixed RouterOS release; restrict SSH and review indicators · CISA date September 28 · Newsletter Drop Date October 26

CVE-2026-67279 — CISA KEV · Known exploited

CISA identifies this exact workflow-bypass vulnerability as chainable with another RouterOS flaw. MikroTik’s September chain page uses related CVE identities, so it is not treated as directly assigning every step in that chain to CVE-2026-67279.

Action and dates: Upgrade to RouterOS 7.25beta3, 7.24.2, 7.23.4 or 6.49.21 as applicable. Restrict SSH exposure and review Flagged logs, unfamiliar users and scripts. KEV addition and last material update: September 25. First CCD tracking: September 28; prior newsletter appearance not established. CISA remediate-by: September 28. Newsletter Drop Date: October 26.

MikroTik September 2026 vulnerability chain page

Continuing watch

CVE-2026-82583, CVE-2026-78224 and CVE-2026-82578 · NextGen Healthcare Mirth Connect CONTINUING WATCH · not in CISA KEV at cutoff · update to 4.7.2+ · no CISA date listed · Newsletter Drop Date October 12

CVE-2026-82583

CVSS v3.1: 8.3.

CVE-2026-78224

CVSS v3.1: 8.2.

CVE-2026-82578

CVSS v3.1: 7.5.

Action and dates: Update Mirth Connect to 4.7.2 or later through NextGen’s customer portal. CISA’s medical advisory reported no known public exploitation. First CCD tracking: September 14; prior newsletter appearance not established. Last material update: September 10. No CISA remediate-by date was listed. Newsletter Drop Date: October 12.

CISA medical advisory ICSMA-26-253-01

CVE-2026-84869 — CISA KEV · Known exploited · ConnectWise ScreenConnect CONTINUING WATCH · upgrade server to 26.6.5 and refresh clients/agents; permission removal is temporary · CISA date September 14 · Newsletter Drop Date October 12

CVE-2026-84869 — CISA KEV · Known exploited

Action: Upgrade on-premises servers to 26.6.5 and update or reinstall clients and access agents. Removing the TransferFiles permission is a temporary mitigation, not the fix.

Dates: First CCD tracking: September 14; prior newsletter appearance not established. Last material update and KEV addition: September 11. CISA remediate-by: September 14. Newsletter Drop Date: October 12.

ConnectWise ScreenConnect bulletin

CVE-2026-20079 — CISA KEV · Known exploited · Cisco Secure Firewall Management Center / Security Cloud Control CONTINUING WATCH · apply Cisco’s release-specific FMC hotfix; SaaS SCC fixed · CISA date September 12 · Newsletter Drop Date October 12

CVE-2026-20079 — CISA KEV · Known exploited

Action: Apply Cisco’s release-specific FMC hotfix; Cisco lists no workaround. Cisco fixed the SaaS Security Cloud Control service.

Dates: First CCD tracking: September 14; prior newsletter appearance not established. Last material update and KEV addition: September 9. CISA remediate-by: September 12. Newsletter Drop Date: October 12.

Cisco FMC advisory and release-specific hotfix table

CVE-2026-86218 — CISA KEV · Known exploited · N-able N-central CONTINUING WATCH · self-hosted: install 2026.3 HF4 build 2026.3.1.14+; hosted systems patched · CISA date September 11 · Newsletter Drop Date October 12

CVE-2026-86218 — CISA KEV · Known exploited

Action: Self-hosted customers should install N-central 2026.3 HF4 build 2026.3.1.14 or later. N-able says hosted systems were patched.

Dates: First CCD tracking: September 14; prior newsletter appearance not established. Last material update and KEV addition: September 8. CISA remediate-by: September 11. Newsletter Drop Date: October 12.

N-able N-central hotfix notice

CVE-2026-19490 — CISA KEV · Known exploited · Citrix NetScaler ADC/Gateway CONTINUING WATCH · upgrade customer-managed branches to Citrix’s fixed releases; no workaround · CISA date September 12 · Newsletter Drop Date October 12

CVE-2026-19490 — CISA KEV · Known exploited

This authentication-bypass identity is distinct from this week’s CVE-2026-88771 and CVE-2026-88772; the newer flaws do not reset its tracking dates.

Action and dates: Upgrade each affected customer-managed branch to the exact fixed release in Citrix’s table; there is no workaround. Citrix-managed services were provider-updated. First CCD tracking: September 14; prior newsletter appearance not established. Last material update and KEV addition: September 9. CISA remediate-by: September 12. Newsletter Drop Date: October 12.

Citrix CTX696939 and fixed-release table

CVE-2026-85706 — CISA KEV · Known exploited · GitLab CE/EE CONTINUING WATCH · self-managed: update to 19.1.8, 19.2.6, 19.3.2 or later on branch; GitLab.com patched · CISA date September 14 · Newsletter Drop Date October 12

CVE-2026-85706 — CISA KEV · Known exploited

Action: Upgrade self-managed GitLab to 19.1.8, 19.2.6, 19.3.2 or later on the applicable branch. GitLab.com was patched.

Dates: First CCD tracking: September 14; prior newsletter appearance not established. Last material update and KEV addition: September 11. CISA remediate-by: September 14. Newsletter Drop Date: October 12.

GitLab 19.3.2 patch release and branch versions

CVE-2026-42018 — CISA KEV · Known exploited · JFrog Artifactory Self Hosted CONTINUING WATCH · use JFrog’s exact branch-specific fixed release; broad affected range begins below 7.111.20 · CISA date September 25 · Newsletter Drop Date October 12

CVE-2026-42018 — CISA KEV · Known exploited

Action: Use JFrog’s exact branch-specific fixed-release mapping. The broad affected range begins below 7.111.20, and later branches have separate fixes; do not treat one floor as universal.

Dates: First CCD tracking: September 14; prior newsletter appearance not established. Last material update and KEV addition: September 11. CISA remediate-by: September 25. Newsletter Drop Date: October 12.

JFrog security advisories and branch mapping

CVE-2026-76461 — CISA KEV · Known exploited · Cisco Secure Email Gateway; CVE-2026-76460 — CISA KEV · Known exploited · Cisco ISE/ISE-PIC CONTINUING WATCH · exact fixed releases and separate compromise recovery · CISA dates September 17/19 · Newsletter Drop Date October 19

CVE-2026-76461 — CISA KEV · Known exploited

Secure Email Gateway: upgrade customer-managed appliances to 15.5.5-014, 16.0.4-302 or 16.5.0-780 as applicable; Cisco recommends 16.5.0-780 and lists no workaround. Cisco Secure Email Cloud was upgraded by Cisco. Inspect external network and firewall logs; follow Cisco’s physical or virtual recovery path; renew affected credentials and cryptographic material; restore every member of a cluster containing a compromised appliance because shared SSH keys can expose peers.

First CCD tracking: September 21; prior newsletter appearance not established. Last material update: September 17. KEV addition: September 14. CISA remediate-by: September 17. Newsletter Drop Date: October 19.

CVE-2026-76460 — CISA KEV · Known exploited

ISE/ISE-PIC: install 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 or 3.5 Patch 4. ISE 3.0 is out of software maintenance and must migrate to a supported fixed release. Cisco lists no workaround; infrastructure ACLs are mitigation only. Inspect access.log on every node and external network/firewall logs; if malicious activity is suspected, re-image affected nodes and restore configuration as needed.

First CCD tracking: September 21; prior newsletter appearance not established. Last material update and KEV addition: September 16. CISA remediate-by: September 19. Newsletter Drop Date: October 19.

Cisco Secure Email Gateway advisory · Cisco ISE advisory

CVE-2026-87886 — CISA KEV · Known exploited · Acronis Backup control-panel plugins/extensions CONTINUING WATCH · update cPanel, Plesk or DirectAdmin plugin to the exact fixed level · CISA date September 19 · Newsletter Drop Date October 19

CVE-2026-87886 — CISA KEV · Known exploited

Acronis describes limited targeted exploitation involving cPanel/WHM. Vendor rating: High; CVSS v3.0: 7.8.

Action and dates: Update to cPanel 1.9.3.1021, Plesk 1.8.11.638 or DirectAdmin 1.2.3.238 or later as applicable. First CCD tracking: September 21; prior newsletter appearance not established. First disclosure and last material update: September 17. KEV addition: September 16. CISA remediate-by: September 19. Newsletter Drop Date: October 19.

Acronis SEC-10986

CVE-2026-58704 — CISA KEV · Known exploited · Google Pixel cellular modem CONTINUING WATCH · update supported Pixels to patch level 2026-09-05+ · CISA date September 19 · Newsletter Drop Date October 19

CVE-2026-58704 — CISA KEV · Known exploited

Google reports indications of limited, targeted exploitation.

Action and dates: Update supported Pixel devices to security patch level 2026-09-05 or later. First CCD tracking: September 21; prior newsletter appearance not established. First disclosure: September 15. KEV addition and last material update: September 16. CISA remediate-by: September 19. Newsletter Drop Date: October 19.

Google Pixel September 2026 security bulletin

CVE-2025-39964 — CISA KEV · Known exploited; CVE-2026-53266 — CISA KEV · Known exploited; CVE-2025-39682 — CISA KEV · Known exploited · Linux kernel CONTINUING WATCH · patch only through exact distro/release/kernel flavor or appliance support path; verify running state · CISA date September 21 · Newsletter Drop Date October 19

CVE-2025-39964 — CISA KEV · Known exploited · AF_ALG

Applicability: Exact distribution release, kernel package/flavor and product support path control exposure. For embedded appliances, use the appliance maker’s supported firmware or advisory unless it explicitly supports installing a distribution kernel.

Patch examples: Ubuntu generic: 25.04 6.14.0-37.37; 24.04 6.8.0-90.91; 22.04 5.15.0-164.174; 20.04 5.4.0-224.244; 18.04 4.15.0-245.257; 16.04 4.4.0-276.310. Debian: bullseye 5.10.247-1; bookworm 6.1.158-1 (DSA-6053-1); trixie 6.12.57-1; bullseye linux-6.1 6.1.158-1~deb11u1. SUSE: SLES 15 SP7 kernel-default >= 6.4.0-150700.53.81.1; SLES 16.0 >= 6.12.0-160000.37.1; SLES 15 SP6 LTSS >= 6.4.0-150600.23.92.1; SLES 12 SP5 LTSS >= 4.12.14-122.296.1.

Ubuntu cloud, HWE and vendor flavors and SUSE cloud/image branches have separate status; some remained vulnerable or work in progress as of cutoff. Red Hat listed no mitigation meeting its criteria. No Red Hat fixed-package version was confirmed in the cited record as of cutoff; use the current product-specific advisory to identify the applicable status and package.

First CCD tracking: September 21; prior newsletter appearance not established. KEV addition and last material update: September 18. CISA remediate-by: September 21. Newsletter Drop Date: October 19.

CVE-2026-53266 — CISA KEV · Known exploited · ebtables SNAT

Applicability: Red Hat says exposure requires bridge-netfilter ebtables SNAT rules that rewrite ARP hardware addresses. Exact release and kernel flavor still control affected status; appliances need their vendor’s supported firmware or advisory.

Patch examples: Ubuntu 26.04 generic 7.0.0-31.31 and Ubuntu 24.04 HWE 7.0 7.0.0-31.31~24.04.1. As of cutoff, Ubuntu generic 24.04, 22.04 and 20.04 and many cloud flavors remained vulnerable or work in progress; the two fixed examples are not universal Ubuntu remediation. Debian listed DLA-4664-1, DLA-4665-1 and DLA-4671-1 as of cutoff; use the current Debian tracker for applicable release and package status. SUSE: SLES 15 SP7 kernel-default >= 6.4.0-150700.53.66.1; SLES 16.0 >= 6.12.0-160000.36.1; SLE Micro 6.0/6.1 >= 6.4.0-49.1; SLE Micro 6.2 >= 6.12.0-160000.36.1.

Workaround: Where the Red Hat exposure condition applies and a patch is pending, disable ARP hardware-address rewriting in affected ebtables rules or remove the ARP SNAT rules. This is a workaround, not the patch.

First CCD tracking: September 21; prior newsletter appearance not established. KEV addition and last material update: September 18. CISA remediate-by: September 21. Newsletter Drop Date: October 19.

CVE-2025-39682 — CISA KEV · Known exploited · kernel TLS receive path

Applicability: Red Hat says the trigger requires use of the kTLS ULP (CONFIG_TLS, attached through SOL_TLS). kTLS use is an applicability condition, not a workaround. Appliances need their vendor’s supported firmware or advisory.

Patch examples: Ubuntu: 25.04 generic 6.14.0-34.34; 24.04 generic 6.8.0-86.87; 22.04 HWE 6.8 6.8.0-86.87~22.04.1; Ubuntu 22.04, 20.04 and 18.04 generic were marked not affected. Debian: bullseye not affected; bookworm 6.1.153-1 (DSA-6009-1); trixie 6.12.48-1 (DSA-6008-1); bullseye linux-6.1 6.1.153-1~deb11u1; unstable 6.16.5-1. SUSE: SLES 15 SP6 kernel-default >= 6.4.0-150600.23.73.1; SLES 15 SP7 >= 6.4.0-150700.53.19.1; SLES 16.0 >= 6.12.0-160000.6.1; SLE Micro 6.0/6.1 >= 6.4.0-35.1.

Ubuntu cloud and HWE flavors and other vendor branches have separate status. No Red Hat fixed-package version was confirmed in the cited record as of cutoff; use the current Red Hat advisory for product-specific status and the applicable package.

First CCD tracking: September 21; prior newsletter appearance not established. KEV addition and last material update: September 18. CISA remediate-by: September 21. Newsletter Drop Date: October 19.

For all three Linux records: Apply the supported distribution package or appliance firmware, follow vendor reboot guidance and verify the running kernel and package afterward. An upstream commit alone is not operational remediation. Patching or using a workaround does not determine whether a previously exposed system was compromised; investigate that separately under product-vendor guidance and the incident-response process.

Primary status pages: CVE-2025-39964 — Ubuntu, Debian, Red Hat, SUSE; CVE-2026-53266 — Ubuntu, Debian, Red Hat, SUSE; CVE-2025-39682 — Ubuntu, Debian, Red Hat, SUSE.

Sources

Primary sources and date context for this edition

Healthcare incidents

AI and clinical automation

Regulatory and privacy

Medical devices

Current-window CVEs

Continuing CVEs

Linux distribution status

Clinical Cyber Dispatch

Independent healthcare cybersecurity analysis for security and technology leaders.