> ## Content Index
> Fetch the complete content index at: https://www.clinicalcyber.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Senate Passes Healthcare Cybersecurity Bill; iRhythm Begins Patient Notifications
- URL: https://www.clinicalcyber.com/clinical-cyber-dispatch-edition-2026-10-05/
- Published: 2026-10-05T12:29:53.000Z
- Updated: 2026-10-05T12:29:53.000Z
- Description: S. 3315 clears the Senate with proposed minimum cybersecurity requirements, while iRhythm begins notifying patients following data theft from third-party business applications.
- Author: Clinical Cyber Dispatch
- Tags: #ccd-content:d7843661ca5dde4213df888b7dbbb1e317e43d3ae2e89f61a27c8aaa71432041, #ccd-edition:edition-2026-10-05

**Reporting window:** September 28–October 4, 2026 (America/New\_York) · **Evidence cutoff:** October 5, 2026, 12:00 a.m. EDT

Cisco disclosed an actively exploited path to administrator access in Catalyst SD-WAN Manager, while iRhythm moved a previously reported intrusion into patient notification. This issue also tracks an exploited FortiMail flaw without an available fix at the cutoff, California’s new health-AI laws, and a newly classified infant breathing-circuit recall.

**Later verification:** Primary sources were checked through October 5 at 12:06 a.m. EDT to confirm explicitly dated facts. That check did not move later activity into this reporting window.

- [CISO Quick Read](#quick-read)
- [Priority CVEs](#priority-cves)
- [Healthcare Incident Watch](#healthcare-incident-watch)
- [AI & Clinical Automation](#ai-clinical-automation)
- [Regulatory & Privacy](#regulatory-privacy)
- [Clinical Engineering & Medical Device Watch](#clinical-engineering)
- [CVE Tracker](#cve-tracker)
- [Sources](#sources)

## CISO Quick Read

- **S. 3315 would set a 36-month runway for proposed minimum healthcare cybersecurity practices.** The Senate-passed bill would direct HHS toward risk-based controls including multifactor authentication, PHI encryption and monitoring that includes penetration testing. Healthcare leaders can use the proposal to test budgets and evidence of implemented controls. [Read what the engrossed bill would change](#reg-s3315).
- **iRhythm began notifications October 2 after its forensic investigation and data review.** The company separated the June 3–8 unauthorized access, June 8 detection and October notification, and said the affected third-party business applications did not include its products or clinical and medical-device systems. [See the incident timeline](#incident-irhythm).
- **Luminis Health restored MyChart, but recovery work was not finished.** On September 29, Luminis said paper downtime records were still being scanned and some notes, labs and imaging might not yet be visible. Recovery teams should reconcile those records and downstream result workflows. [Read the recovery update](#incident-luminis).
- **California enacted two health-AI measures on September 30.** AB 1979 protects licensed clinicians’ independent judgment; SB 503 adds bias-risk, documentation, monitoring and mitigation duties for covered clinical-decision-support developers and deployers. Both take effect January 1, 2027; covered facilities, practices, developers and deployers should use that date to plan implementation. [Read the practical distinctions](#california-health-ai).
- **Cisco fixed an exploited SD-WAN Manager admin bypass; FortiMail fixed releases were still upcoming.** Customer-managed Cisco deployments should upgrade to the applicable fixed branch and investigate prior compromise; Cisco said its managed cloud service was fixed. For affected FortiMail releases, disable IBE, remove public webmail exposure or restrict it to trusted private networks until a fixed release is available. [Cisco details](#priority-cisco-sdwan) · [FortiMail details](#priority-fortimail).

## Priority CVEs

CISA’s dates below direct U.S. Federal Civilian Executive Branch agencies. They are not universal private-sector legal deadlines. For other organizations, the useful decision is whether the product and configuration are present, what the vendor requires, and whether investigation is warranted in addition to remediation.

CVE-2026-76504 · Cisco Catalyst SD-WAN Manager · CVSS 3.1 9.8 · CISA KEV · Known exploitedUpgrade to the fixed branch release; no workaround · CISA federal due date was October 3 

### Cisco Catalyst SD-WAN Manager API authentication bypass

CVE-2026-76504 lets an unauthenticated remote request reach Cisco Catalyst SD-WAN Manager as the administrator account. Cisco said it became aware of active exploitation in September. Customer-managed deployments should move to the fixed release for their installed branch; there is no workaround, and restricting management access is only temporary risk reduction. Cisco said it fixed the managed cloud service itself. Before or alongside upgrading, preserve evidence and investigate whether encoded API requests or unexpected administrative users indicate earlier compromise. An upgrade does not answer that question.

[Cisco security advisory for CVE-2026-76504](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU?ref=clinicalcyber.com) · [Tracker dates and retention](#cve-2026-76504)

CVE-2026-104286 · Fortinet FortiMail · CISA KEV · Known exploitedUse the vendor workaround while target releases remain upcoming · CISA federal due date was October 4 

### FortiMail unauthenticated arbitrary-file-write flaw

Fortinet says crafted HTTP or HTTPS requests can combine path traversal with null-byte handling to write arbitrary files, and that exploitation has been reported. The affected ranges are 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8 and 7.2.0–7.2.9.

**Patch status at the cutoff:** Fortinet listed 8.0.2, 7.6.7 and 7.4.9 as target releases but still described them as upcoming. Version 7.2 must move to 7.4 or later. Verify availability in Fortinet’s current advisory rather than assuming those builds have shipped.

**Workaround:** Until a fixed release is available, disable IBE, remove public webmail exposure or allow access only from trusted private networks. Fortinet also describes a WAF rule for `/ibe` POST requests containing `../`. A workaround is not a patch.

**Compromise investigation:** Review Fortinet’s published IOC addresses and system and encryption-log patterns separately from workaround or patch verification. Fortinet’s public advisory did not provide a numeric CVSS, so none is supplied here.

[Fortinet PSIRT advisory FG-IR-26-175](https://fortiguard.fortinet.com/psirt/FG-IR-26-175?ref=clinicalcyber.com) · [Tracker dates and retention](#cve-2026-104286)

CVE-2026-102489 · Zammad · CISA KEV · Known exploited; CVE-2026-102490 · Zammad · CISA KEV · Known exploitedTreat as an application-to-root chain; use current vendor security releases · CISA federal due date: October 5 

### Zammad application-to-root exploit chain

CISA describes CVE-2026-102489 as session fixation that can lead to remote code execution as the `zammad` user, and CVE-2026-102490 as local privilege escalation from that account to root. The two identities can be chained, but each remains a separate vulnerability with its own record.

**Action with an evidence limit:** Self-hosted owners should consult Zammad’s current security releases and apply the vendor’s remediation. The available first-party material did not establish exact fixed branches, so this issue does not invent them.

**Compromise investigation:** Investigate possible host-level and root compromise, not only application-session activity. CISA added both records October 2; their first-public-disclosure timing was not established in the available first-party material.

[CISA record for CVE-2026-102489](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field%5Fcve=CVE-2026-102489&ref=clinicalcyber.com) · [CISA record for CVE-2026-102490](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field%5Fcve=CVE-2026-102490&ref=clinicalcyber.com) · [Zammad releases](https://zammad.com/en/product/releases?ref=clinicalcyber.com) · [Tracker records](#cve-2026-102489)

## Healthcare Incident Watch

### iRhythm begins notification after forensic and data review

On October 2, iRhythm Technologies said an unauthorized party accessed and downloaded information from certain third-party-hosted business applications between June 3 and June 8\. The company detected the access on June 8, then conducted a forensic investigation and data review before beginning notifications on October 2.

The fields identified in that review could include patient name and contact information, iRhythm patient account number, device serial number, insurance number, date of service and date of birth. iRhythm said the applications did not store financial or payment-card information. It also said it had identified no impact to its products, clinical or medical-device systems, customer connections, manufacturing or distribution, patient safety, or its ability to serve patients.

Those are company findings, not a guarantee against future misuse. The release did not give a separate date on which the data review was completed.

[Read iRhythm’s October 2 incident update](https://www.globenewswire.com/news-release/2026/10/02/3374047/0/en/irhythm-provides-update-on-cybersecurity-incident-previously-disclosed-in-june-2026.html?ref=clinicalcyber.com)

### Luminis Health restores MyChart while downtime records are reconciled

Luminis Health said on September 29 that MyChart had been restored for appointments, prescription refills and messages. Telephones were also restored, and emergency departments and surgeries remained open. The system’s staged restoration and testing continued.

Paper records created during downtime were still being scanned, so some notes, laboratory results and imaging might not yet appear in the patient record. Clinical and health-information teams working through recovery should reconcile paper documentation with restored systems and check downstream result visibility rather than assuming restoration made every record immediately complete.

Luminis said the recent incident did not affect the system that stores patient records. It had not named an actor or identified a confirmed notification population in the cited update.

[Read Luminis Health’s cybersecurity incident status page](https://www.luminishealth.org/en/cybersecurity-incident-update?language%5Fcontent%5Fentity=en&ref=clinicalcyber.com)

### IU Health notifies patients after review of isolated legacy imaging-system access

IU Health said it learned on August 4 that its IT vendor, AME Group, might have been susceptible to a previously unknown vulnerability in services supporting an isolated IU Health legacy system. An independent review found unauthorized access to limited radiology information from Southern Indiana imaging centers. IU Health began individual notifications September 29.

The information varied by person and could include name, date of birth, health-plan member ID and limited treatment information. IU Health said its network, core systems and electronic medical record were not accessed, and that patient care was not affected.

The August date marks IU Health’s awareness and the start of review; September 29 marks notification. The record does not establish a notice violation, broader electronic-medical-record access or a patient-care disruption.

[Read IU Health’s vendor incident release](https://iuhealth.org/for-media/press-releases/iu-health-reports-vendor-security-incident-in-southern-indiana?ref=clinicalcyber.com)

## AI & Clinical Automation

### California signs AB 1979 and SB 503

Governor Gavin Newsom signed both measures September 30 as part of a broader California AI package. California’s official status records show that they were chaptered that day: AB 1979 as Chapter 854 and SB 503 as Chapter 857\. Both are non-urgency statutes and take effect January 1, 2027 under Article IV, section 8(c)(1) of the California Constitution.

**AB 1979** requires covered health facilities, clinics and practices to preserve licensed clinicians’ independent professional judgment when clinical-decision-support output informs care. It also bars AI from independently performing functions that California law reserves to licensed people.

**SB 503** requires covered developers and deployers to make reasonable efforts to identify foreseeable biased impacts. Developers must mitigate those impacts and supply documentation about intended use, training data, evaluation, governance, limitations and monitoring. Deployers must monitor regularly and take proportionate mitigation steps.

**Practical review for January 1, 2027:** California providers and vendors should map which party develops or deploys each covered system, how clinician judgment is preserved, what bias monitoring occurs and what documentation contracts must deliver.

[Governor’s September 30 signing announcement](https://www.gov.ca.gov/2026/09/30/californias-nation-leading-ai-framework-just-got-stronger-governor-newsom-signs-more-first-in-the-nation-worker-protections-and-more/?ref=clinicalcyber.com) · [California AB 1979 chapter status](https://leginfo.legislature.ca.gov/faces/billStatusClient.xhtml?bill%5Fid=202520260AB1979&ref=clinicalcyber.com) · [California SB 503 chapter status](https://leginfo.legislature.ca.gov/faces/billStatusClient.xhtml?bill%5Fid=202520260SB503&ref=clinicalcyber.com) · [California Constitution effective-date rule](https://leginfo.legislature.ca.gov/faces/codes%5FdisplaySection.xhtml?lawCode=CONS§ionNum=SEC.+8.&article=IV&ref=clinicalcyber.com)

### Ongoing FDA robotics consultation

FDA’s draft guidance for robotically assisted surgical-device premarket submissions was posted September 24, before this reporting window. It is draft, nonbinding and not for implementation—not an in-window announcement. The consultation remains actionable because comments in docket FDA-2026-N-9505 are due November 24\. [See the active proceeding](#reg-fda-robotic-guidance).

## Regulatory & Privacy

### Senate action on healthcare cybersecurity requirements

S. 3315 · Health Care Cybersecurity and Resiliency Act of 2026 · Senate-passed, not lawTrack House action; do not treat proposed requirements as operative · Next date unknown 

#### The Senate passes S. 3315

The Senate passed S. 3315 with an amendment by unanimous consent on September 30\. The Health Care Cybersecurity and Resiliency Act remains unenacted, and House action is still required.

Section 8 of the engrossed bill would direct HHS to update the HIPAA security regulations with minimum, risk-based practices for covered healthcare-sector entities, covered entities and business associates. The listed practices include multifactor authentication, encryption of protected health information, and monitoring that includes penetration testing. The text does not make penetration testing annual. It would make the updated regulations and each new requirement effective 36 months after enactment.

Other sections would strengthen HHS and CISA coordination and joint incident-response planning; authorize HHS to award cybersecurity grants to specified eligible entities rather than create grants available now; require regulations explaining how recognized security practices and investments are considered in fines, audits and remedies; and address coordination for mandatory cybersecurity incident reporting.

For healthcare security leaders, the practical value now is planning: map current controls against the proposed baseline, model funding and staffing over the 36-month runway, and preserve evidence that safeguards are implemented and operating. That work can inform budgets and board discussions without treating the proposal as a current compliance obligation.

[Congress.gov actions for S. 3315](https://www.congress.gov/bill/119th-congress/senate-bill/3315/all-actions?ref=clinicalcyber.com) · [GovInfo engrossed Senate bill](https://www.govinfo.gov/app/details/BILLS-119s3315es?ref=clinicalcyber.com)

### Active / Ongoing

FDA generative-AI-enabled medical devices discussion paper · Active request for commentSubmit evidence by October 19, 2026 · Not guidance or a policy change 

#### Docket FDA-2026-N-7874

FDA is seeking comment on risk assessment, premarket evaluation and postmarket monitoring for generative-AI-enabled medical devices. This is a discussion paper and request for comment, not draft guidance, final guidance or a new requirement.

**Decision:** Device manufacturers, providers and researchers should decide whether they have evidence to submit by October 19\. FDA states the calendar date but not a separate time-zone cutoff; confirm the docket before a last-day filing.

[FDA discussion paper and comment instructions](https://www.fda.gov/medical-devices/digital-health-center-excellence/considerations-regulation-generative-ai-enabled-medical-devices-discussion-paper-and-request?ref=clinicalcyber.com)

FDA robotically assisted surgical devices draft guidance · Active / Ongoing · Draft, nonbindingComments due November 24, 2026 · Decide whether to submit testing, clinical-data or labeling evidence 

#### Docket FDA-2026-N-9505

The draft covers nonclinical testing, clinical data and labeling for certain teleoperated, software-controlled robotically assisted surgical devices. FDA marks it “not for implementation.” It was posted September 24, before this reporting window, and remains here because the consultation is open.

**Decision:** Device makers, providers and researchers should decide whether to submit evidence by November 24\. FDA supplies a date, not a separate time-zone cutoff; check the docket before a last-day filing.

[FDA draft guidance and submission information](https://www.fda.gov/regulatory-information/search-fda-guidance-documents/robotically-assisted-surgical-devices-premarket-submissions?ref=clinicalcyber.com) · [Federal Register notice](https://www.federalregister.gov/documents/2026/09/25/2026-19704/robotically-assisted-surgical-devices-premarket-submissions-draft-guidance-for-industry-and-food-and?ref=clinicalcyber.com)

### Standing Watch

FDA robotic-device benefit-risk workshop · Scheduled for December 2–3In-person registration closes November 23 or earlier at capacity; this is not a regulatory deadline 

#### Hybrid public workshop

FDA scheduled the workshop for 10:00 a.m.–4:00 p.m. ET on both days to discuss benefit-risk evaluation for robotic medical devices with autonomous functions or remote teleoperation. The November 23 date applies to in-person registration, not comments or compliance; virtual registration remains available.

[FDA workshop page and registration](https://www.fda.gov/news-events/fda-meetings-conferences-and-workshops/public-workshop-evaluating-benefit-risk-robotic-medical-devices-autonomous-or-remote-teleoperation?ref=clinicalcyber.com)

CISA CIRCIA final rule · Rulemaking ongoing; no current reporting duty under CIRCIAMaintain readiness and watch the primary page · Final-rule date unknown 

#### Cyber Incident Reporting for Critical Infrastructure Act

CISA’s rulemaking continues. A CIRCIA reporting requirement does not apply until an effective final rule exists, and no final-rule date was announced in the cited record.

[CISA’s CIRCIA rulemaking page](https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/cyber-incident-reporting-critical-infrastructure-act-2022-circia?ref=clinicalcyber.com)

HHS HIPAA Security Rule NPRM · Pending proposalUse July 2027 only as a planning target, not a legal or compliance deadline 

#### Long-range planning watch

The rulemaking remains pending. Organizations can use the proposal for gap planning, while continuing to distinguish proposed requirements from the current HIPAA Security Rule.

[HHS HIPAA Security Rule NPRM page](https://www.hhs.gov/hipaa/for-professionals/security/hipaa-security-rule-nprm/index.html?ref=clinicalcyber.com)

California CCPA automated-decisionmaking regulations · Future implementation milestonePrepare affected workflow, notice and risk-assessment processes for January 1, 2027 

#### California automated-decisionmaking implementation

The January 1 date is an implementation milestone. Affected organizations should map automated-decision workflows, notices, access and opt-out handling, and risk-assessment obligations to the final California text.

[California Privacy Protection Agency rulemaking updates](https://cppa.ca.gov/regulations/ccpa%5Fupdates.html?ref=clinicalcyber.com)

## Clinical Engineering & Medical Device Watch

### Draeger removes VentStar Resus Neo hoses after crack and detachment reports

FDA updated its communication October 2 to classify event 99787 as Class I. The removal covers VentStar Resus Neo model MP00310, UDI 04048675422358, used for infants weighing up to 22 pounds. A cracked or detached hose can restrict ventilation or delay therapy, potentially causing desaturation, hypoxia or death. Draeger reported no serious injuries or deaths as of September 3.

**Action:** Inspect hoses before use and discard any showing cracks or detachment. These hoses are used in critical and emergency situations, so match the model and UDI rather than treating the notice as a general breathing-circuit warning.

[FDA: Draeger VentStar Resus Neo breathing-circuit recall](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/breathing-circuit-recall-draeger-removes-ventstar-resus-neo-hoses?ref=clinicalcyber.com) · [FDA event 99787 record](https://www.accessdata.fda.gov/scripts/ires/index.cfm?Event=99787&ref=clinicalcyber.com) · [Standing Watch record](#device-99787)

### FDA Class I Standing Watch

AVID Medical kits with Medline Namic Star Off Handle manifolds · Event 99339 · FDA Class I correction · Status not shown as terminatedQuarantine affected kits, apply the warning label and remove the affected manifold 

#### AVID Medical kits with Medline Namic Star Off Handle manifolds · Event 99339

FDA Class I correction · Status not shown as terminated

Quarantine affected kits, apply the warning label and remove the affected manifold; follow FDA instructions if use is medically unavoidable.

[FDA AVID/Namic correction](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/convenience-kit-correction-avid-medical-issues-correction-kits-containing-medline-namic-star-handle?ref=clinicalcyber.com) · [Event 99339](https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfres/res.cfm?start%5Fsearch=1&event%5Fid=99339&ref=clinicalcyber.com)

BMC Medical Luna G3 APAP model LG3600, firmware G3-2.00.76 · Recall Z-2979-2026 · FDA Class I recall · FDA described a potentially uncorrected subsetDiscontinue affected-firmware devices until replacement 

#### BMC Medical Luna G3 APAP model LG3600, firmware G3-2.00.76 · Recall Z-2979-2026

FDA Class I recall · FDA described a potentially uncorrected subset

Firmware can stop therapy under high-pressure, respiratory-rate and peak-flow conditions. Discontinue affected-firmware devices until replacement; verify serial number and firmware with the clinician, DME supplier or provider.

[FDA BMC Luna G3 recall](https://www.fda.gov/safety/recalls-market-withdrawals-safety-alerts/bmc-medical-co-ltd-recalls-luna-g3-apap-model-lg3600-firmware-g3-20076-due-firmware-defect?ref=clinicalcyber.com)

BD Alaris pump infusion sets · Event 99298 · FDA Class I correction · Open/classified at verificationDiscard discontinued sets and use clinically appropriate alternatives 

#### BD Alaris pump infusion sets · Event 99298

FDA Class I correction · Open/classified at verification

Performance discrepancies can cause under- or over-infusion, delayed occlusion alarms and inaccurate bolus delivery. Discard discontinued sets and use clinically appropriate alternatives. Prioritize critical and pediatric patients; if affected sets cannot be avoided, follow BD’s mitigations and use enhanced monitoring.

[FDA BD Alaris update](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/update-alert-infusion-set-performance-issue-bd?ref=clinicalcyber.com) · [Classified record 221227](https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfres/res.cfm?id=221227&ref=clinicalcyber.com)

Abiomed Impella controllers · Event 99671 · FDA Class I removal · Three classified recordsOn the stated alarms, reinsert the purge disc, then use a backup controller 

#### Abiomed Impella controllers · Event 99671

FDA Class I removal · Three classified records

Purge-cassette recognition failure can require a controller exchange and briefly interrupt support. Inventory may remain in use while service is pending; on the stated alarms, reinsert the purge disc, then use a backup controller and coordinate service if the alarm does not clear.

[FDA Abiomed Impella alert](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/early-alert-heart-pump-controller-purge-cassette-issue-abiomed?ref=clinicalcyber.com) · [Event 99671](https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfres/res.cfm?start%5Fsearch=1&event%5Fid=99671&ref=clinicalcyber.com)

AVID/Halyard kits containing recalled sodium chloride ampules · Event 99758 · FDA Class I correction · Open/classified at verificationQuarantine and label the kits, then remove and discard the implicated ampules 

#### AVID/Halyard kits containing recalled sodium chloride ampules · Event 99758

FDA Class I correction · Open/classified at verification

Affected kits contain sodium chloride ampules recalled for a quality and sterility concern. Quarantine and label the kits, then remove and discard the implicated ampules.

[Event 99758](https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfres/res.cfm?start%5Fsearch=1&event%5Fid=99758&ref=clinicalcyber.com) · [FDA sodium chloride ampule recall](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/sodium-chloride-flush-recall-spectra-medical-removes-sodium-chloride-injection-usp-ampules?ref=clinicalcyber.com)

CooperSurgical INCA infant/neonatal nasal CPAP sets · Event 99643 · FDA Class I removal · Open/classified at verificationStop use and distribution, segregate and return affected sets 

#### CooperSurgical INCA infant/neonatal nasal CPAP sets · Event 99643

FDA Class I removal · Open/classified at verification

A loose connection can cause loss of CPAP and decreased oxygenation. Stop use and distribution, segregate and return affected sets; if a connection loosens during use, replace the tubing or CPAP.

[FDA CooperSurgical INCA alert](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/early-alert-ventilator-issue-coopersurgical?ref=clinicalcyber.com) · [Event 99643](https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfres/res.cfm?start%5Fsearch=1&event%5Fid=99643&ref=clinicalcyber.com)

Boston Scientific Imager II angiographic catheters · Event 99687 · FDA Class I removal · Open/classified at verificationStop use and distribution; verify inner and outer UPN and lot markings 

#### Boston Scientific Imager II angiographic catheters · Event 99687

FDA Class I removal · Open/classified at verification

Reduced stabilizing agents can permit tip degradation and detachment; FDA described procedural delay as most likely and embolism or organ failure as a remote worst case, with two serious injuries and no deaths as of July 16\. Stop use and distribution; verify inner and outer UPN and lot markings, segregate and return affected product.

[FDA Imager II recall](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/angiographic-catheter-recall-boston-scientific-removes-imager-ii-angiographic-catheters?ref=clinicalcyber.com) · [Event 99687](https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfres/res.cfm?start%5Fsearch=1&event%5Fid=99687&ref=clinicalcyber.com)

Draeger VentStar Resus Neo hoses, model MP00310 · Event 99787 · FDA Class I removal · Classified October 2Inspect before use and discard hoses showing cracks or detachment 

#### Draeger VentStar Resus Neo hoses, model MP00310 · Event 99787

FDA Class I removal · Classified October 2

See the brief update above for model, UDI and risk. Inspect before use and discard hoses showing cracks or detachment.

[FDA Draeger VentStar Resus Neo recall](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/breathing-circuit-recall-draeger-removes-ventstar-resus-neo-hoses?ref=clinicalcyber.com) · [Event 99787](https://www.accessdata.fda.gov/scripts/ires/index.cfm?Event=99787&ref=clinicalcyber.com)

#### Archived from routine display: Boston Scientific ENROUTE · Event 99454

ENROUTE reached its preserved **Newsletter Drop Date of October 5, 2026** and now leaves routine display. Its FDA identity, removal instructions and history remain archived. This transition does not mean the recall is resolved, remediation is complete or downstream risk has ended.

[FDA: Boston Scientific ENROUTE removal](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/percutaneous-catheter-recall-boston-scientific-removes-enroute-transcarotid-neuroprotection-system?ref=clinicalcyber.com) · [FDA event 99454 recall record](https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfres/res.cfm?start%5Fsearch=1&event%5Fid=99454&ref=clinicalcyber.com)

## CVE Tracker

The current-window records come first. Open a summary for applicability, vendor action, source dates and the identity’s finite newsletter dates.

### New this edition and current-window additions

NEW · CVE-2026-86950 · Apple CoreGraphics · CISA KEV · Known exploitedInstall iOS/iPadOS 26.7.1, macOS Tahoe 26.7.1 or Sequoia 15.8.1 · Federal due date was October 2 · Drop November 2 

#### CVE-2026-86950 · Apple CoreGraphics

Apple says processing a malicious file may lead to code execution and that it is aware of possible use in an extremely sophisticated attack against specific targeted people on iOS before iOS 27\. Apple released the fixes September 28; CISA added the record September 29.

Applicability

Supported Apple devices below iOS/iPadOS 26.7.1, macOS Tahoe 26.7.1 or macOS Sequoia 15.8.1.

Action

Install the applicable Apple fixed release.

CISA federal date

October 2, 2026; applies to federal civilian agencies, not as a universal private-sector deadline.

CCD dates

First tracked October 5; first newsletter appearance not established; last material update September 29; Newsletter Drop Date November 2, 2026.

[Apple iOS/iPadOS advisory](https://support.apple.com/en-us/149226?ref=clinicalcyber.com) · [Apple macOS Tahoe advisory](https://support.apple.com/en-us/149228?ref=clinicalcyber.com) · [Apple macOS Sequoia advisory](https://support.apple.com/en-us/149229?ref=clinicalcyber.com)

NEW · CVE-2026-76504 · Cisco Catalyst SD-WAN Manager · CVSS 3.1 9.8 · CISA KEV · Known exploitedUpgrade to the fixed branch release and hunt separately · Federal due date was October 3 · Drop November 2 

#### CVE-2026-76504 · Cisco Catalyst SD-WAN Manager

Cisco disclosed the unauthenticated admin-level API bypass September 30 and updated the advisory October 2\. The vulnerability applies regardless of configuration; customer-managed action differs from Cisco-managed cloud service.

Action

Upgrade to 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 or 26.2.1, as applicable; migrate releases before 20.9\. There is no workaround. Cisco-managed cloud 20.15.605 was fixed by Cisco.

Investigation

Review `serviceproxy-access.log` for encoded `j_security_check` requests and `vmanage-server.log` for unexpected `viptela-reserved` users. Preserve evidence with `request admin-tech` before TAC review. Treat Live Protect only as temporary partial protection, not remediation.

CISA federal date

October 3, 2026.

CCD dates

First tracked October 5; first newsletter appearance not established; last material update October 2; Newsletter Drop Date November 2, 2026.

[Priority treatment](#priority-cisco-sdwan) · [Cisco advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU?ref=clinicalcyber.com)

NEW · CVE-2026-104286 · Fortinet FortiMail · CISA KEV · Known exploitedUse the supported workaround while target releases remain upcoming · Federal due date was October 4 · Drop November 2 

#### CVE-2026-104286 · Fortinet FortiMail

Fortinet published the exploited arbitrary-file-write flaw October 1\. Affected releases are 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8 and 7.2.0–7.2.9\. Fortinet’s public advisory did not provide a numeric CVSS.

Patch status

Targets are 8.0.2+, 7.6.7+ or 7.4.9+; 7.2 must move to 7.4+. Fortinet still called those target releases upcoming at the cutoff.

Workaround

Disable IBE, remove public webmail exposure, restrict it to trusted private networks, or apply Fortinet’s exact WAF pattern while awaiting a fixed release.

Investigation

Review the vendor’s IOC IP addresses and specified system and encryption logs separately.

CISA federal date

October 4, 2026.

CCD dates

First tracked October 5; first newsletter appearance not established; last material update October 1; Newsletter Drop Date November 2, 2026.

[Priority treatment](#priority-fortimail) · [Fortinet advisory](https://fortiguard.fortinet.com/psirt/FG-IR-26-175?ref=clinicalcyber.com)

CVE-2026-102489 · Zammad · CISA KEV · Known exploited; CVE-2026-102490 · Zammad · CISA KEV · Known exploitedTreat as an application-to-root chain; exact fixed branches were not established · Federal due date October 5 · Drop November 2 

#### CVE-2026-102489 · session fixation and code execution as `zammad`

CISA added the record October 2\. Use current Zammad security releases and vendor remediation; the available first-party material did not establish exact fixed versions. Investigate possible host compromise separately.

**Dates:** First tracked October 5; first newsletter appearance not established; last material update October 2; CISA federal due date October 5; Newsletter Drop Date November 2, 2026.

#### CVE-2026-102490 · local escalation from `zammad` to root

CISA says this identity can chain with CVE-2026-102489\. Preserve it as a separate record and investigate possible root compromise rather than limiting review to application sessions.

**Dates:** First tracked October 5; first newsletter appearance not established; last material update October 2; CISA federal due date October 5; Newsletter Drop Date November 2, 2026.

The first-public-disclosure date for either identity was not established. [Priority treatment](#priority-zammad) · [CISA CVE-2026-102489 record](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field%5Fcve=CVE-2026-102489&ref=clinicalcyber.com) · [CISA CVE-2026-102490 record](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field%5Fcve=CVE-2026-102490&ref=clinicalcyber.com) · [Zammad releases](https://zammad.com/en/product/releases?ref=clinicalcyber.com)

NEW · CVE-2026-88779 · Citrix NetScaler ADC/Gateway with SAML SP or IdP configured · CVSS 4.0 8.7 · CISA KEV · Known exploitedUpgrade customer-managed systems · Federal due date October 7 · Drop November 2 

#### CVE-2026-88779 · Citrix NetScaler ADC and Gateway

Citrix disclosed the remotely reachable memory-overflow denial of service October 3; CISA added it October 4\. It applies to customer-managed systems configured as a SAML service provider or identity provider. Citrix-managed cloud is provider-updated.

Action

Upgrade to 14.1-73.41+, 13.1-64.28+, 14.1-FIPS 14.1-73.41+ or 13.1-FIPS/NDcPP 13.1-37.282+, as applicable.

CISA federal date

October 7, 2026.

CCD dates

First tracked October 5; first newsletter appearance not established; last material update October 4; Newsletter Drop Date November 2, 2026.

[Citrix bulletin CTX697174](https://support.citrix.com/external/article/CTX697174?ref=clinicalcyber.com)

### How to read the continuing watch

A Newsletter Drop Date is the end of routine display, not a remediation deadline or proof that a vulnerability has been fixed. “First tracked” marks when this tracker began carrying the identity; it is not the vulnerability’s publication date. Where an earlier newsletter appearance cannot be confirmed, the record says so. CISA remediate-by dates below apply to federal civilian agencies and remain separate from private-sector decisions.

### Continuing Watch · Newsletter Drop Date October 12

CVE-2026-82583, CVE-2026-78224 and CVE-2026-82578 · NextGen Healthcare Mirth Connect · Not listed in CISA KEV at cutoffUpdate to Mirth Connect 4.7.2 or later · No CISA federal date · Drop October 12 

#### CVE-2026-82583 · CVSS 3.1 8.3

#### CVE-2026-78224 · CVSS 3.1 8.2

#### CVE-2026-82578 · CVSS 3.1 7.5

These healthcare-interface vulnerabilities share the vendor action: update Mirth Connect to 4.7.2 or later through NextGen’s customer portal. CISA’s medical advisory reported no known public exploitation.

**Dates for all three:** First tracked September 14; first newsletter appearance not established; last material update September 10; no CISA federal date; Newsletter Drop Date October 12, 2026.

[CISA medical advisory ICSMA-26-253-01](https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-01?ref=clinicalcyber.com)

CVE-2026-84869 · ConnectWise ScreenConnect · CISA KEV · Known exploitedUpgrade server and agents to 26.6.5+; permission change is temporary · Federal due date was September 14 · Drop October 12 

#### CVE-2026-84869 · ConnectWise ScreenConnect

Upgrade on-premises servers to 26.6.5 or later and update or reinstall clients and access agents. Removing `TransferFiles` permission is a temporary mitigation, not the patch.

**Dates:** First tracked September 14; first newsletter appearance not established; last material update September 11; CISA federal date September 14; Newsletter Drop Date October 12, 2026.

[ConnectWise ScreenConnect security bulletin](https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin?ref=clinicalcyber.com)

CVE-2026-20079 · Cisco Secure Firewall Management Center / Security Cloud Control · CISA KEV · Known exploitedApply the release-specific FMC hotfix; SaaS was provider-fixed · Federal due date was September 12 · Drop October 12 

#### CVE-2026-20079 · Cisco firewall management

Customer-managed FMC requires Cisco’s release-specific hotfix; there is no workaround. Cisco fixed Security Cloud Control as a service.

**Dates:** First tracked September 14; first newsletter appearance not established; last material update September 9; CISA federal date September 12; Newsletter Drop Date October 12, 2026.

[Cisco FMC authentication-bypass advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2?ref=clinicalcyber.com)

CVE-2026-86218 · N-able N-central · CISA KEV · Known exploitedInstall 2026.3 HF4 build 2026.3.1.14+ on self-hosted systems · Federal due date was September 11 · Drop October 12 

#### CVE-2026-86218 · N-able N-central

Self-hosted customers should install N-central 2026.3 HF4 build 2026.3.1.14 or later. N-able said hosted systems were patched.

**Dates:** First tracked September 14; first newsletter appearance not established; last material update September 8; CISA federal date September 11; Newsletter Drop Date October 12, 2026.

[N-able N-central hotfix notice](https://status.n-able.com/2026/09/06/n-central-2026-3-hotfix-4-cve-2026-86218/?ref=clinicalcyber.com)

CVE-2026-19490 · Citrix NetScaler ADC/Gateway · CISA KEV · Known exploitedUse Citrix’s branch-specific fixed release; no workaround · Federal due date was September 12 · Drop October 12 

#### CVE-2026-19490 · Citrix NetScaler authentication bypass

Upgrade affected customer-managed branches to the exact fixed release in Citrix’s table. There is no workaround; Citrix-managed services were provider-updated.

**Dates:** First tracked September 14; first newsletter appearance not established; last material update September 9; CISA federal date September 12; Newsletter Drop Date October 12, 2026.

[Citrix bulletin CTX696939](https://support.citrix.com/external/article/CTX696939/netscaler-adc-and-netscaler-gateway-secu.html?ref=clinicalcyber.com)

CVE-2026-85706 · GitLab CE/EE · CISA KEV · Known exploitedUpgrade self-managed GitLab to the fixed branch release; GitLab.com was patched · Federal due date was September 14 · Drop October 12 

#### CVE-2026-85706 · GitLab CE/EE

Upgrade self-managed GitLab to 19.1.8, 19.2.6, 19.3.2 or later on the applicable branch. GitLab.com was patched by the provider.

**Dates:** First tracked September 14; first newsletter appearance not established; last material update September 11; CISA federal date September 14; Newsletter Drop Date October 12, 2026.

[GitLab 19.3.2 patch release](https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/?ref=clinicalcyber.com)

CVE-2026-42018 · JFrog Artifactory Self Hosted · CISA KEV · Known exploitedUse JFrog’s exact branch-specific fixed-release map · Federal due date was September 25 · Drop October 12 

#### CVE-2026-42018 · JFrog Artifactory Self Hosted

The broad affected range begins below 7.111.20, but later branches have separate fixed versions. Map the deployed branch to JFrog’s table rather than treating 7.111.20 as a universal floor.

**Dates:** First tracked September 14; first newsletter appearance not established; last material update September 11; CISA federal date September 25; Newsletter Drop Date October 12, 2026.

[JFrog security advisories](https://docs.jfrog.com/releases/docs/jfrog-security-advisories?ref=clinicalcyber.com)

### Continuing Watch · Newsletter Drop Date October 19

CVE-2026-76461 · Cisco Secure Email Gateway · CISA KEV · Known exploitedUpgrade customer-managed appliances and preserve cluster-wide recovery boundaries · Federal due date was September 17 · Drop October 19 

#### CVE-2026-76461 · Cisco Secure Email Gateway

Upgrade customer-managed appliances to 15.5.5-014, 16.0.4-302 or 16.5.0-780 as applicable; Cisco recommends 16.5.0-780 and says there is no workaround. Cisco Secure Email Cloud was upgraded by Cisco.

**Investigation and recovery:** Inspect external network and firewall logs. Follow Cisco’s distinct physical and virtual recovery paths, renew affected credentials and cryptographic material, and restore every member of a cluster containing a compromised appliance because shared SSH keys can expose peers.

**Dates:** First tracked September 21; first newsletter appearance not established; last material update September 17; CISA federal date September 17; Newsletter Drop Date October 19, 2026.

[Cisco Secure Email Gateway advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX?ref=clinicalcyber.com)

CVE-2026-76460 · Cisco ISE and ISE-PIC · CVSS 3.1 10.0 · CISA KEV · Known exploitedInstall the exact ISE patch; migrate 3.0; no workaround · Federal due date was September 19 · Drop October 19 

#### CVE-2026-76460 · Cisco Identity Services Engine

Install 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 or 3.5 Patch 4, according to branch. ISE 3.0 is out of software maintenance and must migrate. Infrastructure ACLs are mitigation only, not a workaround.

**Investigation:** Inspect `access.log` on every node and external network and firewall logs. If malicious activity is suspected, follow Cisco guidance to re-image affected nodes and restore configuration as needed.

**Dates:** First tracked September 21; first newsletter appearance not established; last material update September 16; CISA federal date September 19; Newsletter Drop Date October 19, 2026.

[Cisco ISE advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5?ref=clinicalcyber.com)

CVE-2026-87886 · Acronis Backup control-panel plugins · CVSS 3.0 7.8 · CISA KEV · Known exploitedUpdate the cPanel, Plesk or DirectAdmin plugin to its fixed floor · Federal due date was September 19 · Drop October 19 

#### CVE-2026-87886 · Acronis Backup plugins and extensions

Acronis described limited targeted exploitation involving cPanel/WHM. Update to cPanel 1.9.3.1021, Plesk 1.8.11.638 or DirectAdmin 1.2.3.238 or later, as applicable.

**Dates:** First tracked September 21; first newsletter appearance not established; last material update September 17; CISA federal date September 19; Newsletter Drop Date October 19, 2026.

[Acronis advisory SEC-10986](https://security-advisory.acronis.com/advisories/SEC-10986?ref=clinicalcyber.com)

CVE-2026-58704 · Google Pixel cellular modem · CISA KEV · Known exploitedUpdate supported Pixels to security patch level 2026-09-05+ · Federal due date was September 19 · Drop October 19 

#### CVE-2026-58704 · Google Pixel cellular modem

Google reported indications of limited, targeted exploitation. Update supported Pixel devices to security patch level 2026-09-05 or later.

**Dates:** First tracked September 21; first newsletter appearance not established; last material update September 16; CISA federal date September 19; Newsletter Drop Date October 19, 2026.

[Google Pixel September 2026 security bulletin](https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01?ref=clinicalcyber.com)

CVE-2025-39964 · Linux AF\_ALG · CISA KEV · Known exploited; CVE-2026-53266 · Linux ebtables SNAT · CISA KEV · Known exploited; CVE-2025-39682 · Linux kTLS receive path · CISA KEV · Known exploitedUse exact distribution/release/flavor packages, reboot and verify the running kernel · Federal due date was September 21 · Drop October 19 

Upstream fixes alone do not establish a deployable remedy. Exact distribution release, kernel package and flavor—or an appliance maker’s supported firmware—control remediation. Do not install a distribution kernel on an embedded appliance unless its vendor supports that path.

#### CVE-2025-39964 · Linux kernel AF\_ALG

**Supported package examples:**

- **Ubuntu:** 25.04 generic 6.14.0-37.37; 24.04 generic 6.8.0-90.91; 22.04 generic 5.15.0-164.174; 20.04 generic 5.4.0-224.244; 18.04 generic 4.15.0-245.257; 16.04 generic 4.4.0-276.310.
- **Debian:** bullseye 5.10.247-1; bookworm 6.1.158-1 (DSA-6053-1); trixie 6.12.57-1; bullseye linux-6.1 6.1.158-1\~deb11u1.
- **SUSE:** SLES 15 SP7 `kernel-default` 6.4.0-150700.53.81.1 or later; SLES 16.0 `kernel-default` 6.12.0-160000.37.1 or later; SLES 15 SP6 LTSS 6.4.0-150600.23.92.1 or later; SLES 12 SP5 LTSS 4.12.14-122.296.1 or later.

Ubuntu cloud, HWE and vendor flavors and SUSE cloud and image branches have separate status; some remained vulnerable or work in progress at verification. Red Hat said no mitigation met its criteria, and its public CVE page did not provide a fixed-package table. Use the product-specific Red Hat status or advisory.

**Dates:** First tracked September 21; first newsletter appearance not established; last material update September 18; CISA federal date September 21; Newsletter Drop Date October 19, 2026.

[Ubuntu status](https://ubuntu.com/security/CVE-2025-39964?ref=clinicalcyber.com) · [Debian tracker](https://security-tracker.debian.org/tracker/CVE-2025-39964?ref=clinicalcyber.com) · [Red Hat status](https://access.redhat.com/security/cve/cve-2025-39964?ref=clinicalcyber.com) · [SUSE status](https://www.suse.com/security/cve/CVE-2025-39964.html?ref=clinicalcyber.com)

#### CVE-2026-53266 · Linux kernel ebtables SNAT

**Applicability:** Red Hat says exposure requires bridge-netfilter ebtables SNAT rules that rewrite ARP hardware addresses. The exact release and flavor still determine affected status.

**Supported package examples:**

- **Ubuntu:** 26.04 generic 7.0.0-31.31; 24.04 HWE 7.0 7.0.0-31.31\~24.04.1\. At verification, Ubuntu generic 24.04, 22.04 and 20.04 and many cloud flavors remained vulnerable or work in progress; these two examples are not universal Ubuntu remediation.
- **Debian:** the public tracker listed DLA-4664-1, DLA-4665-1 and DLA-4671-1 but did not provide a reliable fixed-version table. Use the current tracker and applicable advisory.
- **SUSE:** SLES 15 SP7 `kernel-default` 6.4.0-150700.53.66.1 or later; SLES 16.0 6.12.0-160000.36.1 or later; SLE Micro 6.0/6.1 6.4.0-49.1 or later; SLE Micro 6.2 6.12.0-160000.36.1 or later.

**Workaround, not patch:** Where the stated exposure condition applies and a supported package is pending, disable ARP hardware-address rewriting in affected ebtables rules or remove the ARP SNAT rules.

**Dates:** First tracked September 21; first newsletter appearance not established; last material update September 18; CISA federal date September 21; Newsletter Drop Date October 19, 2026.

[Ubuntu status](https://ubuntu.com/security/CVE-2026-53266?ref=clinicalcyber.com) · [Debian tracker](https://security-tracker.debian.org/tracker/CVE-2026-53266?ref=clinicalcyber.com) · [Red Hat status](https://access.redhat.com/security/cve/cve-2026-53266?ref=clinicalcyber.com) · [SUSE status](https://www.suse.com/security/cve/CVE-2026-53266.html?ref=clinicalcyber.com)

#### CVE-2025-39682 · Linux kernel TLS receive path

**Applicability:** Red Hat says the trigger requires use of the kTLS ULP—`CONFIG_TLS`, attached through `SOL_TLS`. That condition is not a workaround and does not change the KEV status.

**Supported package examples:**

- **Ubuntu:** 25.04 generic 6.14.0-34.34; 24.04 generic 6.8.0-86.87; 22.04 HWE 6.8 6.8.0-86.87\~22.04.1\. Ubuntu marked 22.04, 20.04 and 18.04 generic not affected; cloud, HWE and vendor flavors retain separate status.
- **Debian:** bullseye not affected; bookworm 6.1.153-1 (DSA-6009-1); trixie 6.12.48-1 (DSA-6008-1); bullseye linux-6.1 6.1.153-1\~deb11u1; unstable 6.16.5-1.
- **SUSE:** SLES 15 SP6 `kernel-default` 6.4.0-150600.23.73.1 or later; SLES 15 SP7 6.4.0-150700.53.19.1 or later; SLES 16.0 6.12.0-160000.6.1 or later; SLE Micro 6.0/6.1 6.4.0-35.1 or later.

Red Hat’s public CVE page did not provide a fixed-package table; use its current product-specific status.

**Dates:** First tracked September 21; first newsletter appearance not established; last material update September 18; CISA federal date September 21; Newsletter Drop Date October 19, 2026.

[Ubuntu status](https://ubuntu.com/security/CVE-2025-39682?ref=clinicalcyber.com) · [Debian tracker](https://security-tracker.debian.org/tracker/CVE-2025-39682?ref=clinicalcyber.com) · [Red Hat status](https://access.redhat.com/security/cve/cve-2025-39682?ref=clinicalcyber.com) · [SUSE status](https://www.suse.com/security/cve/CVE-2025-39682.html?ref=clinicalcyber.com)

#### Running-state verification

After installing the supported distribution package or appliance firmware, follow that vendor’s reboot guidance and verify the running kernel and flavor—not only the package present on disk. A generic kernel version does not prove that a cloud, HWE, realtime, vendor or appliance branch is fixed.

#### Compromise investigation

Patching or applying the limited ebtables workaround does not determine whether an affected, exposed system was previously compromised. Investigate that question separately under the product vendor’s guidance and the organization’s incident-response process.

### Continuing Watch · Newsletter Drop Date October 26

CVE-2026-7273 · Zyxel GS1900 switches · CISA KEV · Known exploitedApply model-specific firmware and restrict management to trusted LANs · Federal due date was September 24 · Drop October 26 

#### CVE-2026-7273 · Zyxel GS1900 Series

Apply the model-specific 2.90(...2)C0 fixed release in Zyxel’s ten-model table. Restrict management to trusted LANs until upgraded. The original vendor disclosure was June 16; the September 21 KEV addition did not make the disclosure new.

**Dates:** First tracked September 28; first newsletter appearance not established; last material update September 21; CISA federal date September 24; Newsletter Drop Date October 26, 2026.

[Zyxel GS1900 advisory](https://community.zyxel.com/en/discussion/33340/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches?ref=clinicalcyber.com)

CVE-2026-85102 · Check Point gateways/Spark · CVSS 3.1 9.8 · CISA KEV · Known exploited; CVE-2026-93616 · Check Point Security Management · CVSS 3.1 9.8 · CISA KEV · Known exploitedApply the exact supported-branch fixes and investigate exposed systems · Federal due date was September 25 · Drop October 26 

#### CVE-2026-85102 · Check Point Security Gateways and Spark

Apply Check Point’s exact supported-branch fix and investigate exposed systems separately. Check Point said attacks were observed from September 12\. The initial fix availability predates this window; the exploitation update and KEV addition were in-window.

#### CVE-2026-93616 · Check Point Security Management

Apply the exact management-server branch fix and review management exposure and logs separately. Check Point disclosed this identity September 22 and reported a handful of targeted attacks on July 23.

**Dates for both:** First tracked September 28; first newsletter appearance not established; last material update September 22; CISA federal date September 25; Newsletter Drop Date October 26, 2026.

[Check Point advisory for both identities](https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/?ref=clinicalcyber.com)

CVE-2026-93952 · Arista VeloCloud Orchestrator · CVSS 3.1 10.0 · CISA KEV · Known exploitedPatch on-premises VCO; hosted service was patched · Federal due date was September 25 · Drop October 26 

#### CVE-2026-93952 · Arista VeloCloud Orchestrator

Hosted VCO was patched. On-premises customers should apply 5.2.3.16+ or 6.4.2.8+ as applicable; at the cutoff, fixes for 6.1 and 7.0 were forthcoming. Restrict web administration to trusted networks while applying a supported fix.

**Dates:** First tracked September 28; first newsletter appearance not established; last material update September 22; CISA federal date September 25; Newsletter Drop Date October 26, 2026.

[Arista security advisory 0183](https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183?ref=clinicalcyber.com)

CVE-2026-94127 · F5 BIG-IP APM · CISA KEV · Known exploitedApply the exact fixed/hardened branch release; iRule is detection support, not patch · Federal due date was September 25 · Drop October 26 

#### CVE-2026-94127 · F5 BIG-IP APM

For systems using an access policy and OAuth profile, apply F5’s exact fixed or hardened release for the installed branch. The vendor iRule is temporary detection and forensic support, not final remediation. The available primary record did not establish first-publication timing.

**Dates:** First tracked September 28; first newsletter appearance not established; last material update September 22; CISA federal date September 25; Newsletter Drop Date October 26, 2026.

[F5 advisory K000162605](https://my.f5.com/manage/s/article/K000162605?ref=clinicalcyber.com)

CVE-2026-5430 · WSO2 products · CISA KEV · Known exploitedUse WSO2’s exact product and update-level table · Federal due date was September 27 · Drop October 26 

#### CVE-2026-5430 · WSO2 products

Map the installed WSO2 product and update level to the vendor table. WSO2 describes an unsupported-JWT-algorithm authentication bypass and account-takeover path. The original May 3 disclosure predates the September 24 KEV addition.

**Dates:** First tracked September 28; first newsletter appearance not established; last material update September 24; CISA federal date September 27; Newsletter Drop Date October 26, 2026.

[WSO2 advisory WSO2-2026-5328](https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5328/?ref=clinicalcyber.com)

CVE-2026-71362 · Adobe Commerce / Magento Open Source · CISA KEV · Known exploitedApply Adobe’s fixed release for the installed 2.4.x branch · Federal due date was September 27 · Drop October 26 

#### CVE-2026-71362 · Adobe Commerce and Magento Open Source

Apply the fixed release for the applicable 2.4.x branch in APSB26-92\. Adobe’s original August 11 disclosure predates the September 24 KEV addition.

**Dates:** First tracked September 28; first newsletter appearance not established; last material update September 24; CISA federal date September 27; Newsletter Drop Date October 26, 2026.

[Adobe bulletin APSB26-92](https://helpx.adobe.com/security/products/magento/apsb26-92.html?ref=clinicalcyber.com)

CVE-2026-67279 · MikroTik RouterOS · CISA KEV · Known exploitedUpgrade RouterOS and review Flagged logs, users and scripts · Federal due date was September 28 · Drop October 26 

#### CVE-2026-67279 · MikroTik RouterOS

Upgrade to RouterOS 7.25beta3, 7.24.2, 7.23.4 or 6.49.21 as applicable; restrict SSH and review Flagged logs, unfamiliar users and scripts. CISA lists this exact identity, while MikroTik’s retrieved chain page names related CVEs; do not assign every chain step to CVE-2026-67279.

**Dates:** First tracked September 28; first newsletter appearance not established; last material update September 25; CISA federal date September 28; Newsletter Drop Date October 26, 2026.

[MikroTik September 2026 vulnerability page](https://mikrotik.com/supportsec/september-2026-vulnerability/?ref=clinicalcyber.com)

CVE-2026-65660 · Microsoft SharePoint Server · CVSS 3.1 8.8 · CISA KEV · Known exploitedInstall both required KBs where stated, verify build and investigate exposure · Federal due date was September 28 · Drop October 26 

#### CVE-2026-65660 · Microsoft SharePoint Server

- **Subscription Edition:** KB5002893, build 16.0.19725.20522.
- **SharePoint 2019:** both KB5002894 and KB5002896, build 16.0.10417.20198.
- **SharePoint 2016:** both KB5002905 and KB5002906, build 16.0.5565.1001.

Verify the installed build and investigate exposed servers separately. Microsoft’s original August 11 release predates its September 25 observed-exploitation update and KEV addition.

**Dates:** First tracked September 28; first newsletter appearance not established; last material update September 25; CISA federal date September 28; Newsletter Drop Date October 26, 2026.

[Microsoft CVE-2026-65660 update guide](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660?ref=clinicalcyber.com)

CVE-2026-87902 · WordPress Core · CISA KEV · Known exploitedUpdate to 7.1.2 or the supported branch backport; check exposure conditions · Federal due date was September 28 · Drop October 26 

#### CVE-2026-87902 · WordPress Core

Update to WordPress 7.1.2 or the patched backport for the installed supported branch. Exposure requires a readable top-level theme directory beginning `page-`; the PEAR route also depends on `register_argc_argv` being enabled.

**Dates:** First tracked September 28; first newsletter appearance not established; last material update September 25; CISA federal date September 28; Newsletter Drop Date October 26, 2026.

[WordPress security advisory GHSA-7hp8-65ch-5whp](https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp?ref=clinicalcyber.com)

CVE-2026-88771 · Citrix NetScaler ADC/Gateway · CVSS 4.0 9.5 · CISA KEV · Known exploited; CVE-2026-88772 · NetScaler with DTLS enabled · CVSS 4.0 9.5 · CISA KEV · Known exploitedUpgrade to the exact fixed build and investigate separately · Federal due date was September 30 · Drop October 26 

#### CVE-2026-88771 · Citrix NetScaler ADC and Gateway

Upgrade to 14.1-73.37+, 13.1-64.24+—avoiding 13.1-64.23 where Citrix’s cyclic-reboot condition applies—FIPS 14.1-73.37+, or 13.1-FIPS/NDcPP 13.1-37.279+, as applicable.

#### CVE-2026-88772 · NetScaler with DTLS enabled

This identity requires DTLS, including its default use on VPN virtual servers. Apply the same branch-specific fixed builds and verify the running build. Citrix-managed cloud was patched.

**Investigation:** Run Citrix’s indicator checks and independently scope possible compromise; a clean vendor scan is not conclusive.

**Dates for both:** First tracked September 28; first newsletter appearance not established; last material update September 27; CISA federal date September 30; Newsletter Drop Date October 26, 2026.

[Citrix bulletin for CVE-2026-88771 through CVE-2026-88778](https://community.citrix.com/techzone-blogs/110%5Fsecurity-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778?ref=clinicalcyber.com)

CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859 and CVE-2026-86860 · ServiceNow AI Platform · Not listed in CISA KEV at cutoffHosted instances were updated; self-hosted owners must map release family to the exact fixed floor · No CISA federal date · Drop October 26 

ServiceNow disclosed these five identities September 24 and reported no known malicious exploitation. They are not KEV records. Hosted instances were updated; self-hosted customers must map their release family and build to ServiceNow’s table rather than combining alternative fixed floors.

#### CVE-2026-86857 · CVSS 4.0 8.4

#### CVE-2026-86858 · CVSS 4.0 8.7

#### CVE-2026-13016 · unauthenticated SQL injection · CVSS 4.0 9.3

#### CVE-2026-86859 · authorization bypass · CVSS 4.0 8.7

#### CVE-2026-86860 · unauthenticated missing authorization/data disclosure · CVSS 4.0 9.3

**Alternative release-family floors:** Yokohama Patch 13 Hot Fix 5a; Zurich Patch 10 Hot Fix 3b; Zurich Patch 10 Hot Fix 4a W32; Zurich Patch 11 Hot Fix 3; Australia Patch 2 Hot Fix 4b W32; Australia Patch 4 Hot Fix 3; Australia Patch 5\. Use only the floor that matches the deployed family.

**Dates for all five:** First tracked September 28; first newsletter appearance not established; last material update September 24; no CISA federal date; Newsletter Drop Date October 26, 2026.

[ServiceNow KB3159623](https://support.servicenow.com/kb?id=kb%5Farticle%5Fview&sysparm%5Farticle=KB3159623&ref=clinicalcyber.com) · [CNA record 86857](https://cveawg.mitre.org/api/cve/CVE-2026-86857?ref=clinicalcyber.com) · [CNA record 86858](https://cveawg.mitre.org/api/cve/CVE-2026-86858?ref=clinicalcyber.com) · [CNA record 13016](https://cveawg.mitre.org/api/cve/CVE-2026-13016?ref=clinicalcyber.com) · [CNA record 86859](https://cveawg.mitre.org/api/cve/CVE-2026-86859?ref=clinicalcyber.com) · [CNA record 86860](https://cveawg.mitre.org/api/cve/CVE-2026-86860?ref=clinicalcyber.com)

## Sources

Open the complete primary-source index and verification note 

**Verification note:** Sources were checked through October 5, 2026, at 12:06 a.m. EDT. Post-cutoff checking confirmed dated facts only; it did not add later events to the September 28–October 4 reporting window.

### Cybersecurity advisories and CVE continuity

- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?ref=clinicalcyber.com) — catalog version released October 4.
- [Cisco Catalyst SD-WAN Manager CVE-2026-76504 advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU?ref=clinicalcyber.com) — September 30; updated October 2.
- [Fortinet FortiMail advisory FG-IR-26-175](https://fortiguard.fortinet.com/psirt/FG-IR-26-175?ref=clinicalcyber.com) — October 1.
- [Apple iOS/iPadOS CVE-2026-86950 advisory](https://support.apple.com/en-us/149226?ref=clinicalcyber.com), [macOS Tahoe advisory](https://support.apple.com/en-us/149228?ref=clinicalcyber.com), and [macOS Sequoia advisory](https://support.apple.com/en-us/149229?ref=clinicalcyber.com) — fixes released September 28.
- [CISA CVE-2026-102489 record](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field%5Fcve=CVE-2026-102489&ref=clinicalcyber.com), [CISA CVE-2026-102490 record](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field%5Fcve=CVE-2026-102490&ref=clinicalcyber.com), and [Zammad releases](https://zammad.com/en/product/releases?ref=clinicalcyber.com).
- [Citrix CTX697174 for CVE-2026-88779](https://support.citrix.com/external/article/CTX697174?ref=clinicalcyber.com) — October 3.
- [CISA medical advisory for NextGen Mirth Connect](https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-01?ref=clinicalcyber.com).
- [ConnectWise ScreenConnect bulletin](https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin?ref=clinicalcyber.com); [Cisco FMC advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2?ref=clinicalcyber.com); [N-able N-central hotfix notice](https://status.n-able.com/2026/09/06/n-central-2026-3-hotfix-4-cve-2026-86218/?ref=clinicalcyber.com).
- [Citrix CTX696939](https://support.citrix.com/external/article/CTX696939/netscaler-adc-and-netscaler-gateway-secu.html?ref=clinicalcyber.com); [GitLab patch release](https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/?ref=clinicalcyber.com); [JFrog security advisories](https://docs.jfrog.com/releases/docs/jfrog-security-advisories?ref=clinicalcyber.com).
- [Cisco Secure Email Gateway advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX?ref=clinicalcyber.com); [Cisco ISE advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5?ref=clinicalcyber.com); [Acronis SEC-10986](https://security-advisory.acronis.com/advisories/SEC-10986?ref=clinicalcyber.com); [Google Pixel bulletin](https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01?ref=clinicalcyber.com).
- [Ubuntu CVE-2025-39964](https://ubuntu.com/security/CVE-2025-39964?ref=clinicalcyber.com), [Debian CVE-2025-39964](https://security-tracker.debian.org/tracker/CVE-2025-39964?ref=clinicalcyber.com), [Red Hat CVE-2025-39964](https://access.redhat.com/security/cve/cve-2025-39964?ref=clinicalcyber.com), and [SUSE CVE-2025-39964](https://www.suse.com/security/cve/CVE-2025-39964.html?ref=clinicalcyber.com).
- [Ubuntu CVE-2026-53266](https://ubuntu.com/security/CVE-2026-53266?ref=clinicalcyber.com), [Debian CVE-2026-53266](https://security-tracker.debian.org/tracker/CVE-2026-53266?ref=clinicalcyber.com), [Red Hat CVE-2026-53266](https://access.redhat.com/security/cve/cve-2026-53266?ref=clinicalcyber.com), and [SUSE CVE-2026-53266](https://www.suse.com/security/cve/CVE-2026-53266.html?ref=clinicalcyber.com).
- [Ubuntu CVE-2025-39682](https://ubuntu.com/security/CVE-2025-39682?ref=clinicalcyber.com), [Debian CVE-2025-39682](https://security-tracker.debian.org/tracker/CVE-2025-39682?ref=clinicalcyber.com), [Red Hat CVE-2025-39682](https://access.redhat.com/security/cve/cve-2025-39682?ref=clinicalcyber.com), and [SUSE CVE-2025-39682](https://www.suse.com/security/cve/CVE-2025-39682.html?ref=clinicalcyber.com).
- [Zyxel GS1900 advisory](https://community.zyxel.com/en/discussion/33340/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches?ref=clinicalcyber.com); [Check Point advisory](https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/?ref=clinicalcyber.com); [Arista advisory 0183](https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183?ref=clinicalcyber.com).
- [F5 K000162605](https://my.f5.com/manage/s/article/K000162605?ref=clinicalcyber.com); [WSO2-2026-5328](https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5328/?ref=clinicalcyber.com); [Adobe APSB26-92](https://helpx.adobe.com/security/products/magento/apsb26-92.html?ref=clinicalcyber.com); [MikroTik September vulnerability page](https://mikrotik.com/supportsec/september-2026-vulnerability/?ref=clinicalcyber.com).
- [Microsoft CVE-2026-65660](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660?ref=clinicalcyber.com); [WordPress GHSA-7hp8-65ch-5whp](https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp?ref=clinicalcyber.com); [Citrix CVE-2026-88771–88778 bulletin](https://community.citrix.com/techzone-blogs/110%5Fsecurity-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778?ref=clinicalcyber.com).
- [ServiceNow KB3159623](https://support.servicenow.com/kb?id=kb%5Farticle%5Fview&sysparm%5Farticle=KB3159623&ref=clinicalcyber.com) and CNA records for [CVE-2026-86857](https://cveawg.mitre.org/api/cve/CVE-2026-86857?ref=clinicalcyber.com), [CVE-2026-86858](https://cveawg.mitre.org/api/cve/CVE-2026-86858?ref=clinicalcyber.com), [CVE-2026-13016](https://cveawg.mitre.org/api/cve/CVE-2026-13016?ref=clinicalcyber.com), [CVE-2026-86859](https://cveawg.mitre.org/api/cve/CVE-2026-86859?ref=clinicalcyber.com), and [CVE-2026-86860](https://cveawg.mitre.org/api/cve/CVE-2026-86860?ref=clinicalcyber.com).

### Healthcare incident sources

- [iRhythm October 2 incident update](https://www.globenewswire.com/news-release/2026/10/02/3374047/0/en/irhythm-provides-update-on-cybersecurity-incident-previously-disclosed-in-june-2026.html?ref=clinicalcyber.com).
- [Luminis Health cybersecurity incident update](https://www.luminishealth.org/en/cybersecurity-incident-update?language%5Fcontent%5Fentity=en&ref=clinicalcyber.com) — September 29 restoration status.
- [IU Health / AME Group incident release](https://iuhealth.org/for-media/press-releases/iu-health-reports-vendor-security-incident-in-southern-indiana?ref=clinicalcyber.com) — September 29.

### AI, regulatory and privacy sources

- [California governor’s September 30 signing announcement](https://www.gov.ca.gov/2026/09/30/californias-nation-leading-ai-framework-just-got-stronger-governor-newsom-signs-more-first-in-the-nation-worker-protections-and-more/?ref=clinicalcyber.com); [AB 1979 chapter status — Chapter 854](https://leginfo.legislature.ca.gov/faces/billStatusClient.xhtml?bill%5Fid=202520260AB1979&ref=clinicalcyber.com); [SB 503 chapter status — Chapter 857](https://leginfo.legislature.ca.gov/faces/billStatusClient.xhtml?bill%5Fid=202520260SB503&ref=clinicalcyber.com); [California Constitution, Article IV, section 8(c)(1)](https://leginfo.legislature.ca.gov/faces/codes%5FdisplaySection.xhtml?lawCode=CONS§ionNum=SEC.+8.&article=IV&ref=clinicalcyber.com).
- [Congress.gov S. 3315 actions](https://www.congress.gov/bill/119th-congress/senate-bill/3315/all-actions?ref=clinicalcyber.com) and [GovInfo engrossed bill](https://www.govinfo.gov/app/details/BILLS-119s3315es?ref=clinicalcyber.com).
- [FDA generative-AI medical-device discussion paper](https://www.fda.gov/medical-devices/digital-health-center-excellence/considerations-regulation-generative-ai-enabled-medical-devices-discussion-paper-and-request?ref=clinicalcyber.com).
- [FDA robotically assisted surgical-device draft guidance](https://www.fda.gov/regulatory-information/search-fda-guidance-documents/robotically-assisted-surgical-devices-premarket-submissions?ref=clinicalcyber.com) and [Federal Register notice](https://www.federalregister.gov/documents/2026/09/25/2026-19704/robotically-assisted-surgical-devices-premarket-submissions-draft-guidance-for-industry-and-food-and?ref=clinicalcyber.com).
- [FDA robotic-device benefit-risk workshop](https://www.fda.gov/news-events/fda-meetings-conferences-and-workshops/public-workshop-evaluating-benefit-risk-robotic-medical-devices-autonomous-or-remote-teleoperation?ref=clinicalcyber.com).
- [CISA CIRCIA rulemaking](https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/cyber-incident-reporting-critical-infrastructure-act-2022-circia?ref=clinicalcyber.com); [HHS HIPAA Security Rule NPRM](https://www.hhs.gov/hipaa/for-professionals/security/hipaa-security-rule-nprm/index.html?ref=clinicalcyber.com); [California CCPA rulemaking updates](https://cppa.ca.gov/regulations/ccpa%5Fupdates.html?ref=clinicalcyber.com).

### Clinical engineering and device sources

- [FDA CDRH new notices index](https://www.fda.gov/medical-devices/medical-devices-news-and-events/cdrh-new-news-and-updates?ref=clinicalcyber.com) — checked for the reporting window.
- [FDA Draeger VentStar Resus Neo recall](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/breathing-circuit-recall-draeger-removes-ventstar-resus-neo-hoses?ref=clinicalcyber.com) and [event 99787](https://www.accessdata.fda.gov/scripts/ires/index.cfm?Event=99787&ref=clinicalcyber.com).
- [FDA AVID/Namic correction](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/convenience-kit-correction-avid-medical-issues-correction-kits-containing-medline-namic-star-handle?ref=clinicalcyber.com) and [event 99339](https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfres/res.cfm?start%5Fsearch=1&event%5Fid=99339&ref=clinicalcyber.com).
- [FDA BMC Luna G3 recall](https://www.fda.gov/safety/recalls-market-withdrawals-safety-alerts/bmc-medical-co-ltd-recalls-luna-g3-apap-model-lg3600-firmware-g3-20076-due-firmware-defect?ref=clinicalcyber.com).
- [FDA BD Alaris update](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/update-alert-infusion-set-performance-issue-bd?ref=clinicalcyber.com) and [classified recall record](https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfres/res.cfm?id=221227&ref=clinicalcyber.com).
- [FDA Abiomed Impella alert](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/early-alert-heart-pump-controller-purge-cassette-issue-abiomed?ref=clinicalcyber.com) and [event 99671](https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfres/res.cfm?start%5Fsearch=1&event%5Fid=99671&ref=clinicalcyber.com).
- [FDA AVID/Halyard event 99758](https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfres/res.cfm?start%5Fsearch=1&event%5Fid=99758&ref=clinicalcyber.com) and [FDA sodium chloride ampule recall](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/sodium-chloride-flush-recall-spectra-medical-removes-sodium-chloride-injection-usp-ampules?ref=clinicalcyber.com).
- [FDA CooperSurgical INCA alert](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/early-alert-ventilator-issue-coopersurgical?ref=clinicalcyber.com) and [event 99643](https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfres/res.cfm?start%5Fsearch=1&event%5Fid=99643&ref=clinicalcyber.com).
- [FDA Boston Scientific Imager II recall](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/angiographic-catheter-recall-boston-scientific-removes-imager-ii-angiographic-catheters?ref=clinicalcyber.com) and [event 99687](https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfres/res.cfm?start%5Fsearch=1&event%5Fid=99687&ref=clinicalcyber.com).
- [FDA Boston Scientific ENROUTE removal](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/percutaneous-catheter-recall-boston-scientific-removes-enroute-transcarotid-neuroprotection-system?ref=clinicalcyber.com) and [event 99454](https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfres/res.cfm?start%5Fsearch=1&event%5Fid=99454&ref=clinicalcyber.com).