VulnOps
2026-09-15CISA added ten known exploited vulnerabilities to its catalog today, significantly expanding the list of threats requiring immediate prioritization in remediation workflows. These additions include a critical SQL injection vulnerability in Cisco Secure Email Gateway, underscoring active exploitation risks in widely-deployed email security infrastructure.
- →CISA KEV Catalog Expanded with Ten New Entries: Practitioners must immediately review these additions to update patch prioritization matrices and compliance timelines, as KEV designation indicates active exploitation in the wild.
- →Cisco Secure Email Gateway SQL Injection (CVE-2026-76461) Added to KEV Catalog: Email security infrastructure is a high-value target; this SQL injection vulnerability requires urgent assessment across deployed instances and expedited patching to prevent data exfiltration.
- →Increased KEV Catalog Activity Signals Rising Exploitation Pressure: The volume of new catalog additions suggests heightened threat actor activity, requiring vulnops teams to accelerate remediation cycles and strengthen vulnerability detection monitoring.
Review CISA's updated KEV catalog immediately, prioritize Cisco Secure Email Gateway patching, and adjust your remediation SLAs to reflect the accelerated exploitation timeline.
CVE-2026-8452 Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability [...] CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability CVE-2015-5287 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability CVE-2019-1068 Microsoft SQL Server Remote Code Execution Vulnerability CVE-2021-23758 Ajax.NET Professional Deserialization of Untrusted Data Vulnerability CVE-2022-0995 Linux Kernel Out-of-Bounds Write
Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
Release Date CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability CVE-2026-81963 Microsoft Windows Link Following Vulnerability CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability CVE-2026-86218 N-able N-central Static Code Injection Vulnerability [...] While BOD