CISA added at least 11 vulnerabilities to its Known Exploited Vulnerabilities catalog between 21 and 27 September 2026, five of them carrying a CVSS score of 9.0 or higher, and all eleven confirmed under active exploitation at the time of addition. At least three of the week’s flaws had public proof-of-concept detail circulating before vendors shipped a fix. Patch the two unauthenticated Citrix NetScaler remote code execution flaws first: they hit every default configuration, were exploited before any patch existed, and sit on internet-facing VPN and application-delivery appliances that are the most common initial access point in this report’s history. The pattern this week is unauthenticated, pre-fix exploitation against edge infrastructure, from network appliances down to a 1990s-era switch line still running in production.
Which vulnerabilities should you patch first this week?
CVE-2026-88771: Citrix NetScaler ADC and Gateway remote code execution
What it is: CVE-2026-88771 is an improper input validation vulnerability in Citrix NetScaler ADC and NetScaler Gateway that lets an unauthenticated attacker run arbitrary commands on the appliance’s default configuration, with no login or existing session required.
Affected products and versions: NetScaler ADC and Gateway 14.1 before build 14.1-73.37, and 13.1 before build 13.1-64.23, including the 14.1-FIPS and 13.1-FIPS/NDcPP variants before their respective corresponding builds.
Severity: CVSS 9.5 Critical, CVSS 4.0, assigned by Citrix in security bulletin CTX697096. EPSS not available.
Exploitation status: Confirmed in the wild. Citrix and independent researchers at watchTowr confirmed active exploitation before a patch existed. Added to CISA KEV on 27 September 2026. Federal remediation due date: see KEV entry.
Patch status: Fixed in 14.1-73.37 and 13.1-64.23, released 27 September 2026 alongside the disclosure.
What to do: Upgrade to the fixed builds immediately regardless of maintenance windows, since exploitation predates the patch. Audit NetScaler instances configured as SSL VPN, ICA proxy, CVPN, RDP proxy, or AAA virtual servers for signs of compromise before and after patching. Treat any NetScaler appliance patched after 27 September as presumed compromised until forensics say otherwise.
CVE-2026-88772: Citrix NetScaler ADC and Gateway memory overflow
What it is: CVE-2026-88772 is a memory overflow vulnerability in Citrix NetScaler ADC and Gateway that leads to remote code execution or denial of service when DTLS is enabled, which is the default configuration for VPN virtual servers.
Affected products and versions: NetScaler ADC and Gateway 14.1 before build 14.1-73.37, and 13.1 before build 13.1-64.23, including the FIPS and NDcPP variants, the same version boundaries as CVE-2026-88771.
Severity: CVSS 9.5 Critical, CVSS 4.0, assigned by Citrix. EPSS not available.
Exploitation status: Confirmed in the wild, disclosed alongside CVE-2026-88771 as a companion zero-day exploited before any fix existed.
Patch status: Fixed in the same 14.1-73.37 and 13.1-64.23 builds released 27 September 2026.
What to do: Apply the single NetScaler firmware update that resolves both CVE-2026-88771 and CVE-2026-88772 in one pass rather than treating them as separate patch cycles. Disable DTLS on VPN virtual servers as an interim mitigation only if the fixed build cannot be deployed immediately. Confirm the same forensic review covers both CVE IDs, since both were exploited during the same zero-day window.
CVE-2026-94127: F5 BIG-IP Access Policy Manager unauthenticated remote code execution
What it is: CVE-2026-94127 is a heap-based buffer overflow in F5 BIG-IP Access Policy Manager that allows an unauthenticated attacker to achieve remote code execution by sending crafted traffic to a virtual server with an access policy and OAuth authorization server profile configured.
Affected products and versions: BIG-IP APM 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0, per CERT-EU’s advisory; F5 shipped hotfixes as 21.1.0.2.0.30.22-ENG, 17.5.1.9.0.160.12-ENG, and 17.1.3.5.0.41.14-ENG.
Severity: CVSS 9.8 Critical, confirmed by both CERT-EU’s security advisory and independent analysis from Rapid7. EPSS not available.
Exploitation status: Confirmed in the wild as a zero-day, exploited before F5’s hotfix was available. Added to CISA KEV on 22 September 2026. Federal remediation due date: 25 September 2026.
Patch status: Hotfixes released 22 September 2026 for the three affected branches listed above.
What to do: Apply the branch-specific hotfix immediately on any BIG-IP instance with an APM access policy and OAuth profile configured on a virtual server. If an immediate hotfix is not possible, remove or disable the OAuth authorization server profile from internet-facing virtual servers as a temporary mitigation. Review APM logs for anomalous traffic patterns predating the 22 September disclosure, since exploitation began before the fix existed.
CVE-2026-5430: WSO2 API Manager and related products authentication bypass
What it is: CVE-2026-5430 is a JWT authentication bypass in WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway that lets an attacker forge a token signed with an unsupported algorithm to bypass authentication and gain unauthorized, potentially administrative, access.
Affected products and versions: WSO2 API Control Plane 4.5.0 and 4.6.0; API Manager 4.1.0 through 4.6.0; Traffic Manager 4.5.0 and 4.6.0; Universal Gateway 4.5.0 and 4.6.0.
Severity: CVSS 10.0 for multi-tenant deployments and CVSS 9.8 for single-tenant deployments, both assigned by WSO2 in its own advisory (WSO2-2026-5328). The Hacker News, citing CISA’s KEV notice, reported the flaw at CVSS 9.8; both figures are recorded here since the vendor and press coverage differ on which deployment configuration each score applies to.
Exploitation status: Confirmed in the wild. Added to CISA KEV on 24 September 2026. Federal remediation due date: 27 September 2026.
Patch status: Fixed via subscription updates, including API Manager 4.6.0 Update 21 and 4.5.0 Update 57; open source deployments should apply the public fix or migrate to an unaffected version.
What to do: Apply the vendor update matching your deployment tier immediately, since this flaw grants administrative-level access without valid credentials. Rotate any API keys, service credentials, or downstream secrets accessible through the API Manager control plane, since a bypass at this layer can expose everything behind it. Audit JWT validation configuration across any custom API gateway logic to confirm unsupported algorithms are explicitly rejected rather than silently accepted.
CVE-2026-7273: Zyxel GS1900 series switches stack-based buffer overflow
What it is: CVE-2026-7273 is a stack-based buffer overflow in the CGI program of Zyxel GS1900 series switch firmware that allows a LAN-based, unauthenticated attacker to execute operating system commands through a crafted HTTP request.
Affected products and versions: GS1900-8, GS1900-8HP, GS1900-10HP, GS1900-16, GS1900-24, GS1900-24E, GS1900-24EP, GS1900-24HPv2, GS1900-48, and GS1900-48HPv2, all on firmware 2.90 and earlier per model-specific build numbers in Zyxel’s advisory.
Severity: CVSS 8.8 per SecurityAffairs’ reporting of the CISA alert. EPSS not available.
Exploitation status: Confirmed in the wild. A Chinese-speaking threat actor compromised 996 GS1900 switches across 48 countries in an operation that began around 17 August 2026, exfiltrating configuration files, network information, and hashed root credentials; 564 of the compromised devices still had factory-default credentials active. Added to CISA KEV on 21 September 2026. Federal remediation due date: 24 September 2026.
Patch status: Zyxel released patched firmware in June 2026, three months before this exploitation campaign became public, meaning the compromised devices were running firmware Zyxel had already fixed.
What to do: Apply Zyxel’s June 2026 firmware update immediately if it has not already been deployed. Change all default and factory credentials on network switches as a baseline control, since 564 of 996 compromised devices in this campaign still used default logins. Treat any GS1900 switch that has been internet- or LAN-exposed with default credentials since June as presumed compromised and rotate all downstream secrets it had access to.
New hacking technique: autonomous AI agent chain used to breach 27 e-commerce companies
What researchers demonstrated: Threat intelligence firm Gambit documented, and BleepingComputer independently corroborated on 23 September 2026, a campaign in which a single operator chained three open-source AI agent frameworks, Strix for reconnaissance, Cairn for autonomous exploitation, and Hermes for orchestration and post-exploitation decisions, to breach at least 27 companies and plant card skimmers on 119 or more websites between July and 22 September 2026.
How it works:
- A human operator gave brief, high-level objectives to Hermes, an orchestration layer built on Claude Opus 4.6 with a persona and skill set tuned for offensive operations.
- Strix scanned candidate targets, prioritizing sites running custom e-commerce software identified through traffic-ranking services.
- Cairn autonomously exploited identified weaknesses to obtain shell or administrative access without further human direction.
- Hermes orchestrated post-exploitation steps, including deploying payment card skimmers and, per skill instructions Gambit recovered, wiping source-field data in batches after exfiltration to disrupt the victim’s own recovery.
- The operator repeated this loop across at least 105 attack waves at an average cost of roughly 25 dollars per targeted company.
What to do: Treat traffic-ranking visibility and custom e-commerce software stacks as attacker reconnaissance signals, not just competitive intelligence, since this campaign explicitly prioritized targets that way. Monitor for the specific secondary damage pattern this technique introduces, batch data wiping after exfiltration, as a distinct incident response scenario separate from card theft itself. Validate that externally reachable checkout and payment flows are tested against autonomous, not just manual, exploitation attempts, since the entire point of this campaign was that human-paced defenses could not keep up with agent-paced attacks.
CISA KEV additions, 21 to 27 Sep 2026
| CVE | Product | CVSS | Date added to KEV | Federal due date |
|---|---|---|---|---|
| CVE-2026-7273 | Zyxel GS1900 series switches | 8.8 | 21 Sep 2026 | 24 Sep 2026 |
| CVE-2026-85102 | Check Point multiple products (certificate validation) | Not disclosed in available sources | 22 Sep 2026 | 25 Sep 2026 |
| CVE-2026-93616 | Check Point multiple products (path traversal) | Not disclosed in available sources | 22 Sep 2026 | 25 Sep 2026 |
| CVE-2026-93952 | Arista VeloCloud Orchestrator | Not disclosed in available sources | 22 Sep 2026 | 25 Sep 2026 |
| CVE-2026-94127 | F5 BIG-IP APM | 9.8 | 22 Sep 2026 | 25 Sep 2026 |
| CVE-2026-5430 | WSO2 API Manager and related products | 10.0 / 9.8 (see CVE item) | 24 Sep 2026 | 27 Sep 2026 |
| CVE-2026-71362 | Adobe Commerce / Magento Open Source | 9.1 | 24 Sep 2026 | 27 Sep 2026 |
| CVE-2026-65660 | Microsoft SharePoint Server | 8.8 | 25 Sep 2026 | See KEV entry |
| CVE-2026-67279 | MikroTik RouterOS | 6.9 | 25 Sep 2026 | See KEV entry |
| CVE-2026-88771 | Citrix NetScaler ADC / Gateway | 9.5 | 27 Sep 2026 | See KEV entry |
| CVE-2026-88772 | Citrix NetScaler ADC / Gateway | 9.5 | 27 Sep 2026 | See KEV entry |
No KEV additions were found for 23 or 26 September 2026 after a dedicated search for each date.
Related reading
- Weekly Report: New Hacking Techniques and Critical CVEs, 07 Sep to 13 Sep 2026: last edition’s Cisco FMC and Citrix NetScaler entries, a preview of this week’s return of both product lines to the KEV catalog.
- Continuous, automated pentesting: the testing cadence gap this week’s zero-day exploitation against Citrix and F5 illustrates, since both were exploited before any patch existed for defenders to apply.
- The Great AI Divide: the widening gap between attacker speed and defender testing cadence, visible this week in the autonomous AI agent campaign against 27 e-commerce companies.
Frequently asked questions
Which CVEs were actively exploited this week?
All eleven CVEs added to CISA’s KEV catalog between 21 and 27 September 2026 were confirmed under active exploitation, spanning Citrix NetScaler, F5 BIG-IP APM, WSO2 API Manager, Adobe Commerce, Microsoft SharePoint, MikroTik RouterOS, Zyxel switches, Check Point products, and Arista VeloCloud Orchestrator.
What is the most critical CVE this week?
CVE-2026-88771 and CVE-2026-88772 in Citrix NetScaler ADC and Gateway rank as the most urgent, both CVSS 9.5, unauthenticated, remote code execution capable, and exploited in the wild before Citrix released a fix on 27 September 2026.
Is CVE-2026-94127 being exploited?
Yes. CISA added CVE-2026-94127, a heap-based buffer overflow in F5 BIG-IP Access Policy Manager, to its KEV catalog on 22 September 2026 after confirming active exploitation as a zero-day, before F5’s hotfix existed.
How do I fix CVE-2026-5430?
Apply WSO2’s vendor update for your deployment tier, including API Manager 4.6.0 Update 21 or 4.5.0 Update 57 for subscription customers, or the public open source fix, and rotate any credentials the API Manager control plane could reach, since the flaw allows JWT-based authentication bypass to administrative access.
How many vulnerabilities did CISA add to KEV this week?
CISA added at least 11 vulnerabilities to its Known Exploited Vulnerabilities catalog during the week of 21 to 27 September 2026, across five separate alerts dated 21, 22, 24, 25, and 27 September, with no additions found for 23 or 26 September.
How should security teams prioritize this week’s patches?
Rank by confirmed exploitation status first, external reachability second, and CVSS or EPSS third. This week that puts the unauthenticated, pre-patch-exploited Citrix and F5 flaws ahead of the WSO2 bypass, which requires a specific JWT validation path, even though WSO2’s own CVSS score is the highest of the week.
