Newsdesk
Engineering
Data & AI
Industries
Enterprise Systems
Go-to-Market
Longform
DesignIndiaAll stories

Security Weekly Digest

15 September 2026

12 vulnerabilities added to CISA's exploited-in-the-wild catalog this week.

One week of Security Weekly Digest, 7 stories, as published.

Exploited CVEs

CVE-2026-76461: Cisco Secure Email Gateway

Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.

Why it matters — Confirmed exploited in the wild. CVSS 9.8 (CRITICAL). CISA remediation deadline 17 Sep 2026 — 2 days out.

CISA KEV · 15 September 2026 · Read the original →

Exploited CVEs

CVE-2026-84869: ConnectWise ScreenConnect

ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation.

Why it matters — Confirmed exploited in the wild. CVSS 9.9 (CRITICAL). CISA remediation deadline 14 Sep 2026 — already passed.

CISA KEV · 15 September 2026 · Read the original →

Exploited CVEs

CVE-2026-85706: GitLab Community Edition and Enterprise Edition

GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.

Why it matters — Confirmed exploited in the wild. CVSS 10.0 (CRITICAL). CISA remediation deadline 14 Sep 2026 — already passed.

CISA KEV · 15 September 2026 · Read the original →

Exploited CVEs

CVE-2026-86060: MikroTik RouterOS

MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation.

Why it matters — Confirmed exploited in the wild. CVSS 9.2 (CRITICAL). CISA remediation deadline 13 Sep 2026 — already passed.

CISA KEV · 15 September 2026 · Read the original →

Exploited CVEs

CVE-2026-19490: Citrix NetScaler

Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication.

Why it matters — Confirmed exploited in the wild. CVSS 9.3 (CRITICAL). CISA remediation deadline 12 Sep 2026 — already passed.

CISA KEV · 15 September 2026 · Read the original →

Exploited CVEs

CVE-2026-20079: Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.

Why it matters — Confirmed exploited in the wild. CVSS 10.0 (CRITICAL). CISA remediation deadline 12 Sep 2026 — already passed.

CISA KEV · 15 September 2026 · Read the original →

Exploited CVEs

CVE-2026-75650: Adobe Commerce and Magento

Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.

Why it matters — Confirmed exploited in the wild. CVSS 10.0 (CRITICAL). CISA remediation deadline 11 Sep 2026 — already passed.

CISA KEV · 15 September 2026 · Read the original →

Go ahead and pre-approve the emergency change requests.

7 stories, every Tuesday

Published here every week. Follow by RSS to get it as it lands.

← Previous issue Next issue →