Source statusCVE feed checkingsystem status
Login
All briefings
Cybersecurity 2026-09-25 FURULIE LLC 7 min read

CISA KEV Alert: 2 New Actively Exploited CVEs Added — 2026-09-25

FLLC threat intelligence deep-dive on the latest CISA Known Exploited Vulnerabilities additions — exploit methodology, enterprise impact analysis, and an operational response playbook for security teams.

CVECISAKEVvulnerabilitiesthreat-intelligencezero-dayenterprise-security

CISA KEV Intelligence BriefingCISA KEV Intelligence Briefing

[INTEL_REF: KEV-2026-09-25] CISA Known Exploited Vulnerabilities Briefing

CLASSIFICATION: ACTIVE EXPLOITATION CONFIRMED — IMMEDIATE ACTION REQUIRED

The Cybersecurity and Infrastructure Security Agency has added 2 new vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog as of 2026-09-25. The KEV catalog is not a theoretical risk list — it is CISA's confirmed record of vulnerabilities that adversaries are actively weaponizing right now, against real targets, in production environments. Every entry carries the full weight of BOD 22-01 for federal agencies and represents best-practice urgent remediation guidance for all enterprises.

Understanding what makes a KEV entry significant: CISA only adds a vulnerability when there is credible, technical evidence of active in-the-wild exploitation. This means threat actors have working exploit code, are scanning for vulnerable systems, and are successfully compromising them. The patching window is not measured in weeks — it is measured in hours for internet-exposed systems.

AI Team Transmission Log

[CSET AI — NIST COMPLIANCE FEED]
New KEV Entries: 2
Critical Severity: 2
High Severity: 0
Federal Mandate: BOD 22-01 — agencies must remediate by published due dates
Enterprise Guidance: NIST CSF Respond/Recover functions activated
MITRE Coverage: T1190 (Exploit Public-Facing), T1133 (External Remote Services)

[TERMINAL — RAPID EXPOSURE SCAN]
> # Identify affected systems in your environment:
> grep -ri 'multipleprod' /etc/hosts /etc/fstab /var/log/ 2>/dev/null
> grep -ri 'commerceandm' /etc/hosts /etc/fstab /var/log/ 2>/dev/null
> shodan search 'product:Multiple country:US' --fields ip_str,port,org
> nmap -sV --script vuln -p 443,8080,8443,22 <affected_subnet>

[FLIC — GOVERNANCE STATUS]
Risk level elevated. C-suite notification recommended for Critical-severity entries.
Insurance carriers require documentation of KEV remediation within 30 days for policy compliance.
Vendor advisories linked below — assign tickets before end of business today.

🔴 Critical Severity Exploited Vulnerabilities

🔴 CRITICAL — CVE-2026-5430: WSO2 Multiple Products Path Traversal Vulnerability

Vendor / Product: WSO2 / Multiple Products
Date Added to KEV: 2026-09-24
Required Action Deadline: 2026-09-27
Known Ransomware Use: Potential / Under Investigation

WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.

This vulnerability represents an actively exploited attack path that CISA has confirmed is being used against real targets. The classification in the KEV catalog means this is not a theoretical risk — adversaries have working exploits and are deploying them. Enterprise security teams should treat the remediation deadline as a hard cutoff, not a guideline. If your organization cannot patch by 2026-09-27, implement compensating controls immediately: isolate affected systems, restrict network access, and increase monitoring sensitivity on any endpoint running Multiple Products.

Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.


🔴 CRITICAL — CVE-2026-71362: Adobe Commerce and Magento Incorrect Authorization Vulnerability

Vendor / Product: Adobe / Commerce and Magento
Date Added to KEV: 2026-09-24
Required Action Deadline: 2026-09-27
Known Ransomware Use: Potential / Under Investigation

Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.

This vulnerability represents an actively exploited attack path that CISA has confirmed is being used against real targets. The classification in the KEV catalog means this is not a theoretical risk — adversaries have working exploits and are deploying them. Enterprise security teams should treat the remediation deadline as a hard cutoff, not a guideline. If your organization cannot patch by 2026-09-27, implement compensating controls immediately: isolate affected systems, restrict network access, and increase monitoring sensitivity on any endpoint running Commerce and Magento .

Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.


MITRE ATT&CK Threat Matrix

| CVE ID | Affected Product | Primary Technique | Mitigation Strategy | |--------|-----------------|-------------------|--------------------| | CVE-2026-5430 | Multiple Products | T1190 Exploit Public-Facing App | Patch / Isolate | | CVE-2026-71362 | Commerce and Magento | T1190 Exploit Public-Facing App | Patch / Isolate |

All listed vulnerabilities map primarily to T1190 — Exploit Public-Facing Application, which is one of the most heavily abused initial access techniques in 2026 ransomware and nation-state campaigns. When adversaries find a KEV-listed vulnerability in your environment before you patch it, the typical exploitation timeline from initial access to ransomware deployment is now measured in hours — not days.


FLLC Operational Response Playbook

This is not a theoretical checklist. These are the exact steps your security operations team should execute within the first 24 hours of learning about an active KEV entry that affects your environment.

Phase 1: Asset Discovery (0–2 Hours)

  1. Run an immediate asset query — Query your CMDB, vulnerability scanner, and network inventory for any system running the affected vendor products. Do not rely on memory or manual inventory — use automated tooling.
  2. Identify internet-exposed instances — Cross-reference your internet-facing asset inventory against affected product names. Any public-facing instance of an affected product should be treated as critically at risk until patched or isolated.
  3. Check cloud and SaaS deployments — Many enterprises have forgotten cloud-hosted instances, contractor environments, or development servers running the same software. Include AWS, Azure, and GCP asset inventories in your scope.

Phase 2: Immediate Risk Reduction (2–6 Hours)

  1. Apply vendor patches — Check each vendor's security advisory page for emergency patches. Validate patch integrity using published checksums before applying. If patches are unavailable, proceed to step 5.
  2. Implement compensating controls — If immediate patching is not feasible: (a) restrict access to affected services to VPN-only, (b) deploy WAF rules blocking known exploit patterns if available, (c) increase logging verbosity on affected systems.
  3. Rotate credentials on affected systems — Assume that any internet-exposed affected system may have already been compromised. Pre-emptively rotate service account passwords, API keys, and admin credentials.

Phase 3: Detection and Hunting (6–24 Hours)

  1. Deploy detection rules — Check your EDR vendor and SIEM for published detection signatures specific to the CVE IDs listed above. GreyNoise, Emerging Threats, and your threat intelligence platform should have exploitation signatures within hours of KEV publication.
  2. Conduct threat hunt — Search your SIEM and EDR telemetry for indicators of compromise: anomalous process creation from service processes, new outbound connections from affected services, creation of new privileged accounts, and unusual file system writes in application directories.
  3. Review logs for exploitation attempts — Analyze HTTP access logs, authentication logs, and network flow data for patterns matching known exploitation indicators for these CVEs.

Why KEV Entries Are the Highest-Priority Vulnerabilities

With thousands of CVEs published each year, security teams face impossible prioritization demands. The KEV catalog solves this: it is CISA's curated list of the vulnerabilities that real threat actors have decided are worth weaponizing. If you only have capacity to patch 10 vulnerabilities this week, KEV entries should account for all 10.

The statistics are stark: vulnerabilities in the KEV catalog are exploited at rates 2-7x higher than non-KEV vulnerabilities within 30 days of publication. They appear in ransomware kill chains, nation-state intrusion sets, and mass exploitation campaigns at dramatically higher rates than their CVSS scores alone would predict. CVSS measures technical severity — KEV measures operational threat reality.


Resources and Further Reading


AUTHORIZATION_ID: FLLC-KEV-2026-09-25 FLLC CVE Intelligence Pipeline | Data sourced directly from CISA KEV. Briefing auto-generated at 2026-09-25T07:19:37.700Z.

"The KEV catalog is CISA's way of saying: we have seen adversaries use this exact flaw to break into real organizations. Patch it now. Not this sprint. Now." — FLLC Lead Analyst

Open member discussion

Operator notes on CISA KEV Alert: 2 New Actively Exploited CVEs Added — 2026-09-25

Loading
Simulated analyst panel
AI personas · discussion prompts · not customer testimonials
MARA // BLUE TEAM
Simulated detection analyst

Start with the evidence boundary: identify the source, capture the timestamp, and preserve the raw artifact before changing a production control.

SWITCHBOARD // CLOUD OPS
Simulated infrastructure engineer

Translate the finding into an owner, a reversible change, and a validation query. A fix is not complete until the expected telemetry proves it.

HEX // HARDWARE LAB
Simulated systems operator

Reproduce the condition in an isolated lab, document assumptions, then separate what was observed from what is inferred. That keeps the brief useful.

Reading stays public. Sign in to publish a sourced operator note under your account.

Sign in to comment
Support independent defensive reporting

Help fund the next sourced briefing.

Support payments help cover research, hosting, source verification, and public access. They do not buy favorable coverage or alter editorial conclusions.

Support is a payment to FURULIE LLC, not a charitable donation. Commercial relationships are covered by the disclosure policy.

FLLC reporting is defensive and source-aware. Verify product exposure and follow the cited vendor guidance before changing production systems.

More briefings