Ransomware gangs are exploiting patched flaws in TeamCity and VMware vCenter that let attackers run commands without logging in, CISA warned. Cisco also patched an actively exploited flaw in its Identity Services Engine that gives unauthenticated attackers root access.
CISA is pushing federal agencies to prioritize vulnerabilities attackers are actually using, rather than severity scores alone, and will end its weekly vulnerability bulletin September 28. Agencies face a patch deadline today for exploited Check Point, Arista VeloCloud Orchestrator and F5 BIG-IP APM flaws, with Adobe and WSO2 fixes due September 27.
The gap between security orders and implementation extends beyond patching: a DHS watchdog found 78 federal agencies still had not fully met mandatory cloud security requirements as of February. Missing safeguards included multifactor authentication and blocking outdated login methods, while CISA lacks authority to enforce full, timely compliance.
CISA ordered federal civilian agencies to fix exploited flaws in WSO2 products and Adobe Commerce and Magento by September 27, 2026. CVE-2026-5430 allows authentication bypass in multiple WSO2 products, while CVE-2026-71362 lets unauthenticated attackers hijack customer accounts and access private data. The Adobe flaw affects Commerce, Commerce B2B and Magento Open Source versions through the July 2026 patches.
Bipartisan lawmakers proposed two bills Thursday to protect biotechnology, biomanufacturing and biological data as critical infrastructure without creating a new sector. The measures would require DHS to develop protection plans and CISA to coordinate security exercises with biotech organizations and add personnel focused on biometric data security. Systems handling genomic sequences and sensitive biometric data would also receive critical infrastructure coverage.
NIST released a draft update to its operational technology security guide, while CISA and the FBI warned critical infrastructure operators about risks from third-party ICS integrators. The agencies cited a 2025 intrusion in which foreign actors staged nine archives containing 800 network schematics, device configurations and customer details. NIST’s draft SP 800-82 Revision 4 is open for public comment through November 30, 2026.
Ransomware gangs are exploiting CVE-2026-63077, a critical authentication bypass flaw in JetBrains TeamCity On-Premises that allows unauthenticated attackers to execute operating system commands, CISA warned. JetBrains patched the flaw on July 25 in versions 2025.11.7 and 2026.1.3. Shadowserver tracks just over 160 unpatched servers, down from about 700 internet-exposed servers identified shortly after the patch.
CISA published a plan to improve CVE data quality, governance and infrastructure as new vulnerability records topped 67,000 in 2026. The plan also calls for broader participation across the global software community. Experts welcomed the goals but questioned the lack of public quality metrics and attention to missing machine-readable software identifiers.
CISA added four actively exploited flaws affecting Check Point products, Arista VeloCloud Orchestrator and F5 BIG-IP APM to its Known Exploited Vulnerabilities catalog, setting a September 25 deadline for federal civilian agencies to fix them. The flaws include Check Point path traversal vulnerability CVE-2026-93616 and F5 vulnerability CVE-2026-94127, both of which allow unauthenticated code execution.
Eighty-eight of 102 federal civilian executive branch agencies missed the June 2025 deadline to implement all mandatory cloud security policies under CISA’s BOD 25-01, the DHS inspector general found. As of February 2026, 78 agencies remained noncompliant. Missing safeguards included multifactor authentication and blocking outdated authentication methods; the watchdog said CISA lacks authority to enforce full, timely compliance.
Rep. Josh Gottheimer introduced a bipartisan bill to create a CISA pilot giving critical infrastructure operators free access to frontier AI models and technical support to address cybersecurity vulnerabilities. The AI Cyber Defense Act would authorize $100 million for 2027–2031, subject to appropriations, and prioritize nonprofit, publicly owned, rural and small organizations. Recent cyberattacks on water facilities prompted the proposal.
CISA confirmed active exploitation of CVE-2026-7273, a stack-based buffer overflow in Zyxel GS1900 Series Switches, and added it to its Known Exploited Vulnerabilities catalog. The flaw can let unauthenticated attackers on the local network execute operating-system commands through crafted HTTP requests. CISA set a September 24, 2026, remediation deadline and required forensic triage under BOD 26-04.
CISA ordered federal agencies to fix three Linux kernel vulnerabilities by September 21, 2026, after adding them to its Known Exploited Vulnerabilities catalog. The flaws are CVE-2025-39682 in the TLS receive path, CVE-2026-53266 involving an out-of-bounds write, and CVE-2025-39964 involving a race condition. Potential impacts include sensitive memory exposure, denial-of-service and privilege escalation; details of exploitation were not available.
CISA launched VINCE-NT on Sept. 17, 2026, a fully agency-hosted replacement for the original VINCE coordinated vulnerability disclosure system, which had been run since 2020 by Carnegie Mellon's CERT Coordination Center. The new platform adds automated advisory publishing, enhanced triage, secure file-sharing tools, and standardized terminology aligned with CSAF and CVE Record Format. Current VINCE users must update their reporting procedures, and active cases will migrate to VINCE-NT over the coming weeks, while historical data stays in the legacy system.
CISA will discontinue its weekly vulnerability bulletin starting September 28, citing its new Binding Operational Directive (BOD 26-04), which requires federal agencies to prioritize patching based on real-world exploitation evidence rather than severity scores alone. The agency will still publish its Known Exploited Vulnerabilities catalog, Cybersecurity Alerts and Advisories, and CVE listings, and it's urging CISOs to rely more on vendors' own security bulletins.
The Cybersecurity and Infrastructure Security Agency has published new guidance urging organizations of all sizes to deploy honeypots, breadcrumbs, tripwires, and honeytokens to catch attackers using stolen credentials and living-off-the-land techniques. The advisory frames decoys as a complement to Zero Trust architectures, arguing they generate high-fidelity alerts, cut down alert fatigue, and can be added to existing security stacks without major changes, using the MITRE ATT&CK and MITRE Engage frameworks as implementation guides.
Cisco patched an actively exploited authentication bypass in its Identity Services Engine and ISE Passive Identity Connector, tracked as CVE-2026-76460 with a maximum CVSS score of 10.0, allowing unauthenticated attackers to gain root access via a crafted API request. CISA added the flaw to its Known Exploited Vulnerabilities catalog, and Cisco separately fixed 20 other critical, high, and medium-severity bugs in ISE plus flaws in its Secure Firewall ASA, Threat Defense, and Management Center products. Fixes are available in ISE versions 3.1 Patch 12 through 3.5 Patch 4.
CISA added three actively exploited flaws to its Known Exploited Vulnerabilities catalog: CVE-2026-76460 (CVSS 10.0), an authentication bypass in Cisco Identity Services Engine allowing unauthenticated remote access via a crafted API request; CVE-2026-87886, a local privilege escalation bug in Acronis Backup's cPanel/WHM plugin and Plesk extension caused by insecure file permissions; and CVE-2026-58704 (CVSS 8.8), a permission-bypass flaw in the Google Pixel cellular modem exploited without user interaction. Acronis and Google both confirmed limited, targeted exploitation, and federal agencies must remediate under BOD 22-01.
New guidance from NIST and CISA, "Protecting Tokens and Assertions from Forgery, Theft, and Misuse" (NIST IR 8587), sets rules for securing digitally signed tokens used in single sign-on and API access, but explicitly leaves AI agent actions out of scope. Experts say agentic systems break the guidance's core assumption of a single, bounded token holder, warning that prompt injection and multi-step delegation chains can let a valid token be misused without detection, and recommend treating AI agents as low-trust identities with task-based, expiring credentials.
CISA added CVE-2026-84869, a critical ConnectWise ScreenConnect flaw involving improper privilege management and missing authorization, to its Known Exploited Vulnerabilities catalog on September 11, 2026, after confirming active exploitation. The bug lets attackers transfer and execute files during active remote sessions without user authorization, potentially enabling persistence or lateral movement across managed environments. Agencies under Binding Operational Directive 26-04 face a September 14 remediation deadline and must also conduct forensic triage, not just patch.
CISA has added CVE-2026-76461, a critical zero-day (CVSS 9.8) in Cisco Secure Email Gateway, to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The flaw lets unauthenticated attackers send crafted emails with malicious SQL statements to gain root-level command execution on affected physical and virtual devices, and Cisco says no workarounds exist. Federal agencies must remediate by September 17, 2026.
CISA officials said the agency's Continuous Diagnostics and Mitigation program, which supplies cybersecurity tools to federal agencies, needs to move faster and unify data across agencies to keep pace with emerging threats. Program leaders outlined a three-year roadmap to expand SIEM as a Service and described plans to aggregate agency demand, buy outcomes rather than specific products, and design acquisitions for continuous improvement. Officials noted the program has evolved since the SolarWinds breach exposed gaps in government-wide visibility during incident response.
CISA has confirmed ransomware gangs are now exploiting CVE-2026-59310, a critical directory traversal flaw in VMware vCenter's Syslog server that Broadcom patched July 29. The vulnerability, which allows unauthenticated remote code execution, was already under attack by a suspected APT group deploying reverse SSH tools on over 361 compromised IPs across 47 countries. Shadowserver currently tracks more than 450 vCenter servers still exposed online, with no data on how many remain unpatched.
CISA has added CVE‑2026‑85706, a maximum-severity path traversal flaw in GitLab's repository commits API, to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The bug, rated 10/10, lets unauthenticated attackers read sensitive files such as credentials and secrets; GitLab fixed it in CE/EE versions 19.3.2, 19.2.6, and 19.1, and federal agencies have three days to patch. Researchers at watchTowr say they've already spotted in-the-wild probes targeting the flaw.

