【Vulnerability Alert】CISA Added 14 Known Exploited Vulnerabilities to the KEV Catalog (2026/09/07-2026/09/13)
Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026091602091111 | Publication Time | 2026-09-16 14:24:13 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-09-16 14:24:13 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】CISA Added 14 Known Exploited Vulnerabilities to the KEV Catalog (2026/09/07-2026/09/13) |
|||
| [Content]
Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202609-00000016 【For detailed vulnerability information, please refer to the attachment】 【CVE-2026-75650】Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability (CVSS v3.1: 10.0) 【CVE-2026-81963】Microsoft Windows Link Following Vulnerability (CVSS v3.1: 7.8) 【CVE-2026-86218】N-able N-central Static Code Injection Vulnerability (CVSS v3.1: 9.8) 【CVE-2026-85880】Microsoft Windows Heap-Based Buffer Overflow Vulnerability (CVSS v3.1: 7.8) 【CVE-2026-19490】Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability (CVSS v3.1: 9.8) 【CVE-2025-25249】Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability (CVSS v3.1: 8.1) 【CVE-2026-87491】Google Chromium V8 Out of Bounds Write Vulnerability (CVSS v3.1: 8.8) 【CVE-2026-20079】Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability (CVSS v3.1: 100) 【CVE-2026-86060】MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability (CVSS v3.1: 9.8) 【CVE-2026-67277】MikroTik RouterOS Missing Authentication for Critical Function Vulnerability (CVSS v3.1: 8.2) 【CVE-2026-84869】ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability (CVSS v3.1: 9.9) 【CVE-2026-42016】JFrog Artifactory Incorrect Authorization Vulnerability (CVSS v3.1: 8.1) 【CVE-2026-42018】JFrog Artifactory Improper Authentication Vulnerability (CVSS v3.1: 7.5) 【CVE-2026-85706】GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability (CVSS v3.1: 10.0) Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
For detailed information, please refer to the Affected Platforms section in the attachment: |
|||
|
[Recommended Actions] 【CVE-2026-75650】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version: 【CVE-2026-81963】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version: 【CVE-2026-86218】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version: 【CVE-2026-85880】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version: 【CVE-2026-19490】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version: 【CVE-2025-25249】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version: 【CVE-2026-87491】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version: 【CVE-2026-20079】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version: 【CVE-2026-86060】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version: 【CVE-2026-67277】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version: 【CVE-2026-84869】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version: 【CVE-2026-42016】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version: 【CVE-2026-42018】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version: 【CVE-2026-85706】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version: |
|||
|
[Reference] |
|||
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw





