Jump to the main content block

【Vulnerability Alert】CISA Added 14 Known Exploited Vulnerabilities to the KEV Catalog (2026/09/07-2026/09/13)

publish date : 2026-09-30 update date : 2026-10-02

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026091602091111 Publication Time 2026-09-16 14:24:13
Incident Type ANA-Vulnerability Alert Discovery Time 2026-09-16 14:24:13
Impact Level Low  
[Subject]
【Vulnerability Alert】CISA Added 14 Known Exploited Vulnerabilities to the KEV Catalog (2026/09/07-2026/09/13)
[Content]

Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202609-00000016

【For detailed vulnerability information, please refer to the attachment】

【CVE-2026-75650】Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability (CVSS v3.1: 10.0)

【CVE-2026-81963】Microsoft Windows Link Following Vulnerability (CVSS v3.1: 7.8)

【CVE-2026-86218】N-able N-central Static Code Injection Vulnerability (CVSS v3.1: 9.8)

【CVE-2026-85880】Microsoft Windows Heap-Based Buffer Overflow Vulnerability (CVSS v3.1: 7.8)

【CVE-2026-19490】Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability (CVSS v3.1: 9.8)

【CVE-2025-25249】Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability (CVSS v3.1: 8.1)

【CVE-2026-87491】Google Chromium V8 Out of Bounds Write Vulnerability (CVSS v3.1: 8.8)

【CVE-2026-20079】Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability (CVSS v3.1: 100)

【CVE-2026-86060】MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability (CVSS v3.1: 9.8)

【CVE-2026-67277】MikroTik RouterOS Missing Authentication for Critical Function Vulnerability (CVSS v3.1: 8.2)

【CVE-2026-84869】ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability (CVSS v3.1: 9.9)

【CVE-2026-42016】JFrog Artifactory Incorrect Authorization Vulnerability (CVSS v3.1: 8.1)

【CVE-2026-42018】JFrog Artifactory Improper Authentication Vulnerability (CVSS v3.1: 7.5)

【CVE-2026-85706】GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability (CVSS v3.1: 10.0)

Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed)

[Affected Platform]

For detailed information, please refer to the Affected Platforms section in the attachment:

https://cert.tanet.edu.tw/pdf/TWCERTCC_KEV_0914_NISAC.pdf

[Recommended Actions]

【CVE-2026-75650】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version:
https://helpx.adobe.com/security/products/magento/apsb26-146.html

【CVE-2026-81963】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81963

【CVE-2026-86218】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version:
https://me.n-able.com/s/security-advisory/aArVy0000002Ld3KAE/cve202686218-preauthentication-remote-code-execution

【CVE-2026-85880】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880

【CVE-2026-19490】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version:
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939

【CVE-2025-25249】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version:
https://fortiguard.fortinet.com/psirt/FG-IR-25-084

【CVE-2026-87491】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version:
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html

【CVE-2026-20079】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2

【CVE-2026-86060】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version:
https://mikrotik.com/supportsec/september-2026-vulnerability/

【CVE-2026-67277】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version:
https://mikrotik.com/supportsec/september-2026-vulnerability/

【CVE-2026-84869】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version:
https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin

【CVE-2026-42016】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version:
https://docs.jfrog.com/releases/docs/jfrog-security-advisories

【CVE-2026-42018】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version:
https://docs.jfrog.com/releases/docs/jfrog-security-advisories

【CVE-2026-85706】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version:
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/

[Reference]

(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center
Click Num: