This Week in Threats: Sep 08–Sep 22, 2026

Expert cybersecurity insights for IT professionals

Last updated: September 22, 2026

By FixTheVuln Team Peer-reviewed security content Sources: CISA Known Exploited Vulnerabilities Catalog, NVD

Weekly Threat Summary

22 vulnerabilities were added to the CISA Known Exploited Vulnerabilities (KEV) catalog this period. The highest CVSS score is 10.0.

This week includes 8 critical-severity vulnerabilities (CVSS 9.0+) that require immediate attention.

This Week's Vulnerabilities

CVE-2026-85706 — GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability

CVE-2026-20079 — Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

CVE-2026-75650 — Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

CVE-2026-84869 — ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

CVE-2026-76461 — Cisco Secure Email Gateway SQL Injection Vulnerability

CVE-2026-86060 — MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

CVE-2026-19490 — Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability

CVE-2026-86218 — N-able N-central Static Code Injection Vulnerability

CVE-2026-7273 — Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability

CVE-2026-53266 — Linux Kernel Out-of-Bounds Write Vulnerability

CVE-2026-58704 — Google Pixel Improper Authorization Vulnerability

CVE-2026-87491 — Google Chromium V8 Out of Bounds Write Vulnerability

CVE-2026-67277 — MikroTik RouterOS Missing Authentication for Critical Function Vulnerability

CVE-2026-42016 — JFrog Artifactory Incorrect Authorization Vulnerability

CVE-2025-25249 — Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability

CVE-2025-39964 — Linux Kernel Race Condition Vulnerability

CVE-2026-85880 — Microsoft Windows Heap-Based Buffer Overflow Vulnerability

CVE-2026-42018 — JFrog Artifactory Improper Authentication Vulnerability

CVE-2025-39682 — Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

CVE-2026-87886 — Acronis Backup Incorrect Default Permissions Vulnerability

CVE-2026-76460 — Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

What This Means for You

If you run any of the affected products, patch immediately. Critical-severity vulnerabilities are actively exploited in the wild — CISA adds them to the KEV catalog specifically because they represent real, current threats.

Use the CVSS Calculator to assess how these scores apply to your specific environment.

Cert Study Angles

These CVEs map directly to certification exam objectives. Use them as real-world case studies:

CompTIA Security+

ISC2 CISSP

Cisco CCNA

See all CVEs mapped to your cert: Exploit Tracker

Tools to Help

Stay Updated

This roundup is published every Tuesday. Bookmark the FixTheVuln Blog to stay on top of the latest threats — or subscribe via RSS.

Explore More

Free Security Tools Practice Quizzes Cert Comparisons

FixTheVuln Store

CISSP Exam Prep? Get the Study Planner

Comprehensive planner for (ISC)2 certifications. Domain-mapped study schedules, practice tracking, and more.

Shop CISSP Planner

Also available: SSCP, CCSP

CyberFolio

Building cybersecurity skills? Track them in one place.

Build a shareable cybersecurity portfolio that highlights your certifications, projects, and skills — free.

Build Your Portfolio →
← Back to Home ← All Blog Posts