Stay ahead of it

Security advisories

Vulnerabilities that attackers are actively exploiting right now, straight from CISA’s public Known Exploited Vulnerabilities (KEV) catalog. If any of these affect gear you use, patch it — or let us help.

What this actually means

What is a “known exploited vulnerability,” and why should a small business care?

Not theoretical — confirmed, in the wild

Security researchers find thousands of software flaws every year, but most are never actually used against real victims. CISA’s KEV catalog is different: it only lists vulnerabilities the federal government has confirmed are being actively exploited by real attackers, right now. That’s what makes this list worth checking, not the raw size of it.

Why a small business, specifically

Attackers running these exploits usually aren’t hand-picking targets — they’re scanning the whole internet for anything still running the affected software, small business or Fortune 500. A shop running an old router firmware or an unpatched web server is just as reachable as a large company, and often has fewer defenses watching for it.

Live feed

Recently added to the KEV catalog

Source: CISA KEV · as of this build, September 12, 2026

CVE-2026-85706 Sep 11, 2026

GitLab Community Edition and Enterprise Edition

GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository

CVE-2026-42018 Sep 11, 2026

JFrog Artifactory

JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

CVE-2026-42016 Sep 11, 2026

JFrog Artifactory

JFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

CVE-2026-84869 Sep 11, 2026

ConnectWise ScreenConnect

ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confi

CVE-2026-67277 Sep 10, 2026

MikroTik RouterOS

MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.

CVE-2026-86060 Sep 10, 2026

MikroTik RouterOS

MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation.

CVE-2026-20079 Sep 9, 2026

Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote

CVE-2026-87491 Sep 9, 2026

Google Chromium V8

Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium

CVE-2025-25249 Sep 9, 2026

Fortinet Multiple Products

Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.

CVE-2026-19490 Sep 9, 2026

Citrix NetScaler

Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN,

CVE-2026-85880 Sep 8, 2026

Microsoft Windows

Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.

CVE-2026-86218 Sep 8, 2026

N-able N-central

N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.

CVE-2026-81963 Sep 8, 2026

Microsoft Windows

Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.

CVE-2026-75650 Sep 8, 2026

Adobe Commerce and Magento

Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.

CVE-2026-85046 Sep 4, 2026

Google Chromium V8

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, incl

CVE-2026-83549 Sep 2, 2026

SonicWall SMA1000 Appliances

SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

CVE-2026-83548 Sep 2, 2026

SonicWall SMA1000 Appliances

SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.

CVE-2026-9586 Sep 2, 2026

Sangoma Switchvox

Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operatio

CVE-2026-82329 Sep 2, 2026

JFrog Artifactory

JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.

CVE-2026-49869 Sep 2, 2026

Kestra Kestra OSS

Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.

CVE-2026-48710 Sep 2, 2026

Kludex Starlette

Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depe

CVE-2026-59822 Sep 2, 2026

BerriAI LiteLLM

BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.

CVE-2026-81578 Aug 31, 2026

PaperCut NG/MF

PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.

CVE-2026-82078 Aug 31, 2026

PaperCut NG/MF

PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the Pap

This is a snapshot of the most recently added entries, refreshed when the site rebuilds — not a live real-time ticker. For the full, always-current list, see the CISA catalog directly.

What to actually do

If something here touches your gear

1. Check if it applies

Look at the vendor and product name, not just the headline. Most entries affect specific versions of specific software or firmware — check what you’re actually running before assuming the worst.

2. Patch it — don’t wait

These aren’t "someday" updates. If a fix is available for something on this list, that’s the update to prioritize this week, ahead of routine patching.

3. Not sure? Ask us

If you don’t know whether your network, website, or devices are affected — or you just don’t have time to check — that’s exactly what a scoped penetration test or a quick call can answer.

Not sure if you’re exposed?

We do authorized security testing for small businesses and can check whether these affect you.