← Field notesExploited this week · 17 Sep 2026

12 added to KEV since 9 September. Seven sit on the edge.

12 vulnerabilities have been added to CISA's Known Exploited Vulnerabilities catalogue since 9 September. Seven of them sit on the edge of a network or on the box that manages it.

  1. Cisco Secure Email Gateway
  2. Cisco Secure Firewall Management Center
  3. Citrix NetScaler
  4. Fortinet, multiple products (CVE-2025-25249, a 2025 CVE)
  5. MikroTik RouterOS, two entries
  6. ConnectWise ScreenConnect

The other five: JFrog Artifactory (two entries), GitLab, Chromium V8 and Google Pixel.

NCSC said the same thing on 27 August. Disruptive activity is being driven by internet-exposed systems and edge devices. The catalogue this week matches that assessment.

Three things worth doing this week if you run any of the above.

  1. Check the version you are actually running, not the version the change record says you are running.
  2. If it faces the internet and you cannot patch it this week, restrict the management interface to known addresses and write down that you did.
  3. Record the decision either way. A dated note that says checked and not affected is evidence. Silence is not.

Sources: CISA Known Exploited Vulnerabilities catalogue v2026.09.16 (entries dated 9 to 16 Sep 2026). NCSC, 27 Aug 2026, Disruptive cyber activity highlights risk from internet-exposed systems and edge devices: https://www.ncsc.gov.uk/news/disruptive-cyber-activity-highlights-risk-from-internet-exposed-systems-and-edge-devices

Written by Ben Brand, Velinor. The method behind these notes runs as Picket by Velinor.

More notes