Skip to content

Velinor AI Ltd · Company 15700539 · Reviewed October 2026

← Field notesExploited this week · 1 Oct 2026

91 added to KEV since July. 15 are tools that build or run software.

91 vulnerabilities were added to CISA's Known Exploited Vulnerabilities catalogue between 1 July and 22 September. The familiar names are there. Microsoft 11, Cisco 6, Fortinet 4, SonicWall 4.

The part worth noticing is the other column. 15 of the 91 are in tools that build, store or run software.

  1. Code and build. GitLab, Gitea, JetBrains TeamCity and Kestra.
  2. Artifact storage. JFrog Artifactory, four entries.
  3. AI and machine learning. Langflow, three entries, plus LiteLLM, MLflow and Ray.
  4. Web framework. Starlette.

Four more are remote management platforms used to run other people's estates. ConnectWise ScreenConnect, and N-able N-central with three entries.

These systems are often missing from the asset register as infrastructure. They tend to be installed by a development team, a data team or a managed service provider, sometimes in a cloud account the security team does not scan. They hold credentials, source code and the keys to production.

Two checks this week.

  1. Ask each engineering and data team for the self-hosted tools they run. Compare the list with what your scanner covers.
  2. Ask your managed service provider which remote management platform they use on your estate, which version, and who patches it.

Source: CISA Known Exploited Vulnerabilities catalogue v2026.09.23, entries dated 1 Jul to 22 Sep 2026, grouped by product, computed 24 Sep 2026.

Written by Ben Brand, Velinor. The method behind these notes runs as Picket by Velinor.

More notes