← Field notesThe misread · 25 Sep 2026

Authentication failures doubled their share of KEV additions in 2026.

The common picture of an exploited vulnerability is a clever memory bug found by a skilled team. This year's catalogue does not look like that.

Of the 237 vulnerabilities CISA has added to its Known Exploited Vulnerabilities list in 2026, grouped by the weakness recorded against each one:

  1. 53 are injection. The system ran something it was sent.
  2. 45 are authentication or authorisation failures. The system did not properly check who was asking, or what they were allowed to do.
  3. 36 are memory safety bugs.

Authentication failures are 19% of this year's additions. In everything added before 2026 they were under 10%. Memory safety has gone the other way, from 25% to 15%.

Why that matters. A missing authentication check on an internet-facing management interface does not take skill to use once it is public. So the fix has two halves. Patch it. Then ask why it was reachable, because a management interface nobody on the internet can reach cannot be exploited from the internet, whatever its bugs.

Source: CISA Known Exploited Vulnerabilities catalogue v2026.09.23, cwes field, computed 24 Sep 2026. Groupings: injection = CWE-94, 78, 77, 89, 502, 917, 95. Authentication or authorisation = CWE-287, 306, 288, 290, 862, 863, 285, 798, 640, 284. Memory safety = CWE-787, 416, 119, 122, 121, 125, 190, 843, 476, 415, 120. An entry can carry more than one weakness.

Written by Ben Brand, Velinor. The method behind these notes runs as Picket by Velinor.

More notes