CISA's latest release: 4 October 2026, 18:52 UTC
What attackers exploit, and what to patch first
As of , 1,734 vulnerabilities are on CISA's list of exploited vulnerabilities; CISA added 5 in the last 7 days. Patch first: CVE-2026-85706 in GitLab Community Edition and Enterprise Edition.
Patch first now
Our patch-first order for the entries CISA listed in the last 30 days.
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1 | CVE-2026-85706Path Traversal | GitLab Community Edition and Enterprise Edition | Patch nowForensic triage required by CISA; Metasploit module | 0.93 | ||
| 2 | CVE-2026-20079Firewall Management Center Authentication Bypass Using an Alternate Path or Channel | Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management | Patch nowForensic triage required by CISA; Metasploit module | 0.88 | ||
| 3 | CVE-2026-71362Incorrect Authorization | Adobe Commerce and Magento | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.88 | ||
| 4 | CVE-2026-87902Remote File Inclusion | WordPress Core | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.46 | ||
| 5 | CVE-2026-76461SQL Injection | Cisco Secure Email Gateway | Patch nowForensic triage required by CISA | 0.28 | ||
| 6 | CVE-2026-93616Path Traversal | Check Point Multiple Products | Patch nowForensic triage required by CISA | 0.20 | ||
| 7 | CVE-2026-19490Authentication Bypass Using an Alternate Path or Channel | Citrix NetScaler | Patch nowForensic triage required by CISA | 0.23 | ||
| 8 | CVE-2026-76460Incorrect Use of Privileged APIs | Cisco Identity Services Engine | Patch nowForensic triage required by CISA | 0.14 | ||
| 9 | CVE-2026-86218Static Code Injection | N-able N-central | Patch nowForensic triage required by CISA | 0.13 | ||
| 10 | CVE-2026-85102Improper Certificate Validation | Check Point Multiple Products | Patch nowForensic triage required by CISA | 0.08 |
Latest additions
Added each month
Most exploited vendors in 2026
Changes CISA did not announce
CISA's file keeps only the latest state of each entry. We keep what changed.