Analyst Guidance
This week prioritizes two actively exploited Linux kernel vulnerabilities added to CISA's KEV catalog, plus two critical remote code execution flaws in enterprise infrastructure products.
CVE Details & Remediation
How to read this report
🛡️Verified facts — NVD & CISA KEV
⏳Partially verified — awaiting NVD enrichment
🧠AI analysis — synthesis, verify before acting
🛡️Actionable · Verified facts
NVD-published · CISA KEV cross-checked🛡️CVE-2026-76460 – Cisco Identity Services Engine ✓ NVD
CVSS10 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV
EPSS1% · P55
ActionPatch immediately
Remediation Steps
- Apply the vendor security patch from Cisco for ISE authentication bypass
- Review API endpoint access controls and enforce strong authentication
- Audit recent API calls for unauthorized or anomalous activity
- Restrict API endpoint access to authorized administrators and systems only
References:
🛡️CVE-2026-20079 – Cisco Secure Firewall Management Center (FMC) And Security Cloud Control (SCC) Firewall Management ✓ NVD
CVSS10 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS76% · P99
ActionPatch immediately
AffectedGovernment Telecom Technology
Remediation Steps
- Apply the vendor security update for Cisco Secure Firewall Management Center as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-85706 – GitLab Community Edition And Enterprise Edition ✓ NVD
CVSS10 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS15% · P96
ActionPatch immediately
Remediation Steps
- Apply the latest GitLab security patch for Community Edition and Enterprise Edition immediately
- Verify patch application across all GitLab instances in your environment
- Review access logs for evidence of exploitation attempts
- Restrict network access to GitLab instances to trusted networks pending patch confirmation
References:
🛡️CVE-2026-75650 – Adobe Commerce And Magento ✓ NVD
CVSS10 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS2% · P81
ActionPatch immediately
Remediation Steps
- Identify systems affected by CVE-2026-75650 using vulnerability scanning tools
- Apply vendor patches according to the vendor's published security advisory
- Verify patch installation across all affected systems
References:
🛡️CVE-2026-49869 – Kestra OSS ✓ NVD
CVSS10 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS2% · P79
ActionPatch immediately
AffectedTechnology Finance Healthcare
Remediation Steps
- Apply the vendor security update for Kestra OSS as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-83548 – SonicWall SMA1000 Appliances ✓ NVD
CVSS10 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS5% · P91
ActionPatch immediately
Remediation Steps
- Apply SonicWall security updates for SMA 1000 series VPN appliances as released by vendor
- If patching cannot be completed immediately, isolate affected SMA 1000 appliances from untrusted networks
- Monitor appliance logs for unusual SSRF or authentication bypass attempts
- Enforce network access restrictions to administrative interfaces
- Review and revoke any suspicious user sessions or API tokens created on affected appliances
References:
🛡️CVE-2026-21962 – Oracle HTTP Server And Oracle Weblogic Server Proxy Plug-In ✓ NVD
CVSS10 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS42% · P99
ActionPatch immediately
AffectedTechnology Finance Government
Remediation Steps
- Apply the vendor security update for Oracle HTTP Server And Oracle Weblogic Server Proxy Plug-In as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-84869 – ConnectWise ScreenConnect ✓ NVD
CVSS9.9 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS1% · P51
ActionPatch immediately
AffectedGovernment Technology Defense
Remediation Steps
- Apply the vendor security update for Connectwise Screenconnect as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-76461 – Cisco Secure Email Gateway ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS2% · P80
ActionPatch immediately
AffectedTechnology Government
Remediation Steps
- Apply the vendor security update for Cisco Asyncos as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-19490 – Citrix NetScaler ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS6% · P93
ActionPatch immediately
AffectedTechnology Finance
Remediation Steps
- Apply the vendor security update for Citrix NetScaler as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2025-25249 – Fortinet Multiple Products ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS2% · P83
ActionPatch immediately
AffectedTechnology Finance
Remediation Steps
- Apply the vendor security update for Fortinet Multiple Products as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-86218 – N-Able N-Central ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS7% · P94
ActionPatch immediately
Remediation Steps
- Apply the vendor patch for N-able N-central immediately.
- Verify patch deployment across all instances.
- Monitor for indicators of compromise or suspicious authentication attempts.
- Review access logs for unauthorized pre-authentication activities.
References:
🛡️CVE-2026-81578 – PaperCut NG/MF ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS3% · P88
ActionPatch immediately
AffectedEducation
Remediation Steps
- Apply the vendor patch to address the authentication bypass flaw
- Review access logs for evidence of unauthorized authentication or command execution
- Conduct credential audit of accounts that may have been exposed
- Restrict network access to PaperCut management interfaces
References:
🛡️CVE-2026-9586 – Sangoma Switchvox ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS12% · P96
ActionPatch immediately
AffectedTechnology
Remediation Steps
- Apply the vendor security update for Sangoma Switchvox as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-82329 – JFrog Artifactory ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS8% · P94
ActionPatch immediately
AffectedTechnology Healthcare Finance
Remediation Steps
- Apply the vendor security update for JFrog Artifactory as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2023-49105 – Owncloud Server ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS43% · P99
ActionPatch immediately
Remediation Steps
- Apply ownCloud security patch for CVE-2023-49105 immediately
- Review access logs for indicators of compromise targeting file repositories
- Restrict network access to ownCloud instances to trusted networks where possible
- Monitor for unauthorized file access or exfiltration activity
References:
🛡️CVE-2021-23758 – Ajaxpro.2 Project Ajaxpro.2 (also: Michaelschwarz) ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS84% · P100
ActionPatch immediately
AffectedTechnology
Remediation Steps
- Apply the vendor security update for Ajaxpro.2 Project Ajaxpro.2 as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-60004 – Gitea ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS87% · P100
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for Gitea Gitea as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-8452 – Citrix NetScaler ADC And NetScaler Gateway ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS2% · P75
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for Citrix NetScaler ADC and NetScaler Gateway as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-86060 – MikroTik RouterOS ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS1% · P63
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for MikroTik RouterOS as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-82078 – PaperCut NG/MF ✓ NVD
CVSS9.1 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS4% · P89
ActionPatch immediately
AffectedEducation
Remediation Steps
- Apply the vendor patch to address the remote code execution vulnerability
- Audit logs for malicious script execution or unauthorized commands
- Verify integrity of system binaries and scripts on affected servers
- Restrict inbound access to PaperCut services to trusted networks
References:
🛡️CVE-2026-58138 – Orkes Conductor Workflow Platform ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild ● New this week
EPSS9% · P95
ActionPatch within 48 hours
Remediation Steps
- Upgrade Orkes Conductor to version 3.30.2 or later
- Restrict network access to Conductor APIs to trusted networks only
- Monitor authentication logs for suspicious unauthenticated access attempts
- Review any recent API activity logs for signs of compromise
References:
🛡️CVE-2026-53266 – Linux Kernel ✓ NVD
CVSS8.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS<1% · P20
ActionPatch immediately
AffectedTechnology
Remediation Steps
- Apply the vendor security update for Linux Kernel as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-58704 – Google Pixel ✓ NVD
CVSS8.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS<1% · P11
ActionPatch immediately
AffectedTechnology Government Defense
Remediation Steps
- Apply the vendor security update for Google Android as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-42016 – JFrog Artifactory ✓ NVD
CVSS8.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS9% · P95
ActionPatch immediately
Remediation Steps
- Apply vendor security patch for incorrect authorization flaw
- Reset credentials for administrative and service accounts post-patch
- Review audit logs for unauthorized access or privilege escalation
- Restrict Artifactory network access to trusted sources if patching is delayed
References:
🛡️CVE-2026-87491 – Google Chromium V8 ✓ NVD
CVSS8.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS1% · P61
ActionPatch immediately
AffectedTechnology Finance
Remediation Steps
- Apply the vendor security update for Google Chromium V8 as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-85046 – Google Chromium V8 ✓ NVD
CVSS8.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS1% · P72
ActionPatch immediately
AffectedTechnology Retail Telecom
Remediation Steps
- Apply the vendor security update for Google Chrome as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2019-1068 – Microsoft SQL Server ✓ NVD
CVSS8.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS53% · P99
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for Microsoft SQL Server as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-67277 – MikroTik RouterOS ✓ NVD
CVSS8.2 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS1% · P57
ActionPatch immediately
Remediation Steps
- Consult CISA KEV catalog and vendor advisory for affected product and version
- Apply vendor patch to all affected systems
- Verify patch deployment across your environment
References:
🛡️CVE-2026-59822 – BerriAI LiteLLM ✓ NVD
CVSS8.2 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS1% · P57
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for BerriAI LiteLLM as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-87886 – Acronis Backup ✓ NVD
CVSS7.8 NVD 3.0
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV
EPSS<1% · P17
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for Acronis Backup as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-42018 – JFrog Artifactory ✓ NVD
CVSS7.5 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV
EPSS11% · P96
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for JFrog Artifactory as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2025-39682 – Linux Kernel ✓ NVD
CVSS7.1 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV
EPSS1% · P67
ActionPatch immediately
AffectedEnergy
Remediation Steps
- Apply the latest Linux kernel security patch from your distribution
- Reboot systems after kernel update to activate the patch
- Verify kernel version post-reboot to confirm patch application
- Monitor for any anomalous TLS connections or network traffic
References:
🛡️CVE-2026-28326 – SolarWinds Access Rights Manager (ARM) ✓ NVD
CVSS8.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild ● New this week
EPSS1% · P45
ActionPatch within 48 hours
Remediation Steps
- Obtain the vendor patch from SolarWinds for ARM versions 2026.2 and prior
- Apply the security update to all ARM deployments
- Test in a non-production environment before production rollout
- Verify remediation by checking installed ARM version post-patch
References:
🛡️CVE-2025-39964 – Linux Kernel ✓ NVD
CVSS5.5 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV
EPSS1% · P55
ActionPatch immediately
Remediation Steps
- Consult CISA Known Exploited Vulnerabilities catalog for advisory details
- Apply the vendor patch for the affected Linux component
- Verify patching across all Linux systems in your environment
References:
🤖 This vulnerability report was compiled by defend.network using AI-powered analysis of vulnerability databases, vendor advisories, and threat intelligence feeds. Always verify remediation steps through official vendor channels before implementing changes in production environments.