Five security items a day: vulnerabilities actually being exploited first, from the CISA KEV catalogue, then high-severity CVEs in widely deployed software.
CyberWatch Newsletter -- 2026-09-21
5 items out of 248 considered, known-exploited first, then severity and reach (cap 5).
Selection: 5 known-exploited (in the CISA KEV catalogue, attacks are happening now). Each item says which under "Why this is here".
KNOWN EXPLOITEDCRITICALCVSS 9.8published 2025-09-05
KNOWN EXPLOITED. CISA lists this as known-exploited in Linux Kernel on 2026-09-18, so it is being used against people now -- that outranks severity.
What happened: A critical flaw in the Linux kernel TLS implementation mishandled zero-length records on the receive list, potentially allowing attackers to exploit the vulnerability remotely. The issue arises when an initial record from the receive list is zero length, bypassing expected processing logic.
Who is affected: Users running the Linux kernel, including those managing Debian Linux systems or Siemens SIMATIC CN 4100 devices, are affected by this vulnerability. Any environment utilizing TLS over Linux kernel networking stacks may be at risk.
How serious: This vulnerability is rated Critical with a CVSS score of 9.8, indicating severe impact on confidentiality, integrity, and availability. Remote attackers can exploit it without authentication or user interaction.
What to do: Apply the available kernel patches referenced in the stable git commits to resolve the TLS record handling issue. Ensure all systems are updated to a version containing the fix for CVE-2025-39682.
Why this is here: Known exploited -- CISA lists this as known-exploited in Linux Kernel on 2026-09-18, so it is being used against people now -- that outranks severity. CRITICAL (CVSS 9.8); reach 100/100 via "linux kernel".
KNOWN EXPLOITEDCRITICALCVSS 10.0published 2026-09-16
KNOWN EXPLOITED. CISA lists this as known-exploited in Cisco Identity Services Engine on 2026-09-16, so it is being used against people now -- that outranks severity.
What happened: A critical vulnerability in the Cisco Identity Services Engine API allows unauthenticated remote attackers to bypass authentication controls. This flaw enables unauthorized access to the device by circumventing the web-based management interface through crafted requests.
Who is affected: Organizations running Cisco Identity Services Engine Software or the Cisco ISE Passive Identity Connector are at risk.
How serious: The issue is rated Critical with a perfect CVSS score of 10.0, indicating full compromise of confidentiality, integrity, and availability.
What to do: Review the official Cisco Security Advisory for mitigation steps and apply the necessary patches to affected systems immediately.
Why this is here: Known exploited -- CISA lists this as known-exploited in Cisco Identity Services Engine on 2026-09-16, so it is being used against people now -- that outranks severity. CRITICAL (CVSS 10.0); reach 60/100 via "cisco".
KNOWN EXPLOITEDCRITICALCVSS 9.8published 2026-09-14
KNOWN EXPLOITED. CISA lists this as known-exploited in Cisco Secure Email Gateway on 2026-09-14, so it is being used against people now -- that outranks severity.
What happened: A critical vulnerability in Cisco AsyncOS Software for Cisco Secure Email Gateway allows unauthenticated remote attackers to execute arbitrary commands with root privileges. The flaw stems from insufficient validation in the email parsing logic, enabling attackers to inject malicious SQL statements via crafted emails.
Who is affected: Organizations using Cisco Secure Email Gateway hardware appliances (models C195, C395, C695) or virtual appliances (C100v, C300v, C600v) running affected versions of AsyncOS Software.
How serious: This is a critical severity issue with a CVSS score of 9.8, allowing full system compromise including root access and arbitrary command execution on the underlying operating system.
What to do: Apply the vendor-provided patches or updates to the Cisco Secure Email Gateway devices as soon as possible. Monitor the Cisco Security Advisory and CISA Known Exploited Vulnerabilities catalog for specific version details and mitigation steps.
Why this is here: Known exploited -- CISA lists this as known-exploited in Cisco Secure Email Gateway on 2026-09-14, so it is being used against people now -- that outranks severity. CRITICAL (CVSS 9.8); reach 60/100 via "cisco".
KNOWN EXPLOITED. CISA lists this as known-exploited in Linux Kernel on 2026-09-18, so it is being used against people now -- that outranks severity.
What happened: A vulnerability in the Linux kernel's netfilter bridge component allows an attacker with local privileges to write to non-writable memory fragments during ARP source hardware address rewriting. This flaw occurs because the code fails to ensure the ARP header range is writable before accessing or modifying it, potentially leading to memory corruption.
Who is affected: Administrators and developers running Linux systems that utilize the netfilter bridge ebtables SNAT target with ARP rewrite capabilities are affected.
How serious: The issue is rated HIGH severity with a CVSS score of 8.8, indicating significant potential for impact on confidentiality, integrity, and availability.
What to do: Apply the kernel updates referenced in the stable git commits provided in the vulnerability record to resolve the memory handling error.
Why this is here: Known exploited -- CISA lists this as known-exploited in Linux Kernel on 2026-09-18, so it is being used against people now -- that outranks severity. HIGH (CVSS 8.8); reach 100/100 via "linux kernel".
KNOWN EXPLOITED. CISA lists this as known-exploited in Acronis Backup on 2026-09-16, so it is being used against people now -- that outranks severity.
What happened: Acronis Backup plugins for cPanel, Plesk, and DirectAdmin contain insecure file permissions that allow local privilege escalation. This vulnerability affects versions before specific build numbers for each respective hosting control panel integration.
Who is affected: Administrators running Acronis Backup on Linux systems with cPanel & WHM, Plesk, or DirectAdmin are at risk. Any user with local access to these affected installations can potentially escalate privileges.
How serious: The issue is rated HIGH severity with a CVSS score of 7.8, indicating significant impact on confidentiality, integrity, and availability. Attackers can gain full control of the system by exploiting the permission flaws.
What to do: Update the Acronis Backup plugin for cPanel to build 1.9.3.1021 or later. Upgrade the Acronis Backup extension for Plesk to build 1.8.11.638 or later, and the DirectAdmin plugin to build 1.2.3.238 or later.
Why this is here: Known exploited -- CISA lists this as known-exploited in Acronis Backup on 2026-09-16, so it is being used against people now -- that outranks severity. HIGH (CVSS 7.8); reach 100/100 via "linux kernel".
Summaries: 5/5 written by a local LLM.Source: NVD CVE 2.0 API.