The Cybersecurity and Infrastructure Security Agency added a fresh batch of actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog this week, and the update lands at an unusual moment for federal patch policy. Reports tracking CISA’s advisories index show an entry dated September 2, 2026, titled “CISA Adds Seven Known Exploited Vulnerabilities to Catalog,” while KEV-tracking site Senserva counted 11 vulnerabilities added across eight vendors over the same seven-day window. The names on the list read like a cross-section of enterprise IT: Citrix NetScaler, the Linux kernel, Gitea, ownCloud, Red Hat utilities, Microsoft SQL Server, and a legacy .NET framework called Ajax.NET Professional.

What makes this round different from the routine drumbeat of KEV updates is the policy shifting underneath it. On June 10, 2026, CISA issued Binding Operational Directive 26-04, replacing the fixed-deadline model federal agencies have followed since November 2021 with a risk-tiered system that can compress remediation windows to as little as three calendar days. The September additions are among the first waves of CVEs to be triaged under that new framework, and the change is forcing security teams well beyond the federal government to rethink how fast “patch now” actually needs to mean.

What Changed in the CISA KEV Catalog This Week

CISA’s Known Exploited Vulnerabilities catalog exists to answer one question: which bugs are attackers actually using right now, as opposed to which ones merely look dangerous on paper. Unlike a CVSS score, which measures theoretical severity, KEV inclusion means CISA has direct evidence of in-the-wild exploitation. Once a CVE lands on the list, Federal Civilian Executive Branch agencies are legally bound to patch it by a set deadline.

The early-September wave, according to Senserva’s weekly KEV tracking page, included 11 CVEs spanning PaperCut, ownCloud, the Linux kernel, JFrog Artifactory, Red Hat, Microsoft, Citrix, and Gitea. That page explicitly flags PaperCut’s CVE-2026-81578 as carrying a CVSS score of 9.8, the highest severity rating on the scale. A separate report from The Hacker News, dated August 27, 2026, covered an earlier slice of the same wave: Citrix NetScaler ADC and Gateway’s CVE-2026-8452, a Linux kernel privilege-escalation flaw tracked as CVE-2022-0995, two decade-old Red Hat bugs (CVE-2015-5287 and CVE-2015-3246), a Microsoft SQL Server remote-code-execution flaw from 2019 (CVE-2019-1068), and a deserialization bug in Ajax.NET Professional, CVE-2021-23758, dating back to 2021.

That last detail is worth sitting with. Several of the vulnerabilities added to the KEV catalog this month are not new discoveries. They are years-old bugs that attackers only recently started weaponizing at scale, or that CISA only recently confirmed active exploitation for. Old code does not stop being a target just because it stopped making headlines.

The JFrog Case: From “Not Yet in KEV” to Confirmed

One entry in this batch closes a loop this outlet was already tracking. CVE-2026-82329, an authentication-bypass flaw in JFrog Artifactory carrying a CVSS score of 9.8, had not appeared in the KEV catalog as of our prior coverage of the bug. Reporting now indicates that status has changed. The KEV catalog entry for CVE-2026-82329 shows a “Date Added” of September 2, 2026, and notes that the vulnerability requires forensic triage under BOD 26-04, with its “Known To Be Used in Ransomware Campaigns” field marked “Unknown.”

That progression, from disclosed and patchable to confirmed under active attack, is the exact pipeline BOD 26-04 was built to speed up. It also illustrates why security teams cannot treat a CVE’s absence from KEV as a green light to deprioritize it. JFrog Artifactory sits inside the software supply chain of thousands of organizations as an artifact repository, and an auth-bypass bug there can expose build pipelines, container images, and package registries in one move. PaperCut, the other repeat name in this batch, has its own history: CISA added PaperCut flaws to KEV earlier this year in an episode this outlet covered separately, tied to an estimated 70,000 affected print-management deployments.

BOD 26-04: The Policy Shift Driving Faster Deadlines

To understand why September’s KEV wave matters more than a typical monthly update, it helps to compare the rule that used to govern federal patch deadlines with the one that replaced it. Binding Operational Directive 22-01, issued November 3, 2021, required Federal Civilian Executive Branch agencies to remediate every catalog entry by the fixed due date CISA assigned when the CVE was added. Third-party summaries of that policy describe those windows as typically landing in the 14-to-21-day range, regardless of how the vulnerability was actually being used against real targets.

BOD 26-04, issued June 10, 2026, tears up that one-size-fits-all clock. According to a FedRAMP program notice summarizing the directive, agencies must now reprioritize vulnerability remediation based on four factors: public exposure of the affected system, KEV status, whether the flaw is automatable (meaning it can be exploited via scripted, unauthenticated attacks), and technical impact. A vulnerability that checks all four boxes falls into the highest-risk tier, and a research note from the Cloud Security Alliance states that tier carries a three-calendar-day patch deadline, down from the old two-to-three-week window.

Security vendor Nozomi Networks has described BOD 26-04 as consolidating and superseding both BOD 22-01 and the earlier BOD 19-02, folding federal vulnerability policy into a single risk-weighted framework instead of a patchwork of overlapping directives. Zafran, another security vendor tracking the change, described it as signaling the end of a patch-everything mentality that defined federal vulnerability management for the better part of a decade. Whether that characterization holds up in practice depends on how consistently CISA applies the four-factor test across the hundreds of CVEs it reviews each year.

September 2026 KEV Additions: The Full List

The table below compiles the CVEs reported as part of the late-August-through-September 2026 KEV wave, drawn from Senserva’s tracking page, The Hacker News, and cvefeed.io’s KEV tracker. Reported remediation due dates vary by source and by each CVE’s individual triage date, so organizations should confirm exact deadlines against CISA’s own catalog rather than this summary. It is a similar pattern to the one that put an MLflow server-side request forgery bug, covered here previously, onto the KEV catalog earlier this year: a CVE sits disclosed for a stretch, then confirmed exploitation pushes it onto CISA’s radar and a mandatory clock starts.

CVE IDVendor / ProductVulnerability TypeReported CVSSReported Due Date
CVE-2026-81578PaperCut MF/NGCritical remote code execution9.8Reported
CVE-2026-82078PaperCut NG/MFUnsafe reflectionNot disclosedSept. 14, 2026
CVE-2026-82329JFrog ArtifactoryAuthentication bypass9.8Sept. 2, 2026 (added)
CVE-2026-53362Linux kernelMemory safety flawNot disclosedReported
CVE-2023-49105ownCloudImproper access controlNot disclosedReported
CVE-2026-8452Citrix NetScaler ADC/GatewayMemory buffer overflow (DoS)Not disclosedAug. 29, 2026
CVE-2026-60004GiteaNot disclosedNot disclosedReported
CVE-2022-0995Linux kernelOut-of-bounds write / privilege escalationNot disclosedSept. 9, 2026
CVE-2019-1068Microsoft SQL ServerRemote code executionNot disclosedAug. 29, 2026
CVE-2015-5287Red Hat ABRTPrivilege escalation (symlink)Not disclosedSept. 9, 2026
CVE-2015-3246Red Hat libuserRace condition / file corruptionNot disclosedSept. 9, 2026
CVE-2021-23758Ajax.NET ProfessionalInsecure deserialization / RCENot disclosedSept. 9, 2026

Twelve entries, eight distinct vendors, and a spread of vulnerability classes from memory corruption to insecure deserialization. That range is itself a signal. CISA KEV additions used to skew toward flashy remote-code-execution bugs in internet-facing appliances. This batch includes those, but it also includes a decade-old Linux privilege-escalation bug and two Red Hat utilities patched years ago in most current distributions, showing up because attackers are still finding unpatched instances to exploit.

Old Bugs, New Urgency: Why 2015-Era CVEs Are Reappearing

CVE-2015-5287 and CVE-2015-3246, the two Red Hat entries in this wave, were originally disclosed and patched more than a decade ago. Their reappearance on the KEV catalog does not mean the original patches failed. It means CISA has evidence that unpatched, out-of-date systems running the vulnerable versions are being actively targeted today, likely as part of opportunistic scanning campaigns that sweep the internet for any exposed service regardless of age.

This pattern is not new to 2026, but it is a recurring theme in KEV data. A June 2026 KEV digest from VulnCheck tracked 23 vulnerabilities added to the catalog that month alone, including six zero-days and two tied to named threat actor groups, alongside older bugs still circulating in unpatched infrastructure. An August 18, 2026 wave added four critical CVEs rated 9.1 or higher, including flaws in Windows IKE Service Extensions, on-premises SharePoint, VMware vCenter’s Syslog component, and macOS Screen Sharing. The throughline across all of these waves is the same: attackers do not care how old a vulnerability is, only whether a copy of the vulnerable software is still reachable.

How KEV Compares to Other Vulnerability Scoring Systems

Security teams juggle several overlapping systems for deciding what to patch first, and the September KEV wave is a good example of why none of them work alone. CVSS, maintained by FIRST.org, scores a vulnerability’s theoretical severity based on factors like attack complexity and required privileges, but it says nothing about whether anyone is actually exploiting the bug. EPSS, also from FIRST.org, tries to fill that gap by predicting the probability a CVE will be exploited within the next 30 days. CISA’s KEV catalog is the most conservative of the three: it only lists vulnerabilities CISA has confirmed are already being exploited, with no predictive modeling involved.

SystemMaintained ByWhat It MeasuresFederal Deadline Tied to It
CVSSFIRST.orgTheoretical severity (0-10 scale)No
EPSSFIRST.orgPredicted exploitation probability, 30-day windowNo
CISA KEVCISAConfirmed active exploitationYes, under BOD 22-01 / BOD 26-04

The interplay between these systems shows up directly in this batch. Ajax.NET Professional’s CVE-2021-23758 was flagged by KEV trackers as the entry “likeliest to be attacked next” among recent additions, citing a FIRST.org EPSS score of 84% for exploitation within 30 days, according to Senserva’s tracking data. Under BOD 26-04’s four-factor model, a high EPSS score alone would not automatically trigger the three-day deadline. It has to combine with public exposure, automatability, and technical impact before a CVE lands in the fastest tier. That distinction is exactly what BOD 26-04 was designed to introduce: not just “is this bad,” but “is this bad, exposed, easy to automate, and damaging, all at once.”

Historical Context: A Decade of Tightening Federal Patch Rules

CISA’s approach to mandatory patch deadlines has tightened steadily since its earliest directives. BOD 19-02, an earlier policy referenced in Cloud Security Alliance research, set a 15-day window for critical vulnerabilities and 30 days for high-severity ones, based purely on CVSS-style severity ratings. BOD 22-01 replaced that in November 2021 with the KEV-based model, tying deadlines to confirmed exploitation rather than theoretical severity, typically landing in the 14-to-21-day range per catalog entry. BOD 26-04 compresses that further for the highest-risk cases, down to three calendar days when a vulnerability is publicly exposed, KEV-listed, automatable, and technically damaging all at once.

Each iteration reflects the same underlying pressure: attackers have gotten faster at weaponizing disclosed vulnerabilities, so defenders’ mandated response windows have had to shrink to keep pace. A three-day deadline was unthinkable under BOD 19-02’s month-long windows. In 2026, it is federal policy for the vulnerabilities that matter most.

Market Impact: What This Means for Enterprise IT Teams

BOD 26-04 legally binds only Federal Civilian Executive Branch agencies, but its practical reach extends well past the federal government. Large enterprises, state and local agencies, and critical infrastructure operators routinely mirror CISA’s KEV deadlines in their own internal patch-management policies, treating the federal catalog as a de facto industry benchmark even when they are not legally required to follow it. A tighter three-day federal deadline puts pressure on those organizations to match it or explain internally why they are moving slower than the government’s own standard.

For vendors, the shift raises the cost of shipping a patch late. Software makers whose products end up in the highest-risk BOD 26-04 tier will face customers demanding emergency patches on a three-day clock instead of the two-to-three-week runway BOD 22-01 allowed. That compresses the entire vulnerability-disclosure-to-patch pipeline, from the moment a researcher reports a bug to the moment a fix ships, and it raises the stakes for coordinated disclosure timelines that assumed slower federal response windows.

The software-supply-chain angle is where this batch is most instructive. JFrog Artifactory sits in build pipelines. Gitea is a self-hosted Git platform used by development teams who choose it specifically to avoid depending on GitHub or GitLab. ownCloud handles enterprise file sharing. None of these are consumer-facing products, but a compromise in any of them can cascade into every downstream system that trusts artifacts, code, or files coming out of them. KEV additions in this category tend to have outsized blast radius relative to their public profile.

Competitive Landscape: How Other Governments Track Exploited Vulnerabilities

CISA’s KEV catalog is the most widely referenced government-run exploited-vulnerability list in the world, largely because it publishes in machine-readable JSON and CSV formats that security tools can ingest automatically, and because it updates multiple times daily according to CISA’s own catalog documentation. Other governments maintain their own vulnerability databases, but few have built an equivalent mandatory, confirmed-exploitation list with the same public visibility and automation-friendly format. That gap is part of why so many non-federal organizations, and even software vendors outside the United States, treat KEV inclusion as a de facto global signal that a CVE demands immediate attention, regardless of where the affected organization is located or which regulator has jurisdiction over it.

That outsized influence is also a risk. When a single catalog run by a single agency becomes the reference point for patch prioritization worldwide, a delay, an omission, or a misclassification in that catalog ripples across every organization that has built automated tooling around it. BOD 26-04’s four-factor model adds complexity to that pipeline at exactly the moment more of the world is depending on it.

Industry Reaction to the BOD 26-04 Rollout

Reaction from the security vendor community has been largely favorable toward the direction of BOD 26-04, even as some flag execution risk. Cloud Security Alliance’s research note frames the three-day deadline for the highest-risk tier as a meaningful tightening compared to the CVSS-driven windows of BOD 19-02 and the KEV-driven windows of BOD 22-01. Nozomi Networks has positioned the directive as a consolidation move, replacing overlapping older policies with a single risk-weighted framework rather than layering a new rule on top of the old ones. Zafran’s commentary frames the shift as the end of a patch-everything era in federal vulnerability management, arguing that treating every KEV entry identically wasted scarce remediation capacity on lower-risk bugs while higher-risk ones waited in the same queue.

The open question is implementation. A four-factor risk model requires CISA to consistently and quickly assess public exposure, automatability, and technical impact for every new KEV candidate, on top of confirming active exploitation in the first place. That is a heavier analytical lift than a flat 14-to-21-day rule, and any inconsistency in how the four factors get scored could undercut the credibility of the tiering system just as it starts driving real deadlines like the ones applied to this month’s JFrog and PaperCut entries.

What Security Teams Should Do Now

Organizations running any of the affected products, Citrix NetScaler, Linux kernel builds, Gitea, ownCloud, Red Hat utilities, Microsoft SQL Server, JFrog Artifactory, or PaperCut, should treat KEV inclusion as a trigger for immediate patch verification rather than routine backlog triage. The practical steps are straightforward even if the underlying policy is new. Confirm which of the newly added CVEs apply to your environment by cross-referencing asset inventories against the vendor and version list. Check CISA’s KEV catalog feed directly for the specific due date assigned to each applicable CVE, since reported deadlines vary across the tracking sites covering this wave. Container and cloud teams should also revisit recent CVE waves affecting orchestration platforms, including the Kubernetes ingress-nginx flaw and the broader AKS CVE wave reported earlier this year, since exposure logic under BOD 26-04 applies just as much to cluster-facing services as it does to the vendors in this batch. Prioritize internet-facing and build-pipeline systems first, since those meet the “public exposure” criterion that pushes a CVE toward BOD 26-04’s fastest tier. And treat legacy systems running years-old software, like the Red Hat utilities in this batch, as equally in scope: a 2015 disclosure date does not mean a vulnerability is retired from active exploitation.

For organizations outside the federal government that are not legally bound by BOD 26-04, the more useful move is to adopt its logic voluntarily. A four-factor risk screen, exposure, KEV status, automatability, technical impact, is a reasonable internal patch-prioritization framework regardless of whether a regulator requires it, and it is considerably more defensible to auditors and boards than an ad hoc backlog with no stated priority order.

Predictions: Where KEV Policy Goes From Here

Several trends look likely to continue through the rest of 2026 and into 2027 based on the trajectory visible in this data. First, expect the pace of KEV additions to keep climbing rather than plateau, following the pattern of 23 additions in June alone and repeated multi-CVE batches through July, August, and September. Second, expect more three-day-tier designations as CISA gains operational experience applying the four-factor BOD 26-04 model, particularly for internet-facing software with a history of mass scanning, the category NetScaler and Artifactory both fall into. Third, expect non-federal organizations, especially in critical infrastructure and large enterprise IT, to informally adopt BOD 26-04’s tiering logic even without a legal mandate, mirroring how BOD 22-01’s KEV deadlines became a de facto industry benchmark over the past several years. Fourth, expect continued reappearance of pre-2020 CVEs in fresh KEV batches, since unpatched legacy infrastructure remains a reliable target for opportunistic scanning regardless of how old the underlying flaw is. Fifth, expect growing scrutiny of software-supply-chain infrastructure specifically, given that JFrog Artifactory, Gitea, and ownCloud all sit upstream of downstream systems that inherit their risk automatically.

The Bigger Picture for Vulnerability Management in 2026

The September KEV wave is, on its surface, a routine catalog update: a dozen CVEs, eight vendors, a mix of new and decade-old bugs. What makes it worth tracking closely is the policy machinery now processing it. BOD 26-04 represents the most significant change to federal vulnerability remediation policy since KEV itself launched under BOD 22-01 in 2021, and the CVEs added this month are among the first real test cases for whether a risk-tiered deadline system can move faster than a flat one without breaking down under its own complexity. JFrog’s CVE-2026-82329 going from unlisted to KEV-confirmed in the span of a single report cycle is a small but concrete data point in that test. More will follow through the rest of the year.

Frequently Asked Questions

What is the CISA Known Exploited Vulnerabilities catalog?
It is a list, maintained by the Cybersecurity and Infrastructure Security Agency, of CVEs that CISA has confirmed are being actively exploited in real-world attacks, as opposed to vulnerabilities that are merely theoretically dangerous. Federal Civilian Executive Branch agencies are legally required to patch listed vulnerabilities by an assigned deadline. It sits alongside a broader set of security news and vulnerability coverage this outlet tracks throughout the year.

What CVEs were added to the CISA KEV catalog in early September 2026?
Reported additions across this wave include CVE-2026-81578 and CVE-2026-82078 in PaperCut, CVE-2026-82329 in JFrog Artifactory, CVE-2026-53362 in the Linux kernel, CVE-2023-49105 in ownCloud, CVE-2026-8452 in Citrix NetScaler, CVE-2026-60004 in Gitea, CVE-2022-0995 in the Linux kernel, CVE-2019-1068 in Microsoft SQL Server, CVE-2015-5287 and CVE-2015-3246 in Red Hat utilities, and CVE-2021-23758 in Ajax.NET Professional.

What is BOD 26-04?
Binding Operational Directive 26-04 is a CISA policy issued June 10, 2026 that replaces the fixed remediation deadlines of BOD 22-01 with a risk-based tiered system. It scores vulnerabilities on public exposure, KEV status, automatability, and technical impact, with the highest-risk tier carrying a three-calendar-day patch deadline.

How is BOD 26-04 different from BOD 22-01?
BOD 22-01, issued in November 2021, assigned every KEV entry a fixed due date, typically in the 14-to-21-day range, regardless of how the vulnerability was actually being exploited. BOD 26-04 instead applies a four-factor risk model that can compress the deadline to three days for the most dangerous, exposed, and easily automated vulnerabilities, while less urgent ones may still get longer windows.

Does BOD 26-04 apply to private companies?
No. Like its predecessors, BOD 26-04 is legally binding only for Federal Civilian Executive Branch agencies. Private companies and state and local governments are not required to follow it, though many voluntarily mirror CISA’s KEV deadlines as an internal patch-prioritization benchmark.

What is the difference between CVSS, EPSS, and the KEV catalog?
CVSS measures a vulnerability’s theoretical severity on a 0-to-10 scale. EPSS, also maintained by FIRST.org, predicts the probability a CVE will be exploited within the next 30 days. The KEV catalog only lists vulnerabilities CISA has confirmed are already being exploited, making it the most conservative and evidence-based of the three systems.

Why are decade-old CVEs like CVE-2015-3246 showing up in 2026 KEV additions?
KEV additions reflect confirmed current exploitation activity, not the age of the underlying vulnerability. A CVE from 2015 can still be added in 2026 if CISA finds evidence that attackers are actively targeting unpatched, out-of-date systems still running the vulnerable code.

Where can I check the official, up-to-date CISA KEV catalog?
CISA publishes the authoritative catalog directly on cisa.gov in both a browsable format and machine-readable JSON and CSV feeds, which update multiple times daily and remain the primary source for exact CVE entries and remediation due dates.