CyberMax
Home › Blog
CISA added 13 exploited CVEs from 27 September to 8 October 2026, including three 10-year-old bugs

CISA added 13 exploited CVEs from 27 September to 8 October 2026, including three 10-year-old bugs

· by · 3 min read

CISA added 13 CVEs to its Known Exploited Vulnerabilities (KEV) catalog between 27 September and 8 October 2026 (catalog version 2026.10.08, 1,739 CVEs in total). None of the 13 is marked as known to be used in ransomware. Twelve have a federal due date three days after they were added; the Apple CVE has two weeks.

CVEVendor / productAddedFederal dueEPSS
CVE-2026-88771Citrix NetScaler27 Sep30 Sep1.1%
CVE-2026-88772Citrix NetScaler27 Sep30 Sep1.3%
CVE-2026-86950Apple (multiple products)29 Sep13 Oct1.2%
CVE-2026-76504Cisco Catalyst SD-WAN Manager30 Sep3 Oct1.8%
CVE-2026-104286Fortinet FortiMail1 Oct4 Oct2.2%
CVE-2026-102489Zammad2 Oct5 Oct1.3%
CVE-2026-102490Zammad2 Oct5 Oct0.6%
CVE-2026-88779Citrix NetScaler4 Oct7 Oct0.6%
CVE-2015-3306ProFTPD8 Oct11 Oct96.8%
CVE-2016-3081Apache Struts8 Oct11 Oct93.4%
CVE-2015-5477ISC BIND8 Oct11 Oct91.3%
CVE-2021-3199ONLYOFFICE Docs8 Oct11 Oct8.2%
CVE-2023-22894Strapi8 Oct11 Oct1.7%
EPSS of the CVEs CISA added 27 Sep – 8 Oct 2026
ProFTPD (2015): 96.8%ProFTPD (2015)96.8%Apache Struts (2016): 93.4%Apache Struts (2016)93.4%ISC BIND (2015): 91.3%ISC BIND (2015)91.3%ONLYOFFICE Docs: 8.2%ONLYOFFICE Docs8.2%Fortinet FortiMail: 2.2%Fortinet FortiMail2.2%Cisco SD-WAN Mgr: 1.8%Cisco SD-WAN Mgr1.8%Strapi: 1.7%Strapi1.7%Citrix NetScaler: 1.3%Citrix NetScaler1.3%

FIRST EPSS scores dated 8 Oct 2026: the estimated chance of exploitation activity in the next 30 days. Top 8 of the 13 additions; the highest NetScaler CVE is shown.

What stands out

Federal due dates bind US federal civilian agencies; for everyone else they are a useful order of work. Per-vendor lists: Microsoft, Cisco, Apple, all vendors.

Sources: CISA KEV catalog version 2026.10.08 and FIRST EPSS scores of 8 Oct 2026. EPSS is a probability estimate, not a confirmation of exploitation.

More from the CyberMax blog