Last checked: 28 September 2026. This edition brings together the ten newest entries visible on CISA’s alerts and advisories listing, all eight September announcements on NIST’s CSRC news listing, CISA’s weekly-bulletin change and the latest NVD technical update. It is a dated digest of these official sources, not an exhaustive global news feed or an automatically updating service.
Start here: administrators should review the active-exploitation alerts first. Students, developers and business readers can jump to the NIST guidance and learning opportunities below. Publication dates, draft status and event dates are identified separately.
- Active threats and CISA’s newest alerts
- NIST guidance and research
- NVD technical update
- Official sources to follow
Active threats and CISA updates
1. NetScaler: critical vulnerabilities under active exploitation
CISA alert · 27 September 2026. CISA reports eight newly disclosed vulnerabilities in Citrix NetScaler ADC and Gateway. Two—CVE-2026-88771 and CVE-2026-88772—can independently enable remote code execution and are being exploited globally, according to CISA.
For administrators: review the vendor’s affected-version and remediation guidance promptly. CISA advises checking for signs of compromise before patching where possible; if compromise is suspected, preserve forensic evidence because updating may reduce forensic visibility. A patch alone should not be treated as proof that an earlier compromise has been resolved.
Read CISA’s NetScaler alert and vendor links.
2–9. Eight KEV announcements covering 15 vulnerabilities
CISA added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of exploitation. The dates below are the announcement dates, not necessarily the original disclosure dates. Match each entry to your actual software, version and exposure; follow the catalog and vendor guidance for remediation details.
- 27 September — Citrix NetScaler: CVE-2026-88771 and CVE-2026-88772. These are the two exploited flaws in the alert above, not two additional flaws. Official KEV announcement.
- 25 September — WordPress Core: CVE-2026-87902, a remote file inclusion vulnerability. Website administrators should compare their installation with the official affected-version and update guidance. This listing alone does not establish whether any particular website is affected. Official KEV announcement.
- 25 September — SharePoint and RouterOS: CVE-2026-65660 affects Microsoft SharePoint; CVE-2026-67279 affects MikroTik RouterOS. Official KEV announcement.
- 24 September — WSO2 and Adobe commerce software: CVE-2026-5430 affects multiple WSO2 products; CVE-2026-71362 affects Adobe Commerce and Magento. Official KEV announcement.
- 22 September — network and access infrastructure: CVE-2026-85102 and CVE-2026-93616 affect Check Point products; CVE-2026-93952 affects Arista VeloCloud Orchestrator; CVE-2026-94127 affects F5 BIG-IP APM. Official KEV announcement.
- 21 September — Zyxel switches: CVE-2026-7273 affects the GS1900 series. Official KEV announcement.
- 18 September — Linux kernel: CVE-2025-39682 was added in a separate announcement. Official KEV announcement.
- 18 September — two more Linux kernel entries: CVE-2025-39964 and CVE-2026-53266. Linux users should follow their distribution or device vendor’s applicable security updates. Official KEV announcement.
10. Review third-party access to industrial systems
CISA and FBI fact sheet · 23 September 2026. New guidance examines the risks introduced by industrial control system integrators. It encourages operators to limit access to what a supplier actually needs, understand where operational data is stored, monitor remote connections and maintain the ability to recover or operate independently.
Practical takeaway: document integrator access, supplied hardware and software, remote-support arrangements and recovery responsibilities. Coordinate changes with the people responsible for operational safety. Read the official fact sheet.
11. CISA’s weekly Vulnerability Bulletin is ending
Announced 16 September · effective 28 September 2026. CISA says it will discontinue its weekly Vulnerability Bulletin as it shifts toward risk-based prioritisation. Its KEV Catalog and cybersecurity alerts and advisories remain available.
For existing subscribers: CISA recommends selecting the KEV Catalog and Cybersecurity Advisories topics in subscription preferences and consulting vendor advisories directly. Read CISA’s official subscriber announcement.
NIST guidance, research and learning
12. Threshold cryptography talks: dates for your calendar
Announced 25 September 2026 · upcoming event. NIST’s virtual Threshold Call Preview Talks #3 are scheduled for 30 September and 6–7 October 2026. Topics include fully homomorphic encryption, zero-knowledge proofs and threshold cryptographic operations. Researchers and advanced students can use the official agenda to choose relevant sessions. Announcement and registration details.
13. Operational technology security guide: new draft
21 September 2026 · initial public draft. NIST SP 800-82 Revision 4 addresses security for systems that monitor or control physical processes. The revision aligns its structure with CSF 2.0 and expands discussion of asset management, monitoring and security architecture while recognising OT performance, reliability and safety needs.
For OT teams: review the draft against your environment and consider submitting feedback by 30 November 2026. It is not yet final guidance. Read NIST’s draft announcement.
14. O-RAN cybersecurity profile for federal agencies
17 September 2026 · draft IR 8623. NIST maps O-RAN security specifications to Cybersecurity Framework 2.0 outcomes for federal deployments. Network and risk teams can review the mapping and supporting references; the comment period runs through 2 November 2026. Read the official draft announcement.
15. A small-business primer for security assessments
16 September 2026 · published SP 1352. NIST’s new primer introduces assessment concepts and planning for organisations implementing SP 800-171 Revision 3 to protect controlled unclassified information. It is aimed at business leaders and staff preparing for self-assessment or external assessors. Read NIST’s primer announcement.
16. Protect identity and access tokens
15 September 2026 · final IR 8587. NIST and CISA have finalised recommendations for protecting tokens and identity assertions against theft, forgery and misuse. The guidance addresses cloud providers and customers, with revised key-protection advice and additional references for token revocation and related controls.
For developers and identity teams: use the report to review how services protect signing keys and handle tokens. The report also touches on AI and post-quantum migration at a high level. Read NIST’s official announcement.
17. Supply-chain traceability framework finalised
9 September 2026 · final IR 8536. NIST’s NCCoE has published a framework for exchanging and verifying manufacturing traceability information across organisations and industries. It aims to improve the ability to check product provenance while supporting existing standards. Supply-chain teams can review how its principles fit their current records and supplier processes. Read the official release.
18. Storage encryption: XTS-AES revision open for review
3 September 2026 · draft SP 800-38E Revision 1. The proposed revision updates its IEEE specification reference and clarifies the approved scope and requirements for XTS-AES storage confidentiality. This is a technical standards update for implementers, not a notice that every encrypted drive is vulnerable. Read the draft and comment instructions.
19. Hardware security: workshop findings published
1 September 2026 · IR 8615 workshop report. NIST summarises priorities from its January hardware-security workshop, including lifecycle security, supply-chain traceability, verification and workforce collaboration. The report records research and standards priorities; it is not a new product certification. Read the workshop report announcement.
20. Latest NVD technical update: affected products and SSVC
26 August 2026 · latest technical notice found on NIST’s NVD overview at this check. NIST describes adding affected-product data and Stakeholder-Specific Vulnerability Categorization (SSVC) information to CVE detail pages. It also changes affected-data audit-history entries to carry a direct GitHub CVE-record link instead of repeating the full affected-data payload. The current CVE detail endpoint continues to return the latest full affected data.
For tool builders: check how your history-feed parser handles these links and keep current CVE data separate from change-history references. Read the current NVD technical notices.
Keep the official sources close
- NVD News archive — the requested reference page contains older announcements; check the dates.
- Current NVD overview and technical updates.
- NIST CSRC news and publication announcements.
- CISA alerts and advisories.
- CISA Known Exploited Vulnerabilities Catalog.
How to use this edition: identify products you operate, read the linked official advisory, and check the vendor’s current affected-version and remediation instructions. An article’s publication date is not a patch deadline. Guidance, affected versions and remediation details may change after this review.
Summaries are written by MVR from the linked official sources. Practical takeaways are editorial guidance, not quotations or endorsements by NIST or CISA.
Explore more ideas in Technology, or read how we approach our content.



