Patch report · updated daily
Patch report
What to patch, in what order: actively exploited vulnerabilities, the latest Microsoft Patch Tuesday and new critical vulnerabilities from every vendor. Rebuilt automatically from official sources.
Last updated 03 Oct, 15:11 UTC · Next Patch Tuesday 13 Oct 2026
Exploited vulnerabilities added (30 days)
39
Patch these first
October 2026 Early Patch Tuesday
1
0 critical · 0 zero-days
New critical vulnerabilities (7 days)
26
CVSS 9.0 and above, all vendors
1 · Patch these first
Actively exploited vulnerabilities
Added to CISA's Known Exploited Vulnerabilities catalog in the last 30 days. Attackers are using these in real attacks — if you run any of these products, patch now.
- CVE-2026-102490
Added 2 Oct 2026
Zammad GmbH Zammad
Zammad GmbH Zammad Improper Privilege Management Vulnerability
CISA deadline 5 Oct 2026 - CVE-2026-102489
Added 2 Oct 2026
Zammad GmbH Zammad
Zammad GmbH Zammad Session Fixation Vulnerability
CISA deadline 5 Oct 2026 - CVE-2026-104286
Added 1 Oct 2026
Fortinet FortiMail
Fortinet FortiMail Path Traversal Vulnerability
CISA deadline 4 Oct 2026 - CVE-2026-76504
Added 30 Sept 2026
Cisco Catalyst SD-WAN Manager
Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
CISA deadline 3 Oct 2026 - CVE-2026-86950
Added 29 Sept 2026
Apple Multiple Products
Apple Multiple Products Out-of-Bounds Write Vulnerability
CISA deadline 2 Oct 2026 - CVE-2026-88772
Added 27 Sept 2026
Citrix NetScaler
Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
CISA deadline 30 Sept 2026 - CVE-2026-88771
Added 27 Sept 2026
Citrix NetScaler
Citrix NetScaler Improper Input Validation Vulnerability
CISA deadline 30 Sept 2026 - CVE-2026-67279
Added 25 Sept 2026
MikroTik RouterOS
Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
CISA deadline 28 Sept 2026 - CVE-2026-65660
Added 25 Sept 2026
Microsoft SharePoint
Microsoft SharePoint Code Injection Vulnerability
CISA deadline 28 Sept 2026 - CVE-2026-87902
Added 25 Sept 2026
WordPress Core
WordPress Core Remote File Inclusion Vulnerability
CISA deadline 28 Sept 2026 - CVE-2026-5430
Added 24 Sept 2026
WSO2 Multiple Products
WSO2 Multiple Products Path Traversal Vulnerability
CISA deadline 27 Sept 2026 - CVE-2026-71362
Added 24 Sept 2026
Adobe Commerce and Magento
Adobe Commerce and Magento Incorrect Authorization Vulnerability
CISA deadline 27 Sept 2026 - CVE-2026-93952
Added 22 Sept 2026
Arista VeloCloud Orchestrator
Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
CISA deadline 25 Sept 2026 - CVE-2026-94127
Added 22 Sept 2026
F5 BIG-IP APM
F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
CISA deadline 25 Sept 2026 - CVE-2026-93616
Added 22 Sept 2026
Check Point Multiple Products
Check Point Multiple Products Path Traversal Vulnerability
CISA deadline 25 Sept 2026 - CVE-2026-85102
Added 22 Sept 2026
Check Point Multiple Products
Check Point Multiple Products Improper Certificate Validation Vulnerability
CISA deadline 25 Sept 2026 - CVE-2026-7273
Added 21 Sept 2026
Zyxel GS1900 Series Switches
Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
CISA deadline 24 Sept 2026 - CVE-2025-39964
Added 18 Sept 2026
Linux Kernel
Linux Kernel Race Condition Vulnerability
CISA deadline 21 Sept 2026 - CVE-2026-53266
Added 18 Sept 2026
Linux Kernel
Linux Kernel Out-of-Bounds Write Vulnerability
CISA deadline 21 Sept 2026 - CVE-2025-39682
Added 18 Sept 2026
Linux Kernel
Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
CISA deadline 21 Sept 2026 - CVE-2026-58704
Added 16 Sept 2026
Google Pixel
Google Pixel Improper Authorization Vulnerability
CISA deadline 19 Sept 2026 - CVE-2026-76460
Added 16 Sept 2026
Cisco Identity Services Engine
Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
CISA deadline 19 Sept 2026 - CVE-2026-87886
Added 16 Sept 2026
Acronis Backup
Acronis Backup Incorrect Default Permissions Vulnerability
CISA deadline 19 Sept 2026 - CVE-2026-76461
Added 14 Sept 2026
Cisco Secure Email Gateway
Cisco Secure Email Gateway SQL Injection Vulnerability
CISA deadline 17 Sept 2026 - CVE-2026-84869
Added 11 Sept 2026
ConnectWise ScreenConnect
ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
CISA deadline 14 Sept 2026 - CVE-2026-42016
Added 11 Sept 2026
JFrog Artifactory
JFrog Artifactory Incorrect Authorization Vulnerability
CISA deadline 25 Sept 2026 - CVE-2026-42018
Added 11 Sept 2026
JFrog Artifactory
JFrog Artifactory Improper Authentication Vulnerability
CISA deadline 25 Sept 2026 - CVE-2026-85706
Added 11 Sept 2026
GitLab Community Edition and Enterprise Edition
GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
CISA deadline 14 Sept 2026 - CVE-2026-86060
Added 10 Sept 2026
MikroTik RouterOS
MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
CISA deadline 13 Sept 2026 - CVE-2026-67277
Added 10 Sept 2026
MikroTik RouterOS
MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
CISA deadline 13 Sept 2026 - CVE-2026-19490
Added 9 Sept 2026
Citrix NetScaler
Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
CISA deadline 12 Sept 2026 - CVE-2025-25249
Added 9 Sept 2026
Fortinet Multiple Products
Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
CISA deadline 12 Sept 2026 - CVE-2026-87491
Added 9 Sept 2026
Google Chromium V8
Google Chromium V8 Out of Bounds Write Vulnerability
CISA deadline 23 Sept 2026 - CVE-2026-20079
Added 9 Sept 2026
Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
CISA deadline 12 Sept 2026 - CVE-2026-75650
Added 8 Sept 2026
Adobe Commerce and Magento
Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
CISA deadline 11 Sept 2026 - CVE-2026-81963
Added 8 Sept 2026
Microsoft Windows
Microsoft Windows Link Following Vulnerability
CISA deadline 22 Sept 2026 - CVE-2026-86218
Added 8 Sept 2026
N-able N-central
N-able N-central Static Code Injection Vulnerability
CISA deadline 11 Sept 2026 - CVE-2026-85880
Added 8 Sept 2026
Microsoft Windows
Microsoft Windows Heap-Based Buffer Overflow Vulnerability
CISA deadline 22 Sept 2026 - CVE-2026-85046
Added 4 Sept 2026
Google Chromium V8
Google Chromium V8 Type Confusion Vulnerability
CISA deadline 18 Sept 2026
2 · Microsoft
October 2026 Early Patch Tuesday
Released 2 Oct 2026: 1 vulnerabilities that need updates installed — 0 critical, 1 important.
Zero-days (exploited before the patch)
No exploited zero-days in this release.
Highest-rated critical fixes
No critical vulnerabilities in this release.
By impact: Elevation of Privilege (1)
3 · All vendors
New critical vulnerabilities this week
Published to the US National Vulnerability Database in the last 7 days with a CVSS score of 9.0 or higher. Exploited ones are listed first.
- CVE-2026-88771
Published 27 Sept 2026
Citrix NetScaler ADC
Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before…
CVSS 9.8Exploited - CVE-2026-102489
Published 30 Sept 2026
Zammad GmbH Zammad
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to…
CVSS 9.8Exploited - CVE-2026-102490
Published 30 Sept 2026
Zammad GmbH Zammad
All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
CVSS 9.8Exploited - CVE-2026-88773
Published 27 Sept 2026
Citrix NetScaler ADC
Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS,…
CVSS 10.0 - CVE-2026-101072
Published 28 Sept 2026
Netcore NR289-GE
A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.cgi of the component CGI Handler. Such manipulation of the argument ip leads to os command injection. The attack can…
CVSS 10.0 - CVE-2026-101077
Published 28 Sept 2026
Netcore NR289-GE
A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp Handler. This manipulation causes missing authentication. The attack is possible to be carried out remotely. The…
CVSS 10.0 - CVE-2026-102427
Published 30 Sept 2026
ordasoft.com OrdaSoft Joomla CCK
Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or…
CVSS 10.0 - CVE-2026-101038
Published 28 Sept 2026
FAST FAC1200R
A vulnerability was determined in FAST FAC1200R 5.0_20201119_1.0.2. Affected by this vulnerability is the function MmtAtePrase of the component MmtAtePrase Parser. This manipulation causes stack-based buffer overflow. Remote…
CVSS 9.9 - CVE-2026-82041
Published 2 Oct 2026
UTMStack UTMStack
UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role check or command allowlist is applied…
CVSS 9.9 - CVE-2026-88775
Published 27 Sept 2026
Citrix NetScaler ADC
Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37…
CVSS 9.8 - CVE-2026-88776
Published 27 Sept 2026
Citrix NetScaler ADC
Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway:…
CVSS 9.8 - CVE-2026-88777
Published 27 Sept 2026
Citrix NetScaler ADC
Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway:…
CVSS 9.8 - CVE-2026-100255
Published 30 Sept 2026
JetBrains TeamCity
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset
CVSS 9.8 - CVE-2026-100273
Published 30 Sept 2026
JetBrains YouTrack
In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution
CVSS 9.8 - CVE-2026-100277
Published 30 Sept 2026
JetBrains YouTrack
In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature
CVSS 9.8 - CVE-2026-14378
Published 2 Oct 2026
dplugins DevKit Pro
The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled…
CVSS 9.8 - CVE-2026-19660
Published 2 Oct 2026
DiviEngine Divi Membership
The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param`…
CVSS 9.8 - CVE-2026-97637
Published 2 Oct 2026
parorrey JSON API Auth
The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in all versions up to, and including, 3.1.2. The vulnerability exists because the required PI-Media/json-api parent…
CVSS 9.8 - CVE-2026-19652
Published 2 Oct 2026
DiviEngine Divi Membership
The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress…
CVSS 9.8 - CVE-2023-54405
Published 2 Oct 2026
H3C CVM
H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary file upload vulnerability in the /cas/fileUpload/upload endpoint that allows remote attackers to write arbitrary…
CVSS 9.8 - CVE-2026-82042
Published 2 Oct 2026
UTMStack UTMStack
UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable…
CVSS 9.8 - CVE-2026-89134
Published 27 Sept 2026
wolfSSL wolfSSL
A certificate with no dNSName SAN but another SAN type present (e.g. registeredID or iPAddress) bypassed the Subject CN dNSName name-constraint check. The CN-as-DNS fallback was gated on cert->subjectCN != NULL && cert->altNames == NULL…
CVSS 9.1 - CVE-2026-101081
Published 28 Sept 2026
D-Link DI-8400
A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the file menu_nat_more.asp of the component Web Administration Service. The manipulation of the argument opt…
CVSS 9.1 - CVE-2026-87115
Published 3 Oct 2026
e4jvikwp VikAppointments Services Booking Calendar
The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and including, 1.2.21. This makes it…
CVSS 9.1 - CVE-2026-92084
Published 3 Oct 2026
beaverbuilder Beaver Builder Page Builder – Drag and Drop Website Builder
The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to…
CVSS 9.1
Showing 25 of 26, exploited and highest-scored first.
Not sure which of these affect you? A vulnerability assessment finds them, and managed patching closes them.
FAQ
About this patch report
What is Patch Tuesday?
Patch Tuesday is the second Tuesday of every month, when Microsoft releases security updates for Windows, Office, Exchange, Azure and its other products. Other vendors such as Adobe and SAP often release on the same day. This report summarises the latest release: how many vulnerabilities were fixed, which are critical, and which were already being exploited (zero-days).
Which patches should I install first?
Start with anything in the 'Patch these first' list. Those vulnerabilities are on CISA's Known Exploited Vulnerabilities catalog, which means attackers are using them in real attacks. Then install Microsoft zero-days and critical updates, then critical vulnerabilities in internet-facing products such as firewalls, VPNs and remote access gateways.
How often is this patch report updated?
Automatically, several times a day. The page reads the CISA Known Exploited Vulnerabilities catalog, Microsoft's Security Update Guide and the US National Vulnerability Database, and rebuilds itself every 6 hours. No one edits it by hand.
How quickly should critical patches be installed?
Exploited vulnerabilities on internet-facing systems should be patched within days, not weeks; CISA gives US federal agencies two to three weeks at most, and often less. A common baseline for businesses is 14 days for critical patches and 30 days for everything else, with emergency patching for active zero-days.
Can Techx4u patch our systems for us?
Yes. Our managed patch management service tests and deploys Windows, Linux, third-party application and firmware updates on a schedule, handles emergency patches for zero-days, and gives you a monthly compliance report showing every device's patch status.
Sources: CISA Known Exploited Vulnerabilities catalog, Microsoft Security Response Center (Security Update Guide API) and NIST National Vulnerability Database. This product uses data from the NVD API but is not endorsed or certified by the NVD.

Want patching handled for you?
We test and deploy Windows, Linux, third-party and firmware updates on schedule, rush zero-day fixes, and send you a monthly patch compliance report.
