Skip to main content
Techx4u Pvt Ltd

Patch report · updated daily

Patch report

What to patch, in what order: actively exploited vulnerabilities, the latest Microsoft Patch Tuesday and new critical vulnerabilities from every vendor. Rebuilt automatically from official sources.

Last updated 03 Oct, 15:11 UTC · Next Patch Tuesday 13 Oct 2026

Exploited vulnerabilities added (30 days)

39

Patch these first

October 2026 Early Patch Tuesday

1

0 critical · 0 zero-days

New critical vulnerabilities (7 days)

26

CVSS 9.0 and above, all vendors

1 · Patch these first

Actively exploited vulnerabilities

Added to CISA's Known Exploited Vulnerabilities catalog in the last 30 days. Attackers are using these in real attacks — if you run any of these products, patch now.

  • CVE-2026-102490

    Added 2 Oct 2026

    Zammad GmbH Zammad

    Zammad GmbH Zammad Improper Privilege Management Vulnerability

    CISA deadline 5 Oct 2026
  • CVE-2026-102489

    Added 2 Oct 2026

    Zammad GmbH Zammad

    Zammad GmbH Zammad Session Fixation Vulnerability

    CISA deadline 5 Oct 2026
  • CVE-2026-104286

    Added 1 Oct 2026

    Fortinet FortiMail

    Fortinet FortiMail Path Traversal Vulnerability

    CISA deadline 4 Oct 2026
  • CVE-2026-76504

    Added 30 Sept 2026

    Cisco Catalyst SD-WAN Manager

    Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability

    CISA deadline 3 Oct 2026
  • CVE-2026-86950

    Added 29 Sept 2026

    Apple Multiple Products

    Apple Multiple Products Out-of-Bounds Write Vulnerability

    CISA deadline 2 Oct 2026
  • CVE-2026-88772

    Added 27 Sept 2026

    Citrix NetScaler

    Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

    CISA deadline 30 Sept 2026
  • CVE-2026-88771

    Added 27 Sept 2026

    Citrix NetScaler

    Citrix NetScaler Improper Input Validation Vulnerability

    CISA deadline 30 Sept 2026
  • CVE-2026-67279

    Added 25 Sept 2026

    MikroTik RouterOS

    Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

    CISA deadline 28 Sept 2026
  • CVE-2026-65660

    Added 25 Sept 2026

    Microsoft SharePoint

    Microsoft SharePoint Code Injection Vulnerability

    CISA deadline 28 Sept 2026
  • CVE-2026-87902

    Added 25 Sept 2026

    WordPress Core

    WordPress Core Remote File Inclusion Vulnerability

    CISA deadline 28 Sept 2026
  • CVE-2026-5430

    Added 24 Sept 2026

    WSO2 Multiple Products

    WSO2 Multiple Products Path Traversal Vulnerability

    CISA deadline 27 Sept 2026
  • CVE-2026-71362

    Added 24 Sept 2026

    Adobe Commerce and Magento

    Adobe Commerce and Magento Incorrect Authorization Vulnerability

    CISA deadline 27 Sept 2026
  • CVE-2026-93952

    Added 22 Sept 2026

    Arista VeloCloud Orchestrator

    Arista VeloCloud Orchestrator Improper Input Validation Vulnerability

    CISA deadline 25 Sept 2026
  • CVE-2026-94127

    Added 22 Sept 2026

    F5 BIG-IP APM

    F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

    CISA deadline 25 Sept 2026
  • CVE-2026-93616

    Added 22 Sept 2026

    Check Point Multiple Products

    Check Point Multiple Products Path Traversal Vulnerability

    CISA deadline 25 Sept 2026
  • CVE-2026-85102

    Added 22 Sept 2026

    Check Point Multiple Products

    Check Point Multiple Products Improper Certificate Validation Vulnerability

    CISA deadline 25 Sept 2026
  • CVE-2026-7273

    Added 21 Sept 2026

    Zyxel GS1900 Series Switches

    Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability

    CISA deadline 24 Sept 2026
  • CVE-2025-39964

    Added 18 Sept 2026

    Linux Kernel

    Linux Kernel Race Condition Vulnerability

    CISA deadline 21 Sept 2026
  • CVE-2026-53266

    Added 18 Sept 2026

    Linux Kernel

    Linux Kernel Out-of-Bounds Write Vulnerability

    CISA deadline 21 Sept 2026
  • CVE-2025-39682

    Added 18 Sept 2026

    Linux Kernel

    Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

    CISA deadline 21 Sept 2026
  • CVE-2026-58704

    Added 16 Sept 2026

    Google Pixel

    Google Pixel Improper Authorization Vulnerability

    CISA deadline 19 Sept 2026
  • CVE-2026-76460

    Added 16 Sept 2026

    Cisco Identity Services Engine

    Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

    CISA deadline 19 Sept 2026
  • CVE-2026-87886

    Added 16 Sept 2026

    Acronis Backup

    Acronis Backup Incorrect Default Permissions Vulnerability

    CISA deadline 19 Sept 2026
  • CVE-2026-76461

    Added 14 Sept 2026

    Cisco Secure Email Gateway

    Cisco Secure Email Gateway SQL Injection Vulnerability

    CISA deadline 17 Sept 2026
  • CVE-2026-84869

    Added 11 Sept 2026

    ConnectWise ScreenConnect

    ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

    CISA deadline 14 Sept 2026
  • CVE-2026-42016

    Added 11 Sept 2026

    JFrog Artifactory

    JFrog Artifactory Incorrect Authorization Vulnerability

    CISA deadline 25 Sept 2026
  • CVE-2026-42018

    Added 11 Sept 2026

    JFrog Artifactory

    JFrog Artifactory Improper Authentication Vulnerability

    CISA deadline 25 Sept 2026
  • CVE-2026-85706

    Added 11 Sept 2026

    GitLab Community Edition and Enterprise Edition

    GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability

    CISA deadline 14 Sept 2026
  • CVE-2026-86060

    Added 10 Sept 2026

    MikroTik RouterOS

    MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

    CISA deadline 13 Sept 2026
  • CVE-2026-67277

    Added 10 Sept 2026

    MikroTik RouterOS

    MikroTik RouterOS Missing Authentication for Critical Function Vulnerability

    CISA deadline 13 Sept 2026
  • CVE-2026-19490

    Added 9 Sept 2026

    Citrix NetScaler

    Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability

    CISA deadline 12 Sept 2026
  • CVE-2025-25249

    Added 9 Sept 2026

    Fortinet Multiple Products

    Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability

    CISA deadline 12 Sept 2026
  • CVE-2026-87491

    Added 9 Sept 2026

    Google Chromium V8

    Google Chromium V8 Out of Bounds Write Vulnerability

    CISA deadline 23 Sept 2026
  • CVE-2026-20079

    Added 9 Sept 2026

    Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management

    Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

    CISA deadline 12 Sept 2026
  • CVE-2026-75650

    Added 8 Sept 2026

    Adobe Commerce and Magento

    Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

    CISA deadline 11 Sept 2026
  • CVE-2026-81963

    Added 8 Sept 2026

    Microsoft Windows

    Microsoft Windows Link Following Vulnerability

    CISA deadline 22 Sept 2026
  • CVE-2026-86218

    Added 8 Sept 2026

    N-able N-central

    N-able N-central Static Code Injection Vulnerability

    CISA deadline 11 Sept 2026
  • CVE-2026-85880

    Added 8 Sept 2026

    Microsoft Windows

    Microsoft Windows Heap-Based Buffer Overflow Vulnerability

    CISA deadline 22 Sept 2026
  • CVE-2026-85046

    Added 4 Sept 2026

    Google Chromium V8

    Google Chromium V8 Type Confusion Vulnerability

    CISA deadline 18 Sept 2026

2 · Microsoft

October 2026 Early Patch Tuesday

Released 2 Oct 2026: 1 vulnerabilities that need updates installed — 0 critical, 1 important.

Zero-days (exploited before the patch)

No exploited zero-days in this release.

Highest-rated critical fixes

No critical vulnerabilities in this release.

By impact: Elevation of Privilege (1)

3 · All vendors

New critical vulnerabilities this week

Published to the US National Vulnerability Database in the last 7 days with a CVSS score of 9.0 or higher. Exploited ones are listed first.

  • CVE-2026-88771

    Published 27 Sept 2026

    Citrix NetScaler ADC

    Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before…

    CVSS 9.8Exploited
  • CVE-2026-102489

    Published 30 Sept 2026

    Zammad GmbH Zammad

    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to…

    CVSS 9.8Exploited
  • CVE-2026-102490

    Published 30 Sept 2026

    Zammad GmbH Zammad

    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

    CVSS 9.8Exploited
  • CVE-2026-88773

    Published 27 Sept 2026

    Citrix NetScaler ADC

    Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS,…

    CVSS 10.0
  • CVE-2026-101072

    Published 28 Sept 2026

    Netcore NR289-GE

    A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.cgi of the component CGI Handler. Such manipulation of the argument ip leads to os command injection. The attack can…

    CVSS 10.0
  • CVE-2026-101077

    Published 28 Sept 2026

    Netcore NR289-GE

    A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp Handler. This manipulation causes missing authentication. The attack is possible to be carried out remotely. The…

    CVSS 10.0
  • CVE-2026-102427

    Published 30 Sept 2026

    ordasoft.com OrdaSoft Joomla CCK

    Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or…

    CVSS 10.0
  • CVE-2026-101038

    Published 28 Sept 2026

    FAST FAC1200R

    A vulnerability was determined in FAST FAC1200R 5.0_20201119_1.0.2. Affected by this vulnerability is the function MmtAtePrase of the component MmtAtePrase Parser. This manipulation causes stack-based buffer overflow. Remote…

    CVSS 9.9
  • CVE-2026-82041

    Published 2 Oct 2026

    UTMStack UTMStack

    UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role check or command allowlist is applied…

    CVSS 9.9
  • CVE-2026-88775

    Published 27 Sept 2026

    Citrix NetScaler ADC

    Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37…

    CVSS 9.8
  • CVE-2026-88776

    Published 27 Sept 2026

    Citrix NetScaler ADC

    Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway:…

    CVSS 9.8
  • CVE-2026-88777

    Published 27 Sept 2026

    Citrix NetScaler ADC

    Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway:…

    CVSS 9.8
  • CVE-2026-100255

    Published 30 Sept 2026

    JetBrains TeamCity

    In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset

    CVSS 9.8
  • CVE-2026-100273

    Published 30 Sept 2026

    JetBrains YouTrack

    In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution

    CVSS 9.8
  • CVE-2026-100277

    Published 30 Sept 2026

    JetBrains YouTrack

    In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature

    CVSS 9.8
  • CVE-2026-14378

    Published 2 Oct 2026

    dplugins DevKit Pro

    The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled…

    CVSS 9.8
  • CVE-2026-19660

    Published 2 Oct 2026

    DiviEngine Divi Membership

    The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param`…

    CVSS 9.8
  • CVE-2026-97637

    Published 2 Oct 2026

    parorrey JSON API Auth

    The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in all versions up to, and including, 3.1.2. The vulnerability exists because the required PI-Media/json-api parent…

    CVSS 9.8
  • CVE-2026-19652

    Published 2 Oct 2026

    DiviEngine Divi Membership

    The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress…

    CVSS 9.8
  • CVE-2023-54405

    Published 2 Oct 2026

    H3C CVM

    H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary file upload vulnerability in the /cas/fileUpload/upload endpoint that allows remote attackers to write arbitrary…

    CVSS 9.8
  • CVE-2026-82042

    Published 2 Oct 2026

    UTMStack UTMStack

    UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable…

    CVSS 9.8
  • CVE-2026-89134

    Published 27 Sept 2026

    wolfSSL wolfSSL

    A certificate with no dNSName SAN but another SAN type present (e.g. registeredID or iPAddress) bypassed the Subject CN dNSName name-constraint check. The CN-as-DNS fallback was gated on cert->subjectCN != NULL && cert->altNames == NULL…

    CVSS 9.1
  • CVE-2026-101081

    Published 28 Sept 2026

    D-Link DI-8400

    A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the file menu_nat_more.asp of the component Web Administration Service. The manipulation of the argument opt…

    CVSS 9.1
  • CVE-2026-87115

    Published 3 Oct 2026

    e4jvikwp VikAppointments Services Booking Calendar

    The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and including, 1.2.21. This makes it…

    CVSS 9.1
  • CVE-2026-92084

    Published 3 Oct 2026

    beaverbuilder Beaver Builder Page Builder – Drag and Drop Website Builder

    The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to…

    CVSS 9.1

Showing 25 of 26, exploited and highest-scored first.

Not sure which of these affect you? A vulnerability assessment finds them, and managed patching closes them.

FAQ

About this patch report

What is Patch Tuesday?

Patch Tuesday is the second Tuesday of every month, when Microsoft releases security updates for Windows, Office, Exchange, Azure and its other products. Other vendors such as Adobe and SAP often release on the same day. This report summarises the latest release: how many vulnerabilities were fixed, which are critical, and which were already being exploited (zero-days).

Which patches should I install first?

Start with anything in the 'Patch these first' list. Those vulnerabilities are on CISA's Known Exploited Vulnerabilities catalog, which means attackers are using them in real attacks. Then install Microsoft zero-days and critical updates, then critical vulnerabilities in internet-facing products such as firewalls, VPNs and remote access gateways.

How often is this patch report updated?

Automatically, several times a day. The page reads the CISA Known Exploited Vulnerabilities catalog, Microsoft's Security Update Guide and the US National Vulnerability Database, and rebuilds itself every 6 hours. No one edits it by hand.

How quickly should critical patches be installed?

Exploited vulnerabilities on internet-facing systems should be patched within days, not weeks; CISA gives US federal agencies two to three weeks at most, and often less. A common baseline for businesses is 14 days for critical patches and 30 days for everything else, with emergency patching for active zero-days.

Can Techx4u patch our systems for us?

Yes. Our managed patch management service tests and deploys Windows, Linux, third-party application and firmware updates on a schedule, handles emergency patches for zero-days, and gives you a monthly compliance report showing every device's patch status.

Sources: CISA Known Exploited Vulnerabilities catalog, Microsoft Security Response Center (Security Update Guide API) and NIST National Vulnerability Database. This product uses data from the NVD API but is not endorsed or certified by the NVD.

Want patching handled for you?

We test and deploy Windows, Linux, third-party and firmware updates on schedule, rush zero-day fixes, and send you a monthly patch compliance report.