CISA Put 43 Exploited Bugs on Its List in September, the Most in Any Month Since 2022. One Entry Still Carries a ChatGPT Tag.
CISA added 43 vulnerabilities to its Known Exploited Vulnerabilities catalog in September 2026. That is the most in any single month since June 2022. Thirty-five of the 43 came with a three-day federal remediation deadline. And one of them, the MikroTik RouterOS entry, links to the vendor's advisory with a URL that ends in ?utm_source=chatgpt.com.
We pulled the catalog this morning (version 2026.10.02, 1,733 entries) and recomputed every number below from CISA's own JSON. Here is what September actually looked like, what the ChatGPT tag does and does not mean, and the two entries that landed on the list in the first two days of October.
The month, by the numbers
September's 43 beat every month of the past year. The previous high in that span was 31, which happened three times (October, April and August). To find a busier month you have to go back to June 2022, at 48. The months above that in 2021 and early 2022 (291 in November 2021, 226 in March 2022) are not comparable: that was CISA back-filling the catalog with years of older bugs when it launched. Measured against the catalog as a steady-state feed, September is the high-water mark.
The vendor spread was wide, not concentrated. Cisco had four entries. Citrix, MikroTik, Microsoft, the Linux kernel, Google and JFrog had three each. Adobe, Check Point and SonicWall had two. No single vendor carried the month. Defenders who think of KEV as "patch Microsoft and Cisco" spent September patching a lot of other people too.
The deadline is three days now, and that is not new
Thirty-five of September's 43 entries had a due date three days after they were added. That continues a change we wrote up in CISA Has Not Issued a 21-Day Patch Deadline Since March. The median window has been three days every month since June, which is when the BOD 26-04 language first appears in the catalog (2026-06-11). We will not re-run that analysis here. The new part is volume: September is the first month where a three-day window met a record intake. If your process needs a change ticket, a maintenance window and a weekend, the arithmetic no longer works for federal agencies, and private shops that track KEV inherit the same pressure.
Two more fields are worth reading closely. First, CISA's newer forensicTriage flag, which first appears set to "Yes" on 2026-07-01, was "Yes" on 33 of September's 43 entries. That is close to as many as the 38 flagged across July and August combined. CISA is asking for forensic triage, not just patching, on most of what it adds now. Second, all 43 September entries list known ransomware use as "Unknown." That is the default for a new entry, not an all-clear. The catalog as a whole marks 361 entries as known ransomware vectors, and the flag tends to change after the fact.
The ChatGPT tag
The MikroTik entry is CVE-2026-67279, an SSH pre-authentication flaw in RouterOS: a client that asks for a key re-exchange can skip authentication, open a session channel and send an exec request. CISA added it on 2026-09-25 with a due date of 2026-09-28. The notes field links to MikroTik's advisory as https://mikrotik.com/supportsec/september-2026-vulnerability/?utm_source=chatgpt.com.
That suffix is the tag ChatGPT appends when a user clicks a link it cited. It is the only entry of the 1,733 in the catalog that carries one. What it tells you is narrow: somebody copied that URL out of a ChatGPT answer and pasted it into a federal catalog entry without trimming the tracking parameter. What it does not tell you is anything about the vulnerability. The bug is real. The CVE record cites CERT.pl's write-ups, one of which reports the RouterOS flaws as actively exploited. The tag is a clipboard artifact, not a sourcing problem.
It is still worth a sentence, for two reasons. AI assistants are now part of how analysts find vendor advisories, at the agency that sets everyone else's patch clock, and the tag is the first visible trace of that in the catalog. And there is a small mismatch the link does expose: MikroTik's advisory page names CVE-2026-67276, CVE-2026-86060 and CVE-2026-67277 under the "MikroTrick" codename, but not CVE-2026-67279, the CVE CISA catalogued. CISA's entry says 67279 chains into 86060. The CVE record ties them together through CERT.pl's write-ups, so the link is the right page, but a defender reading only MikroTik's advisory would not find the catalogued CVE number on it. MikroTik's fixed builds are 7.25 beta 3, 7.24.2, 7.23.4 and 6.49.21, and its own guidance is to keep SSH off the internet. Credit to the independent researcher who reverse-engineered the 7.23.4 fix MikroTik shipped without explanation; the write-up is cited in the CVE record.
Where we were on MikroTik: after CISA
Our exploit harvester indexed two public proof-of-concept repositories for CVE-2026-67279: HackSpeak/CVE-2026-67279 on 2026-09-26, and tc4dy/CVE-2026-67279-86060-Toolkit, which chains both CVEs, on 2026-09-27. CISA listed the bug on 2026-09-25. We were one and two days behind the catalog, not ahead of it. That is the honest timeline and we would rather say it than skip it.
The harvest also produced something we had to fix. Our extractor labeled ordinary text inside those PoCs as "SQL injection patterns" at 90 percent confidence: the word exec (from the SSH exec request), the word select (from Python's select module). It was not a MikroTik problem. It was ours, and it turned out to be most of that rule class. We corrected those records and the extractor today.
October started the same way
Two days into October, three more entries.
FortiMail, CVE-2026-104286, added 2026-10-01, due 2026-10-04. An unauthenticated attacker can write arbitrary files to the appliance with crafted HTTP or HTTPS requests. Fortinet's advisory, FG-IR-26-175, rates it 9.8, says it is exploited in the wild, and places it in the IBE (encrypted email) feature. Fixed builds are 8.0.2, 7.6.7 and 7.4.9 or later. There is no fix on the 7.2 branch; the advisory says to move to 7.4 or above. This is not FortiMail's first trip to the catalog. CVE-2025-32756 hit FortiMail along with FortiVoice and FortiNDR in May 2025.
Zammad, CVE-2026-102489 and CVE-2026-102490, both added 2026-10-02, due 2026-10-05. These are the first entries ever for Zammad, the open-source help desk. CISA describes a chain: a session fixation that leads to code execution as the zammad user, then a privilege escalation from that user to root. Zammad's own response, posted to its community forum on October 1, adds detail that matters. It says 102489 affects only Zammad 6.5 and older and is fixed in 7.2.0. On 102490, it says the reporter disclosed publicly two days after first contact and has not shared technical details with the vendor, so Zammad cannot yet confirm the scope. If you run Zammad, upgrade to 7.2.0 now and watch the project's GitHub advisories for 102490.
We hold no indicators of compromise and no harvested proofs of concept for either the FortiMail or the Zammad entries. Our honeypots emulate web applications, not mail appliances or help desks, so silence from our sensors on these is not evidence of anything.
What to do with this
Treat KEV as a three-day clock, because for federal agencies it is, and for everyone downstream of a federal contract it is becoming one. Read the forensicTriage flag as an instruction to look for compromise, not just to patch. Do not read "Unknown" ransomware use as safe. And when an entry's link takes you to a vendor page that does not name the CVE you came for, follow the CVE record's own references; that is where the MikroTik trail actually lives.
Every number above comes from CISA's catalog as of version 2026.10.02, and the vendor details come from the advisories linked in each entry. We hold all of it at about 95 percent confidence. The other 5 percent is what changes in the catalog after we hit publish.
Was this useful? Rate this post. The widget is at the bottom of the page, and we read every response.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=cisa-put-43-exploited-bugs-on-its-list-in-september-the-most-in-any-month-since-2022-one-entry-sti



Comments