Threat and Vulnerabilities Report - September 2026

October 6, 2026

September 2026 was the busiest month of the year for defenders. Patch queues grew faster than teams could clear them, attackers moved quickly from disclosure to weaponization, and ransomware operators kept up a steady stream of victim postings. CISA added 43 vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog during the month, the highest monthly total recorded in 2026. Cisco led with four additions, followed by Citrix, MikroTik, Microsoft, Linux, Google, and JFrog with three each, and SonicWall and Check Point with two each. The remaining entries covered a wide range of vendors, including Apple, Adobe, Arista, WordPress, Zyxel, ConnectWise, GitLab, and Fortinet. The spread showed that threat actors targeted network edge devices, enterprise software, developer tooling, and consumer platforms alike.

Active exploitation activity reflected the same breadth. Attackers went after AI and LLM infrastructure such as Langflow and BerriAI LiteLLM, which showed growing interest in the fast-expanding AI application stack. WordPress remained a favored target, with exploitation detected against the WebRehab Super Forms – Drag & Drop Form Builder and Elementor plugins. Threat actors also struck enterprise security and communication systems, exploiting Cisco Secure Firewall and Roundcube Webmail. Several of these campaigns hit flaws that already had patches available, which underscored how unpatched systems remained a dependable entry point for attackers.

Ransomware groups remained highly active throughout the month. TheGentlemen topped the leaderboard with 102 affected organizations, a substantial lead over Qilin, which claimed 74 victims. KRYBIT followed in third place with 34 organizations, while Safepay and IncRansom also contributed notable victim counts. The concentration of activity among a few prolific groups showed that established and emerging ransomware operations alike sustained aggressive campaigns, keeping extortion pressure on organizations across sectors.

Download Report
Stay Ahead

Get the Latest Cybersecurity Insights

Security research, threat intelligence, vulnerability updates, product news, and expert insights, delivered directly to your inbox. Stay informed. Stay secure.