BETWEEN 7 and 13 September 2026, the tracker recorded 3,856 new CVEs, including 318 rated critical and 1,703 rated high. Daily Cybersecurity identified 19 as exploited; 10 were later added to CISA’s Known Exploited Vulnerabilities (KEV) catalogue, while nine were not listed at the time of comparison. The feed reported three shared vulnerabilities before CISA, by between one and three days, although the article cautions that the dates measure different events and are not a controlled benchmark.
CISA separately added four exploited flaws that the feed had not flagged, including CVE-2026-84869 in ConnectWise ScreenConnect and CVE-2026-19490 in Citrix NetScaler.
The most serious highlighted cases include CVE-2026-86218, a CVSS 10.0 unauthenticated code-injection flaw in N-able N-central. N-able said it had been exploited in the wild, while Shadowserver counted nearly 1,500 internet-facing servers. CERT Polska reported active exploitation of the MikroTik RouterOS “MikroTrick” SSH chain, which combines CVE-2026-67276 and CVE-2026-86060 to obtain full control without credentials; more than 122,500 internet-facing RouterOS SSH instances were observed in one scan.
GitLab’s CVE-2026-85706, also rated 10.0, permits unauthenticated reading of files through a path-traversal flaw, with probes reportedly seen from 11 September.
The article recommends prioritising patches for internet-facing systems, including N-central 2026.3.1.14, GitLab 19.1.8, 19.2.6 or 19.3.2, and MikroTik RouterOS 6.49.21, 7.23.4 or 7.24.2. It also advises treating SSH-exposed MikroTik devices as potentially compromised and restricting management interfaces where immediate patching is not possible.