(TLP CLEAR) Weekly Vulnerabilities to Prioritize – September 10, 2026
Created: Thursday, September 10, 2026 - 15:35
Categories: Cybersecurity, Security Preparedness
The below vulnerabilities have been identified by WaterISAC analysts as important for water and wastewater utilities to prioritize in their vulnerability management efforts. WaterISAC shares critical vulnerabilities that affect widely used products and may be under active exploitation. WaterISAC draws additional awareness in alerts and advisories when vulnerabilities are confirmed to be impacting, or have a high likelihood of impacting, water and wastewater utilities. Members are encouraged to regularly review these vulnerabilities, many of which are often included in CISA’s Known Exploited Vulnerabilities (KEV) Catalog.
Cisco Secure Firewall Management Center Authentication Bypass Vulnerability
CVSS v3.1: 10.0
CVE: CVE-2026-20079
Description: CISA recently added this vulnerability to its KEV Catalog. This vulnerability can be exploited remotely by unauthenticated attackers to execute code on an affected device and obtain root access to the underlying operating system. An authentication bypass vulnerability (classified under CWE-288) in the web interface of Cisco Secure Firewall Management Center. According to Cisco, the flaw stems from an improper system process created at boot time. By sending crafted HTTP requests to an affected device, an attacker can exploit this process to execute scripts and commands that allow root access to the device. All on-premises FMC software releases are affected regardless of device configuration. Cloud-Delivered FMC (cdFMC) is not affected.
Source: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2
Additional Reading:
- Critical Cisco Vulnerabilities: CVE-2026-20079 and CVE-2026-20131 Affecting Cisco Secure Firewall Management Center
- Tenable: CVE-2026-20079
Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
CVSS v3.1: 7.4
CVEs: CVE-2025-25249
Description: A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://fortiguard.fortinet.com/psirt/FG-IR-25-084
Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
CVSS v4.0: 9.3
CVEs: CVE-2026-19490
Description: Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939
Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
CVSS v3.1: 10.0
CVEs: CVE-2026-75650
Description: Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://helpx.adobe.com/security/products/magento/apsb26-146.html
Microsoft Windows Link Following Vulnerability
CVSS v3.1: 7.8
CVEs: CVE-2026-81963
Description: Improper link resolution before file access (‘link following’) in Windows Update Stack allows an authorized attacker to elevate privileges locally. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81963
Microsoft Windows Heap-Based Buffer Overflow Vulnerability
CVSS v3.1: 7.8
CVEs: CVE-2026-85880
Description: Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880
N-able N-central Static Code Injection Vulnerability
CVSS v4.0: 10.0
CVEs: CVE-2026-86218
Description: N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://me.n-able.com/s/security-advisory/aArVy0000002Ld3KAE/cve202686218-preauthentication-remote-code-execution
Google Chromium V8 Type Confusion Vulnerability
CVSS: N/A
CVEs: CVE-2026-85046
Description: Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html
Google Chromium V8 Out of Bounds Write Vulnerability
CVSS: N/A
CVEs: CVE-2026-87491
Description: Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html
