(TLP:CLEAR) Weekly Vulnerabilities to Prioritize – October 1, 2026
Created: Thursday, October 1, 2026 - 14:42
Categories: Cybersecurity, Security Preparedness
The below vulnerabilities have been identified by WaterISAC analysts as important for water and wastewater utilities to prioritize in their vulnerability management efforts. WaterISAC shares critical vulnerabilities that affect widely used products and may be under active exploitation. WaterISAC draws additional awareness in alerts and advisories when vulnerabilities are confirmed to be impacting, or have a high likelihood of impacting, water and wastewater utilities. Members are encouraged to regularly review these vulnerabilities, many of which are often included in CISA’s Known Exploited Vulnerabilities (KEV) Catalog.
Citrix NetScaler ADC/Gateway Vulnerabilities
See WaterISAC’s notification regarding these vulnerabilities
Cisco Catalyst SD-WAN Manager Unauthenticated Bypass Vulnerability
See WaterISAC’s notification regarding this vulnerability
Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
CVSS v3.1: 9.2, 6.9
CVEs: CVE-2026-86060, CVE-2026-67279
Description: Together these vulnerabilities give unauthenticated admin access through exposed SSH.
Source: https://mikrotik.com/supportsec/september-2026-vulnerability/
Microsoft SharePoint Code Injection Vulnerability
CVSS v3.1: 8.8
CVEs: CVE-2026-65660
Description: Improper control of generation of code (‘code injection’) in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660
