(TLP:CLEAR) Weekly Vulnerabilities to Prioritize – September 24, 2026
Created: Thursday, September 24, 2026 - 10:00
Categories: Cybersecurity, Security Preparedness
The below vulnerabilities have been identified by WaterISAC analysts as important for water and wastewater utilities to prioritize in their vulnerability management efforts. WaterISAC shares critical vulnerabilities that affect widely used products and may be under active exploitation. WaterISAC draws additional awareness in alerts and advisories when vulnerabilities are confirmed to be impacting, or have a high likelihood of impacting, water and wastewater utilities. Members are encouraged to regularly review these vulnerabilities, many of which are often included in CISA’s Known Exploited Vulnerabilities (KEV) Catalog.
Cisco ISE / ISE-PIC Vulnerabilities
CVSS v3.1: 10.0, 10.0, 10.0
CVEs: CVE-2026-20192, CVE-2026-76423, CVE-2026-76460
Description: Successful exploitation could allow unauthenticated attackers to bypass authentication, gain administrative access, and view or modify sensitive data. Updates are available; prioritize given ISE’s role enforcing network access.
Sources:
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ise-XU5EwX5T
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5
Check Point Multiple Products Path Traversal Vulnerability
CVSS v3.1: 9.8
CVE: CVE-2026-93616
Description: A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://support.checkpoint.com/results/sk/sk1000171/
MikroTik RouterOS Vulnerabilities
CVSS v3.1: 9.2, 6.9
CVEs: CVE-2026-86060, CVE-2026-67279
Description: Together these vulnerabilities give unauthenticated admin access through exposed SSH.
Source: https://mikrotik.com/supportsec/september-2026-vulnerability/
Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
CVSS v3.1: 8.8
CVEs: CVE-2026-7273
Description: A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026
Linux Kernel Vulnerabilities
CVSS v3.1: 9.8, 7.8, 8.8
CVEs: CVE-2025-39682, CVE-2025-39964, CVE-2026-53266
Description: All three of these vulnerabilities have been added to CISA’s Known Exploited Vulnerability Catalog in the past week. Linux underpins many appliances and servers.
Veeam Agent for Microsoft Windows
CVSS v3.1: 7.3
CVEs: CVE-2026-32996
Description: This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.
Source: https://www.veeam.com/kb4852
