Tuesday, September 29, 2026 Newsletter Advertise
Breaking
Top 10

Top 10 vulnerabilities of the week (Sep 22–28, 2026): 5 actively exploited

This week's 10 most urgent vulnerabilities, including 5 CISA confirmed as actively exploited, ranked from CISA and NIST data.

Top 10 vulnerabilities, 5 actively exploited, Sep 22–28, 2026

The 10 vulnerabilities from the past seven days that most need attention, ranked by a fixed rule: flaws CISA confirmed as actively exploited come first (those used in ransomware at the top, then newest first), followed by the highest-scoring Critical CVEs published by NIST’s National Vulnerability Database.

# CVE What it affects Why it ranks Date
1 CVE-2026-88772 Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability Actively exploited (CISA KEV) September 27, 2026
2 CVE-2026-88771 Citrix NetScaler Improper Input Validation Vulnerability Actively exploited (CISA KEV) September 27, 2026
3 CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability Actively exploited (CISA KEV) September 25, 2026
4 CVE-2026-65660 Microsoft SharePoint Code Injection Vulnerability Actively exploited (CISA KEV) September 25, 2026
5 CVE-2026-87902 WordPress Core Remote File Inclusion Vulnerability Actively exploited (CISA KEV) September 25, 2026
6 CVE-2026-101075 A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of the file /location_time.cgi of the component Location Time Handler. The manipulation of the argumen… CVSS 10 Critical (NVD) September 28, 2026
7 CVE-2026-101072 A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.cgi of the component CGI Handler. Such manipulation of the argument ip leads to os command injection… CVSS 10 Critical (NVD) September 28, 2026
8 CVE-2026-101039 A vulnerability was identified in FAST FAC1900R 20190827_2.0.2. Affected by this issue is the function copy_msg_element of the component devdiscover Service. Such manipulation leads to stack-based buffer overflow. The a… CVSS 10 Critical (NVD) September 28, 2026
9 CVE-2026-101000 A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file /usr/share/rpcd/acl.d/unauthenticated.json of the component ACL Handler. This manipulation of the arg… CVSS 10 Critical (NVD) September 28, 2026
10 CVE-2026-101001 A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impacts the function eval of the file /www/cgi-bin/network_tools of the component Web Management Interface. Such manipulation of the argument QU… CVSS 10 Critical (NVD) September 28, 2026

Descriptions are quoted from CISA and NVD. Always confirm fixed versions in the vendor’s own advisory before prioritizing.

The TechUpscale Brief

The day's cyber, AI and tech news in one short email, every weekday morning. Free. Unsubscribe anytime.

I'm most interested in