Covering Mon Sep 14 2026 00:00 UTC – Sun Sep 20 2026 23:59 UTC
2 new ransomware-linked CVE(s); 3 existing CVE(s) newly tied to ransomware; 5 newly exploited.
1. New Vulnerabilities Linked to Ransomware
CVE-2026-59310 affects Broadcom VMware vCenter and can allow Remote Code Execution.
Scores: CVSS v3.1 9.8, EPSS 0.45878.
Source: https://thehackernews.com/2026/08/critical-macos-sharepoint-vcenter-and.html
CVE-2026-20316 affects Cisco Secure Firewall Management Center (FMC) and can allow Authentication Bypass.
Scores: CVSS v3.1 5.3, EPSS 0.09816.
Source: https://blog.talosintelligence.com/fmc-ongoing-exploitation/
Advisory: https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-fmc-static-cred-BET3Cjh.html
2. Known Vulnerabilities with New Ransomware Indicators
CVE-2022-41352 affects Synacor Zimbra Collaboration Suite (ZCS) and can allow Remote Code Execution.
Scores: CVSS v3.1 9.8, EPSS 0.95478.
Source: https://threatprotect.qualys.com/tag/cve-2022-41352
CVE-2026-63077 affects JetBrains TeamCity and can allow Remote Code Execution.
Scores: CVSS v3.1 9.8, EPSS 0.86518.
Source: https://www.bleepingcomputer.com/news/security/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw/
CVE-2025-14733 affects WatchGuard Firebox and can allow Remote Code Execution.
Scores: CVSS v4 9.3, EPSS 0.26510.
Source: https://www.bleepingcomputer.com/news/security/cisa-watchguard-rce-flaw-now-exploited-in-ransomware-attacks/
3. Critical Zero-day Vulnerabilities
No findings for this week for this category.
4. New Actively Exploited Vulnerabilities
CVE-2026-20079 affects Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management and can allow Remote Code Execution.
Scores: CVSS v3.1 10.0, EPSS 0.88180.
Source: https://blog.talosintelligence.com/fmc-ongoing-exploitation/
Advisory: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2
CVE-2026-75650 affects Adobe Commerce and Magento and can allow Remote Code Execution.
Scores: CVSS v3.1 10.0, EPSS 0.03949.
Source: https://www.bleepingcomputer.com/news/security/adobe-fixes-critical-magento-zero-day-exploited-to-backdoor-servers/
Advisory: https://helpx.adobe.com/security/products/magento/apsb26-146.html
CVE-2026-76460 affects Cisco Identity Services Engine and can allow Authentication Bypass.
Scores: CVSS v3.1 10.0, EPSS 0.14026.
Source: https://www.bleepingcomputer.com/news/security/cisco-warns-of-identity-service-engine-zero-day-exploited-in-attacks/
Advisory: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5
CVE-2026-85706 affects GitLab Community Edition and Enterprise Edition and can allow Arbitrary File Read.
Scores: CVSS v3.1 10.0, EPSS 0.91425.
Source: https://securityaffairs.com/198945/hacking/gitlab-cve-2026-85706-one-http-request-no-authentication-full-file-read-exploited-within-24-hours.html
Advisory: https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/
CVE-2026-86218 affects N-able N-central and can allow Remote Code Execution.
Scores: CVSS v4 10.0, EPSS 0.12928.
Source: https://www.helpnetsecurity.com/2026/09/07/n-able-n-central-hotfix-cve-2026-86218/
Advisory: https://status.n-able.com/2026/09/06/n-central-2026-3-hotfix-4-cve-2026-86218/
Summary for the vulnerability management teams:
CVE-2026-59310, CVE-2026-20316, CVE-2022-41352, CVE-2026-63077, CVE-2025-14733, CVE-2026-20079, CVE-2026-75650, CVE-2026-76460, CVE-2026-85706, CVE-2026-86218
Full archive: https://signals.mostexploited.com/weekly/2026-w39/.