Top CVEs of September 2026: Four Zero-Days, and Patching Wasn’t the Fix
- ✓Four of the five were exploited before a patch existed, and GitLab’s was exploited the day after its fix.
- ✓Fix them in this order: Citrix NetScaler, Cisco ISE, F5 BIG-IP APM (only if APM is an OAuth Authorization Server), Adobe Commerce, then GitLab.
- ✓Upgrading isn’t the finish line for any of them. Every vendor made a compromise check or credential rotation part of remediation.
- ✓Watch for two traps: Adobe’s regular September release doesn’t contain the StyleSmuggler fix, and Citrix 13.1-64.23 can reboot-loop on some deployments, so use 13.1-64.24.
Which September 2026 CVEs should you fix first?
Start with what attackers can reach on default settings and what they had the longest head start on. That puts NetScaler first, since it needs no special configuration and attackers used it as a zero-day for weeks. ISE comes next because every configuration is exposed. F5 lands third only because a single OAuth setting decides whether you’re exposed at all, and Adobe Commerce and GitLab close out the list. Notice that three of the five score a perfect 10.0, and none of them is first.
Use the table as your lookup. The sections after it cover what a version range can’t tell you.
| CVE | Product | CVSS | Exploited | Exposed when | Fixed in |
|---|---|---|---|---|---|
| CVE-2026-88771 | Citrix NetScaler ADC and Gateway | 9.5 (v4.0) | Zero-day for weeks; KEV Sept 27 | Any customer-managed deployment on an affected build | 14.1-73.37; 13.1-64.24; FIPS and NDcPP builds per CTX697096 |
| CVE-2026-76460 | Cisco ISE and ISE-PIC | 10.0 (v3.1) | Zero-day; KEV Sept 16 | Any configuration | 3.1 P12, 3.2 P11, 3.3 P12, 3.4 P7, 3.5 P4; 3.0 is out of maintenance, so migrate |
| CVE-2026-94127 | F5 BIG-IP APM | 9.8 (v3.1) | Zero-day; KEV Sept 22 | APM as OAuth Authorization Server on 17.1.0–17.1.3, 17.5.0–17.5.1, or 21.1.0 | F5 engineering hotfixes (K000162605) |
| CVE-2026-75650 | Adobe Commerce, Magento Open Source, Commerce B2B | 10.0 (v3.1) | Zero-day from Sept 4 | Commerce 2.4.4–2.4.9, Magento Open Source 2.4.6–2.4.9, listed B2B builds | Hotfix VULN-39341 (APSB26-146), plus key and credential rotation |
| CVE-2026-85706 | GitLab CE and EE, self-managed | 10.0 (v3.1) | Day after the fix; KEV Sept 11 | 18.7 and later on an unfixed build | 18.11.12, 19.0.9, 19.1.8, 19.2.6, 19.3.2 |
CVE-2026-88771: Why is Citrix NetScaler first?
Because an unauthenticated attacker can run commands on any affected NetScaler ADC or Gateway without you enabling anything extra, and attackers were doing exactly that for weeks before Citrix shipped a fix on September 27. Before the bulletin even came out, incident responders and national agencies were privately telling organizations to shut their appliances down. Once a public PoC appeared, the targeted attacks turned into mass exploitation. One threat intelligence firm reported more than 100 victim organizations, each with its own webshell that you can’t find by scanning from the outside.

The same bulletin also fixes CVE-2026-88772, a memory overflow in DTLS. Since DTLS is on by default for VPN virtual servers, most Gateways carry both bugs.
Be careful when you pick your upgrade target. Citrix documents a cyclic reboot issue on 13.1-64.23 for deployments with configured variables, and it points those customers to 13.1-64.24 instead.
Before you upgrade, preserve your logs, because the NetScaler Console detection script only works on logs from the attack window. After upgrading, run Citrix’s indicators on every appliance, not just the ones that look suspicious, and don’t treat a clean result as proof. Citrix itself says its indicators can’t identify every technique. If you suspect compromise, start incident response and replace the appliance with a new, updated instance, since Citrix states that upgrading doesn’t remove existing artifacts. You’re done when every appliance runs a fixed build, its logs have been reviewed, and any suspected box has been rebuilt rather than upgraded.
CVE-2026-76460: Why does a Cisco ISE bypass rank above F5?
Because it hits every ISE and ISE-PIC deployment on an affected release no matter how it’s configured, and ISE is what decides who and what gets onto your network. A crafted request to an ISE API gets past the web management interface without credentials. Cisco warns that exploitation can lead to root command execution, which means an attacker can remove or hide local evidence.
Cisco disclosed it on September 16, already under exploitation, as part of a batch of 77 Cisco CVEs with 41 of them in ISE. If your team sorted that batch by score, this one sat right next to several other 10.0s.
Check the release on every node, including the secondary admin and policy service nodes, because a deployment-level ticket often gets closed after the first node upgrades. Review the access logs on all nodes and correlate them with network logs stored somewhere off the box, since a node with root compromise can’t vouch for itself. If you suspect malicious activity, follow Cisco’s advice: re-image the node and restore its configuration from backup. You’re done when each node has a recorded release and a recorded investigation result.
CVE-2026-94127: Is every F5 BIG-IP APM exposed?
No. The bug only affects APM when it acts as an OAuth Authorization Server, which means an access policy and an OAuth profile on the same virtual server. If you use APM as an OAuth client or resource server, you’re not affected, and running in Appliance mode doesn’t protect you either way. On a matching configuration, it’s a heap overflow that gives an unauthenticated attacker remote code execution.
That one setting is the only reason F5 ranks third. F5 found the bug internally, then learned it was being exploited, and disclosed it on September 22. CISA gave federal agencies three days to fix it. Shadowserver sees about 14,700 IPs with APM fingerprints, although that count tells you nothing about OAuth configuration. Earlier in September, researchers also found a Linux rootkit built for BIG-IP APM that got in through an older flaw, so attackers are clearly working this platform.
Start by auditing every virtual server for the access policy plus OAuth profile combination with APM as the authorization server, and record the result for each one. On the servers that match, preserve forensic evidence first and then apply the hotfix listed in K000162605. When you investigate, look for OAuth authentication failures, suspicious commands, and TMM failures that line up with each other, and keep in mind that a TMM core file on its own isn’t proof of compromise. You’re done when every virtual server has a recorded configuration check and every matching one has been hotfixed and investigated.
CVE-2026-75650: Why didn’t the September Adobe Commerce update fix StyleSmuggler?
Because the fix ships as a separate hotfix. Adobe’s regular September release (APSB26-138) tells customers to apply the CVE-2026-75650 hotfix on top of it, so if your team installed the monthly release and closed the ticket, you’re still exposed.

StyleSmuggler is unauthenticated remote code execution. Attackers push PHP into Magento’s template processing through HTTP headers and parameters, and the code runs when the store renders its automated emails. Exploitation began on September 4, and Adobe’s emergency hotfix didn’t arrive until September 7. The first known victim was running 2.4.6-p15 with the July and August updates installed, and its patch status looked clean. Later, a second, unrelated attacker used the same bug to drop a 485-byte webshell.
Remediation is really two jobs, and teams tend to skip the second one. On top of the hotfix, Adobe requires you to rotate the encryption key and your credentials, and a new key alone doesn’t invalidate credentials that were already stolen.
Install hotfix VULN-39341 for your exact build and confirm it with vendor/bin/magento-patches -n status. Then rotate the encryption key, followed by admin passwords, integration tokens, and payment-service credentials at each provider, not only inside Commerce. Treat any store exposed since September 4 as possibly compromised and check its cron entries and storefront JavaScript for changes. Once the rotation is finished, retest checkout and every integration. You’re done when the ticket shows the hotfix verified and every credential rotation complete.
CVE-2026-85706: Is a GitLab file read really a CVSS 10.0?
Yes, and the reason is what it reads. Because the repository commits API is missing authentication and path confinement, an unauthenticated attacker can read any file the GitLab service account can read. On most instances, that includes configuration, integration settings, access tokens, and credentials for connected systems.
It ranks last because it wasn’t a zero-day and it leaks data instead of running code. Even so, the gap was only a day: GitLab fixed it on September 10, and probing and the KEV listing both followed on September 11. GitLab backported fixes to 18.11 and 19.0 on September 23, but branches 18.7 through 18.10 got no backport, so you’ll need to move those to a fixed branch.
Preserve your logs before you upgrade, because a restart can rotate them. Then hunt for POST requests to /api/v4/projects/{id}/repository/commits/ that carry file.path parameters. An HTTP status code alone doesn’t prove a file actually left the server, so use GitLab’s procedure to correlate Workhorse written_bytes with api_error. If disclosure is confirmed, rotate whatever was exposed, including personal access tokens, runner tokens, deploy keys, CI/CD variables, and integration credentials. Only rotate gitlab-secrets.json through GitLab’s documented procedure, because regenerating it by hand can make encrypted database values unreadable. You’re done when the instance runs a fixed build and the log review either rules out disclosure or confirms the exposed secrets have been rotated.
Why isn’t a patch report enough this month?
A patch report tells you a build number changed. It can’t tell you whether the system was reachable, whether the vulnerable configuration was actually there, or whether someone got in during the weeks before the fix. So when logs are missing, mark the item as unverified instead of closing it.
You can only answer those questions from the attacker’s side: what’s reachable, what’s exploitable in your environment, and how far it leads. That’s the job of adversarial exposure validation, and it’s why agentic pentesting runs continuously instead of once a year. And if you can’t say which of these five products face the internet, start with attack surface management.
Frequently asked questions
Why do sources show different CVSS scores for the same CVE? Because they use different CVSS versions. Citrix scores CVE-2026-88771 at 9.5 under v4.0, while some databases list it at 9.8 under v3.1. Likewise, F5’s CVE-2026-94127 shows up as 9.8 under v3.1 and 9.3 under v4.0. Only compare scores within the same version.
Do cloud-hosted versions need action? GitLab.com and GitLab Dedicated don’t, because GitLab already remediated them. Citrix handles its own managed cloud services, but customer-managed NetScaler instances used by Secure Private Access Hybrid still need the fix. Adobe Commerce on Cloud does need action: apply the hotfix and use Adobe’s procedure to confirm it reports Applied.
What can I do if I can’t patch today? For NetScaler, take the Gateway off the internet. Cisco offers no workaround for ISE, but limiting management and control-plane access to admin networks reduces your remote exposure. For BIG-IP APM, F5 Support provides an iRule mitigation, which you should track separately from the hotfix. For GitLab, remove public access to your self-managed instances.
What if my logs have already rotated? Then you can’t prove the system is clean. Rebuild NetScaler appliances and re-image ISE nodes on suspicion, and rotate the secrets your GitLab and Adobe Commerce systems held.
Related reading
- Top CVEs of August 2026: Why CVSS 7 Beat CVSS 10
- Top CVEs of July 2026
- Adversarial exposure validation for modern environments
- Understanding external attack surface management (EASM)
Sources
- CISA Known Exploited Vulnerabilities Catalog
- CISA alert: Critical zero-day vulnerabilities exploited in Citrix NetScaler ADC and Gateway
- Citrix CTX697096 security bulletin
- Citrix upgrade and investigation guidance
- Help Net Security: Citrix NetScaler RCE zero-days exploited globally for weeks
- Cisco Security Advisory for CVE-2026-76460
- F5 advisory K000162605
- CERT-EU advisory on CVE-2026-94127
- BleepingComputer: F5 patches BIG-IP APM zero-day exploited in RCE attacks
- Adobe security bulletin APSB26-146
- Adobe implementation and rotation guidance
- Sansec: StyleSmuggler zero-day research
- GitLab patch release 19.3.2 and version matrix
- GitLab: Validating whether a file was exfiltrated via CVE-2026-85706
