deniz.in

Markets

Weather

Loading weather

· via dev.to (home feed)

Seventeen new KEV entries carry three-day deadlines; EPSS scores set the patch order

CISA added 17 exploited CVEs to its KEV catalog between 14 and 25 September 2026, each with a three-day federal patch deadline. A dev.to post ranks them by EPSS score into a practical patch order.

Seventeen new KEV entries carry three-day deadlines; EPSS scores set the patch order

CISA added 17 CVEs to its Known Exploited Vulnerabilities (KEV) catalog between 14 and 25 September 2026, and according to a dev.to post by CyberMax, every one of them carries a federal patch deadline just three days after being added — the latest falling on 28 September. With more than 380,000 CVEs now carrying an EPSS score and no team able to patch them all, the post lays out a repeatable ranking built on two free signals: KEV, for confirmed exploitation in the wild, and FIRST's Exploit Prediction Scoring System (EPSS), which estimates the probability of exploitation activity over the next 30 days.

Seventeen additions, three-day clocks

The new entries bring the catalog (version 2026.09.25) to 1,726 CVEs. Sorted by EPSS scores dated 27 September, the top of the list is dominated by internet-facing products. An Adobe Commerce and Magento flaw, CVE-2026-71362, scores 87.5%. It is followed by Cisco Secure Email Gateway (CVE-2026-76461, 28.3%), a Check Point flaw affecting multiple products (CVE-2026-93616, 19.7%) and a remote file inclusion bug in WordPress core (CVE-2026-87902, 18.2%). Cisco Identity Services Engine sits at 14.0%, with the Linux kernel, Zyxel GS1900 switches, F5 BIG-IP APM, Microsoft SharePoint and MikroTik RouterOS all between 2.9% and 1.0%. Seven further additions — among them Arista VeloCloud Orchestrator, WSO2, Acronis Backup and Google Pixel flaws — score below 1.1%. The post cautions that a low EPSS score does not mean safe: these CVEs are confirmed exploited, and the score only indicates where mass exploitation is most likely.

A repeatable patch order

The proposed triage has four tiers. First, anything in KEV and internet-facing: Adobe Commerce and Magento, WordPress core, Cisco Secure Email Gateway, Check Point gateways, F5 BIG-IP APM and SharePoint, since exploitation is confirmed and the systems are reachable by anyone. Second, KEV entries sitting inside the network: Cisco ISE, the Linux kernel bugs, Zyxel switches, MikroTik routers and Acronis Backup. Third comes the early-warning tier — CVEs not yet in KEV but scoring above 10% on EPSS. On 27 September, 17,267 CVEs scored 10% or higher, yet only 1,274 of them were in KEV; the post argues this gap is where the next KEV entries usually come from. Everything else drops to CVSS and exposure on the normal patch cycle.

Why two signals beat CVSS alone

CVSS describes how bad a flaw could be, not whether anyone is using it. Of the 1,726 KEV entries, 361 are known to be used in ransomware campaigns, and the risk is concentrated by vendor: Microsoft accounts for 389 KEV entries, Cisco 99, Apple 94 and Ivanti 35, according to the tallies in the post.

Tooling, with a caveat

The piece doubles as promotion for the publisher's own product, a CVE-priority API called Kevscope that returns a verdict of act_now, high, medium or low alongside KEV status, EPSS, CVSS and SSVC evidence, at up to 20 CVEs per call. It is free for 200 calls a day, then $19 a month for 10,000 calls, which the post contrasts with OpenCVE's €19 and €49 tiers and Vulners' $600-a-month entry point. Those are vendor-supplied figures, though the post states every number is drawn from public CISA, FIRST and NIST NVD data, so the underlying catalog and scores can be checked directly.

Why it matters

Patch backlogs are measured in months while KEV deadlines run in days, and that mismatch is the operational problem this method addresses. By filtering first on confirmed exploitation, then on near-term exploitation probability, a team turns an unpatchable queue of 380,000-plus CVEs into a short, ranked list that front-loads internet-facing systems. Both signals are free and updated continuously, so the workflow is reproducible from nothing more than a scanner export — even for teams that never buy the tooling built around it.

  • #security
  • #vulnerability-management
  • #cisa
  • #epss
  • #patching

Related posts