Monthly exploitation report · September 2026

Known Exploited Vulnerabilities Report — September 2026

Executive analysis of KEV additions, sensor-observed exploitation activity, CISA visibility gaps, and the vulnerabilities that drove September 2026.

156
KEVs added

148 were outside CISA KEV when added

214,577
Exploitation events

Up 30.4% from August

80.1%
Top-five concentration

Share of events tied to five vulnerabilities

0.8 days
Median CISA lead

Across 35 vulnerabilities added by Previdian first

Executive brief

The month in three decisions

01

Validate exposure against the top five

Five vulnerabilities produced 80.1% of September events. Prioritize asset discovery and remediation around PHPUnit, react-server-dom-webpack, react-server-dom-turbopack, react-server-dom-parcel, PHP, IP Camera, and vite, vite-plus.

02

Do not rely on CISA KEV alone

Previdian added 148 exploited vulnerabilities outside CISA KEV during September; 113 were still absent at month-end.

03

Treat telemetry as directional evidence

Event volume and source breadth help identify pressure, but observations do not prove that a real-world target was compromised or represent all exploitation activity worldwide.

Exploitation activity

Activity rose sharply—and remained concentrated

Previdian sensors recorded 214,577 exploitation events in September, up from 164,539 in August. A small set of vulnerabilities drove most of the observed volume.

+30.4% month over month

Observed exploitation events

August versus September 2026

August
164,539 September
214,577

208

Vulnerabilities observed

4,280

Source IPs

27

First observed

Concentration of observed events

Top vulnerability 51.1%
Top five 80.1%
Top ten 91.4%

For CISOs, this concentration supports a focused exposure-validation and remediation sprint rather than treating every observed CVE as equally urgent.

CVE Publication to KEV

KEVs took longer after CVE publication

155 of the KEVs added during September 2026 had a CVE publication date. 31 were concurrent disclosures (CVE record and KEV on the same UTC day) and are excluded from the median. 6 were added before the CVE record was published. The median among the remaining 118 was 216 days, up from 90 days in August.

216 days

Median after publication (126 days slower than August)

20.0%

Concurrent same-day share

Most targeted

The vulnerabilities driving September activity

Ranked by sensor-observed exploitation events. Event volume shows intensity; unique source IPs help indicate breadth.

1
CVE-2017-9841

PHPUnit · PHPUnit

In CISA KEV

51.1% of monthly events

Events
109,675
Source IPs
701
2
CVE-2025-55182

Meta · react-server-dom-webpack, react-server-dom-turbopack, react-server-dom-parcel

In CISA KEV

11.7% of monthly events

Events
25,060
Source IPs
413
3
CVE-2024-4577

PHP Group · PHP

In CISA KEV

7.6% of monthly events

Events
16,287
Source IPs
727
5
CVE-2026-39364

Vitejs · vite, vite-plus

Outside CISA KEV at month-end

4.6% of monthly events

Events
9,973
Source IPs
332
6
CVE-2018-20062

NoneCms · NoneCms

In CISA KEV

2.8% of monthly events

Events
5,955
Source IPs
604
7
CVE-2022-47945

ThinkPHP · ThinkPHP Framework

Outside CISA KEV at month-end

2.6% of monthly events

Events
5,505
Source IPs
531
8
CVE-2026-75650

Adobe · Adobe Commerce, Adobe Commerce B2B, Magento Open Source

In CISA KEV

2.4% of monthly events

Events
5,240
Source IPs
88
9
CVE-2021-41773

Apache · Apache HTTP Server

In CISA KEV

2.0% of monthly events

Events
4,270
Source IPs
727

Vendor exposure

Newly added KEVs by vendor

Car_rental_management_system_project

4 outside CISA KEV when added

4

Cisco

4 outside CISA KEV when added

4

Mikrotik

3 outside CISA KEV when added

4

Yonyou

4 outside CISA KEV when added

4

Google

3 outside CISA KEV when added

3

Weakness patterns

Most common CWE classes

CWE-89 · Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Most common newly added weakness

39

CWE-22 · Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

11 newly added KEVs

11

CWE-77 · Improper Neutralization of Special Elements used in a Command ('Command Injection')

10 newly added KEVs

10

CWE-78 · Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

9 newly added KEVs

9

CWE-74 · Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

8 newly added KEVs

8

51.3%

Critical severity

259

Public PoC references

216

Nuclei references

207

Observed request paths

Methodology and limitations

How to interpret and cite this report

These notes define the reporting window, what sensor observations mean, and where the dataset should not be generalized.

Full Previdian methodology
Reporting period

1 September 2026 00:00 UTC through 30 September 2026 23:59 UTC.

Sensor scope

Previdian telemetry represents activity observed by the Previdian sensor network; it does not represent all exploitation activity globally.

Interpretation

An observed exploitation attempt does not by itself demonstrate that a real-world target was successfully compromised.

CISA status

Month-end status is reconstructed from stored CISA addition dates. Removals are not tracked.

Source-IP coverage

Unique source-IP counts require raw sensor rows. When only daily rollups exist, the metric is unavailable.

Historical records

Historical or backfilled KEV records cannot be identified reliably from existing fields and are not listed as a separate category.

Sensor network size

Public reports do not disclose Previdian sensor network size or per-CVE sensor counts.

Early-warning lead time

Early-warning lead time is the gap from first autonomous-watchlist listing to first Previdian KEV. Only positive gaps are counted. Listings after a KEV already existed are excluded.

CVE publication to KEV

Time from CVE publication to KEV uses UTC calendar days from the CVE publication date to the first Previdian KEV. Same-day concurrent disclosures (CVE record and KEV on the same UTC day) are counted separately and excluded from the median, as are KEVs added before the CVE record was published.

Prefer deep links to individual CVE reports and this methodology when citing sensor-observed vulnerabilities.