Skip to main content

Mapping September 2026 CISA KEV Batch to Services

An analysis of the September 2026 CISA KEV additions, ZoomEye internet measurement statistics, and strategies for mapping vulnerabilities.

AI-written
Inewgen
20 Sep 2026Source: Dev.to3 min read (0 views)
Share
Mapping September 2026 CISA KEV Batch to Services

Stock photo for illustration only, not from the actual event

Font size
  • The CISA KEV catalog lists exploited flaws but does not show what is exposed in a specific environment.
  • Internet measurement bridges the gap between vulnerability lists and actual reachable services.
  • ZoomEye scan data from September 2026 highlights the visibility difference between fingerprintable services and hidden management consoles.

The CISA Known Exploited Vulnerabilities (KEV) catalog lists flaws that attackers actively exploit in the wild, but it does not reveal what is exposed within a given environment. Bridging this gap is crucial, and internet measurement serves as one of the concrete inputs to achieve it. The September 2026 KEV additions offer a practical example of how to address this operational challenge.

Several vulnerabilities added in September 2026 share common characteristics, affecting services frequently reachable from the internet that handle credentials or system controls. Notable examples include CVE-2026-85706, an unauthenticated arbitrary file read in GitLab repository commits API rated CVSS 10.0; CVE-2026-20079, a pre-authentication auth bypass in Cisco Secure Firewall Management Center rated 10.0; CVE-2026-59822 in BerriAI LiteLLM; CVE-2026-56164 in Microsoft SharePoint; and two Windows zero-day flaws both rated 7.8.

network server data center dashboard screen no logo

Stock photo for illustration only, not from the actual event

1,262,273GitLab IPv4 device matches
34,402LiteLLM IPv4 device matches

The operational question for administrators is how many affected systems face untrusted networks. ZoomEye queries run on September 19, 2026, produced concrete metrics for fingerprintable services, yielding 1,262,273 IPv4 matches for GitLab and 34,402 for LiteLLM. Conversely, Cisco Secure Firewall Management Center (FMC) returned zero matches because management consoles are typically shielded behind VPNs or jump hosts and present minimal identifying details.

A near-zero external measurement result for management planes like Cisco FMC reflects visibility limits rather than a small attack surface. Organizations must build asset inventories using internal records and continuous discovery rather than relying solely on passive external scans.

The effective workflow starts with the KEV catalog, identifies matching services in your estate, and determines reachability. For fingerprintable services such as GitLab and LiteLLM, external data can be reconciled with internal asset inventories to locate unpatched systems. For management planes, internal discovery tools remain essential to uncover hidden infrastructure.

Source: Dev.to

Comments

Leave a Comment
0/2000

Found something wrong in this article? Report an issue with this article