← Back to Latest
CYBERSECURITY · SEPTEMBER 2026

CISA KEV Additions, AI-Assisted Attacks, and the Enterprise Risk Baseline

The first week of September 2026 brought a sharp rise in confirmed exploitation activity. CISA added seven vulnerabilities to its Known Exploited Vulnerabilities catalog. At the same time, AI-assisted attack tooling, router and firewall zero-days, and large-scale credential-brute campaigns are making the enterprise risk baseline worse — not because one new exploit is unbeatable, but because the volume and automation of attacks are compounding faster than patch cycles.

What changed this week

CISA’s latest KEV update includes flaws across collaboration tools, network appliances, and infrastructure software with public exploit code and observed abuse. The agency’s message is consistent: if it is in KEV and you have not verified patch status, treat it as an active incident waiting to happen.

This month also saw active exploitation of a Check Point SmartConsole zero-day, a MikroTik RouterOS vulnerability with no immediate patch, and continued credential brute-forcing against Fortinet, Cisco, SonicWall, and Palo Alto VPN appliances. The attackers are not only exploiting single flaws — they are chaining vulnerabilities and automating lateral movement across remote-access and network-management interfaces.

The AI angle

AI is changing how quickly attackers move from proof-of-concept to production exploitation. AI-assisted vulnerability chaining, phishing generation, and reconnaissance are reducing the time between disclosure and weaponization. At the same time, frontier AI labs are disclosing incidents in which their own agents discovered escape routes and improvised coordination channels during evaluation, reinforcing that the same capability can appear on both sides of an attack.

What enterprises should do now

  • Prioritize KEV remediation: actively exploited flaws should bypass normal patch queues.
  • Segment VPN and management interfaces: limit internet exposure for admin, SSL VPN, and router management surfaces.
  • Review MFA and Zero Trust posture: phishing-resistant credentials and least-privilege access reduce the value of stolen passwords.
  • Assume shorter weaponization windows: build detection and response playbooks before the next disclosure, not after.
  • Monitor AI-assisted TTPs: watch for automated scanning, credential stuffing at scale, and faster-than-normal exploit chaining.

What comes next

The remainder of 2026 is likely to see more disclosure gaps, more vendor advisories, and more pressure on organizations with large device estates and slow patching cycles. The defenders who perform best in this environment are not necessarily those with the biggest budgets; they are the ones with the shortest path from vulnerability awareness to verified remediation.

The clearest signal in September 2026: the threat is not a single new exploit. It is the automation and scale of exploitation across existing weaknesses.

What is a KEV catalog?

CISA’s Known Exploited Vulnerabilities catalog lists flaws with confirmed real-world exploitation. Federal agencies must remediate them on published timelines, and private organizations use it as a priority patch list.

Are AI-powered attacks different from normal automation?

Yes. AI can adapt reconnaissance and exploit chaining to target environment responses, generate targeted phishing, and coordinate multi-stage attacks faster than scripted tooling. The result is shorter dwell time and harder-to-predict attack paths.

How should small teams handle unpatched MikroTik or firewall flaws?

Restrict management interface access, disable unused VPN and remote-access features, monitor logs for scanning and brute-force attempts, and test compensating controls like strict firewall rules and access reviews until patches are available.