Security Leader Briefing
Week ending 19 September 2026 — what changed, whether it affects you, and what to tell the board. Composed from live exploit-risk signal, the AI Hype Index, and our control mappings.
Last updated: 19 September 2026 00:29 UTC
Board talking points
The headline read, in plain language.
- 7 newly confirmed-exploited vulnerabilities entered CISA’s KEV catalog this week.
- Highest-exposure vendors this week: Linux, Cisco, Google, Acronis.
- The AI Hype Index is 76/100 (down 3 pts) — overall CVE disclosure is on pace for a record year (~115,077 projected vs 49,972 in 2025). Volume is climbing to new highs, but still runs well below the most aggressive LLM-discovery forecasts: the AI-driven surge is real and accelerating, not yet the predicted flood.
- Control leverage concentrates in Developer Testing and Evaluation (SA-11) — the mitigation most often cited against this week’s exploited CVEs.
This week’s material changes — exploited in the wild
New CISA KEV additions (last 7 days). Each carries the confirmed-exploitation rationale, affected technology, CISA’s required action, and a link to the evidence.
Likely to be exploited next
CVEs whose exploit probability (EPSS) is rising fast, plus fresh criticals with an exploit indicator. Not yet on KEV — watch or pre-emptively patch.
- 99 CVE-2026-1281 EPSS 98.6% · rising
- 99 CVE-2026-1340 EPSS 98.7% · rising
- 96 CVE-2023-3710 EPSS 49.0% · rising
- 91 CVE-2025-34511 EPSS 29.8% · rising
- 70 CVE-2013-5223 EPSS 50.8% · rising
- 70 CVE-2025-5301 EPSS 62.4% · rising
- No fresh criticals with exploit signal.
AI risk signal
A record year for CVE volume — but is it the predicted AI-driven flood? AI Hype Index →
Two things are true at once. CVE disclosure is on pace for a record year — roughly 115,077 projected for 2026 versus 49,972 in all of 2025 — so overall vulnerability volume is climbing to new highs. Yet that surge still runs well below the most aggressive LLM-discovery forecasts, which is why the Hype Index reads high. The AI-driven acceleration is real; the predicted explosion has not (yet) landed. Sustain the patch program — no emergency AI-exposure action is indicated this week.
Control implications
The NIST 800-53 controls most often cited as mitigating this week’s exploited CVEs — where to focus verification effort.
- SA-11 Developer Testing and Evaluation cited for 4 of this week’s CVEs
- SI-10 Information Input Validation cited for 4 of this week’s CVEs
- AC-6 Least Privilege cited for 3 of this week’s CVEs
- SA-15 Development Process, Standards, and Tools cited for 2 of this week’s CVEs
- SI-3 Malicious Code Protection cited for 1 of this week’s CVEs
Recommended decisions
Concrete, imperative next steps.
- Patch or mitigate the 7 newly-KEV CVEs on your standard exploited-in-the-wild priority track.
- Verify SA-11, SI-10 are enforced on Linux, Cisco, Google systems.
- Brief leadership that CVE volume is on track for a record year but still short of the aggressive LLM-discovery forecasts — sustain the patch program; no emergency AI-exposure action this week.