Cyber Resilience
Due for you in the next 90 days If we are hit tomorrow, clocks that start

Security Leader Briefing

Week ending 19 September 2026 — what changed, whether it affects you, and what to tell the board. Composed from live exploit-risk signal, the AI Hype Index, and our control mappings.

Last updated: 19 September 2026 00:29 UTC

Board talking points

The headline read, in plain language.

  • 7 newly confirmed-exploited vulnerabilities entered CISA’s KEV catalog this week.
  • Highest-exposure vendors this week: Linux, Cisco, Google, Acronis.
  • The AI Hype Index is 76/100 (down 3 pts) — overall CVE disclosure is on pace for a record year (~115,077 projected vs 49,972 in 2025). Volume is climbing to new highs, but still runs well below the most aggressive LLM-discovery forecasts: the AI-driven surge is real and accelerating, not yet the predicted flood.
  • Control leverage concentrates in Developer Testing and Evaluation (SA-11) — the mitigation most often cited against this week’s exploited CVEs.

This week’s material changes — exploited in the wild

New CISA KEV additions (last 7 days). Each carries the confirmed-exploitation rationale, affected technology, CISA’s required action, and a link to the evidence.

CVE-2025-39964 · Linux Kernel Race Condition
So whatConfirmed exploited in the wild; CISA added it to KEV on 2026-09-18.
Affected technologyLinux Kernel
Recommended actionApply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see… by 2026-09-21
EvidenceCVE-2025-39964 · CISA KEV
CVE-2026-53266 · Linux Kernel Out-of-Bounds Write
So whatConfirmed exploited in the wild; CISA added it to KEV on 2026-09-18.
Affected technologyLinux Kernel
Recommended actionApply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see… by 2026-09-21
EvidenceCVE-2026-53266 · CISA KEV
CVE-2025-39682 · Linux Kernel Improper Check for Unusual or Exceptional Conditions
So whatConfirmed exploited in the wild; CISA added it to KEV on 2026-09-18.
Affected technologyLinux Kernel
Recommended actionApply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see… by 2026-09-21
EvidenceCVE-2025-39682 · CISA KEV
CVE-2026-58704 · Google Pixel Improper Authorization
So whatConfirmed exploited in the wild; CISA added it to KEV on 2026-09-16.
Affected technologyGoogle Pixel
Recommended actionApply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see… by 2026-09-19
EvidenceCVE-2026-58704 · CISA KEV
CVE-2026-76460 · Cisco Identity Services Engine Incorrect Use of Privileged APIs
So whatConfirmed exploited in the wild; CISA added it to KEV on 2026-09-16.
Affected technologyCisco Identity Services Engine
Recommended actionApply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see… by 2026-09-19
EvidenceCVE-2026-76460 · CISA KEV
CVE-2026-87886 · Acronis Backup Incorrect Default Permissions
So whatConfirmed exploited in the wild; CISA added it to KEV on 2026-09-16.
Affected technologyAcronis Backup
Recommended actionApply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see… by 2026-09-19
EvidenceCVE-2026-87886 · CISA KEV
CVE-2026-76461 · Cisco Secure Email Gateway SQL Injection
So whatConfirmed exploited in the wild; CISA added it to KEV on 2026-09-14.
Affected technologyCisco Secure Email Gateway
Recommended actionApply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see… by 2026-09-17
EvidenceCVE-2026-76461 · CISA KEV

Likely to be exploited next

CVEs whose exploit probability (EPSS) is rising fast, plus fresh criticals with an exploit indicator. Not yet on KEV — watch or pre-emptively patch.

EPSS movers
Fresh criticals

AI risk signal

A record year for CVE volume — but is it the predicted AI-driven flood? AI Hype Index →

76 / 100 · down 3 pts · 0 = predictions on track, 100 = pre-LLM baseline

Two things are true at once. CVE disclosure is on pace for a record year — roughly 115,077 projected for 2026 versus 49,972 in all of 2025 — so overall vulnerability volume is climbing to new highs. Yet that surge still runs well below the most aggressive LLM-discovery forecasts, which is why the Hype Index reads high. The AI-driven acceleration is real; the predicted explosion has not (yet) landed. Sustain the patch program — no emergency AI-exposure action is indicated this week.

Control implications

The NIST 800-53 controls most often cited as mitigating this week’s exploited CVEs — where to focus verification effort.

Recommended decisions

Concrete, imperative next steps.

  • Patch or mitigate the 7 newly-KEV CVEs on your standard exploited-in-the-wild priority track.
  • Verify SA-11, SI-10 are enforced on Linux, Cisco, Google systems.
  • Brief leadership that CVE volume is on track for a record year but still short of the aggressive LLM-discovery forecasts — sustain the patch program; no emergency AI-exposure action this week.