This website uses cookies

Read our Privacy policy and Terms of use for more information.

Bayou Bytes  //  Issue #12 · Due Date Week

Come, Take Your First Byte.

Three sections, twelve minutes. Starting now.
 
New free tool drops today
Gatorbyte #014 — free download, run it this week
The Security Stack Kit →

The Pulse

Every Tuesday: the threats that actually moved, one fix you can ship before lunch, and the plain-English version your non-technical CEO needs to hear. Three things worth your scroll this week — all three read off the Known Exploited Vulnerabilities catalog itself, version 2026.09.18.

Now, this week:

🔴 Threat level: elevated — and the sort key this week isn’t a severity score. It’s the date printed beside it.

1 · The box that decides who gets on your network got a three-day date. On Sep 16 CISA added CVE-2026-76460 in Cisco Identity Services Engine to the Known Exploited Vulnerabilities catalog, filed under CWE-648, Incorrect Use of Privileged APIs, with a remediation date of Sep 19 — three days, and binding on federal civilian agencies only. Cisco’s own advisory scores it 10.0; CISA publishes no CVSS score in KEV, so that number is Cisco’s and nobody else’s. Cisco PSIRT states it is aware of active exploitation, and it is a zero-day. The shape of it: a remote, unauthenticated attacker sends crafted requests to an API endpoint that does not apply sufficient authentication controls, bypasses authentication, and can execute commands with root privileges — which includes hiding or deleting the indicators that any of it happened. It affects Cisco ISE and ISE-PIC regardless of device configuration, which removes the usual “we don’t have that feature turned on” exit. Fixed in 3.5 Patch 4 · 3.4 Patch 7 · 3.3 Patch 12 · 3.2 Patch 11 · 3.1 Patch 12. Read that product name again and notice what it does for a living: it is the appliance that decides who is allowed onto the network.

→ cisa.gov/known-exploited-vulnerabilities-catalog

2 · Two remote-management platforms reached the catalog three days apart. Sep 8: CVE-2026-86218 in N-able N-central — we covered that one last issue. Sep 11: CVE-2026-84869 in ConnectWise ScreenConnect — CWE-269 Improper Privilege Management plus CWE-862 Missing Authorization, with a remediation date for federal civilian agencies of Sep 14, again three days. The ScreenConnect flaw affects the client prior to 26.6.5: missing authorization controls allow file transfer and execution through an active remote session without host confirmation. Huntress reported it exploited in the wild since 2026-08-20 — roughly three weeks before it appeared on the catalog — and reported it showing worm-like behaviour, with a modified ScreenConnect instance deploying four VBScript files for persistence and propagation to other ScreenConnect clients. That is Huntress’s reported behaviour, not our observation. The fix is 26.6.5 or later; ConnectWise’s interim mitigation is to disable TransferFiles permissions. We are deliberately not quoting a severity number on either of these, because the whole argument of this issue is that the date outranks the score — and if you run an MSP, or you buy from one, both of those products are the thing that reaches every system in the book of business.

→ cisa.gov/known-exploited-vulnerabilities-catalog

3 · A vendor advisory and a KEV entry landed on the same day, which is what “zero-day” looks like in the record. On Sep 14 CISA added CVE-2026-76461 in Cisco Secure Email Gateway — CWE-89, SQL injection — with a remediation date for federal civilian agencies of Sep 17. Cisco’s advisory for it published Sep 14 as well: same day. There is no user interaction and no authentication in the path — a crafted email passing through the gateway carries SQL statements, and exploitation can reach root command execution on the underlying OS. Affects AsyncOS 16.5, 16.0, and 15.5 and earlier, on-prem physical and virtual appliances. Fixed in AsyncOS 15.5.5-0141 · 16.0.4-3021 · 16.5.0-780, and there is no workaround — the only lever is the upgrade. Sit with the delivery mechanism for a second: the thing you bought to inspect hostile email is compromised by hostile email, in transit, with nobody clicking anything.

→ cisa.gov/known-exploited-vulnerabilities-catalog

 

The Hardened Stack

Deep Dive: you wrote down what answers the internet. Now stop ranking it by the wrong number.

Last week’s afternoon produced a register: everything of yours that answers the internet, tagged, owned, dated. Step 3 of that afternoon said to check the KEV catalog by product name, not by score. This week is what to do with what came back — because the catalog hands you a ranking for free, and almost nobody reads it, because it does not look like a ranking. It looks like a date.

Every entry in CISA’s Known Exploited Vulnerabilities catalog carries a dueDate field. It is not a severity score. It is a remediation deadline, and under BOD 26-04, Prioritizing Security Updates Based on Risk, issued June 10, 2026, that deadline already folds in the four things you were going to weigh by hand anyway: whether the asset is exposed, whether the flaw is being exploited, whether exploitation can be automated, and whether it yields partial or total control. The judgement has been made. It ships as an integer.

The scope clause, and it is not optional: those deadlines are compulsory for Federal Civilian Executive Branch agencies only. They do not bind your company, your MSP, or your clients, and nobody is failing an obligation by missing one. For everyone outside FCEB, the dueDate is a free published risk signal — copy the signal, never a claim of compliance. Binding for federal civilian agencies; free for everyone else to copy. That is the entire offer, and it is a good one.

Here is what the field did to September. Read live on 2026-09-18: catalog version 2026.09.18, 1,715 entries total, 28 added between Sep 1 and Sep 18. Sorted by that deadline, the window splits into exactly two piles — twenty CVEs got three days, eight got fourteen. No middle. And every one of the 28 carries knownRansomwareCampaignUse: “Unknown”, so that field sorted nothing in the window either. The date did all the work.

Now the part that should reorganise your queue. Cisco ISE: scored 10.0 by Cisco’s own advisory — unauthenticated, remote, root. → three days. Acronis Backup (CVE-2026-87886): rated 7.8 by Acronis — a local privilege-escalation issue from insecure file permissions that requires an attacker to already hold authenticated, low-privileged local access to the Linux server. → three days. A 2.2-point spread, two completely different threat models, and the same deadline, because both were observed being exploited. Exploitation is binary. Severity is a continuum. Only one of those is a sort key. The scores are not wrong — Cisco’s 10.0 and Acronis’s 7.8 are honest answers to “how bad is this if it happens.” The date answers a different question: “is somebody doing it.”

Run it the other way and it gets worse for instinct. Google Chromium V8 out-of-bounds write, CVE-2026-87491, added Sep 9 → fourteen days. Acronis Backup local privilege escalation, CVE-2026-87886, added Sep 16 → three days. Rank those two off the top of your head and most people invert them. The browser waited. The backup plugin did not. (For the record, Acronis confirmed exploitation observed in the wild against its cPanel & WHM plugin, and lists affected builds before 1.9.3.1021 for cPanel & WHM, 1.8.11.638 for the Plesk extension, and 1.2.3.238 for the DirectAdmin plugin — all Linux.)

And then the finding that gave this week its kit. Define the category tightly so the count is auditable — products whose purpose is to secure, authenticate, protect, back up, or remotely manage other systems — and the window’s catalog holds ten of them: Cisco Identity Services Engine · Acronis Backup · Cisco Secure Email Gateway · ConnectWise ScreenConnect · Citrix NetScaler · Fortinet (multiple products) · Cisco Secure Firewall Management Center · N-able N-central · SonicWall SMA1000 ×2. All ten landed in the three-day pile. Ten for ten. (MikroTik RouterOS twice is excluded as general networking rather than security tooling; include it and you would say twelve. We say ten, and we say why.)

The tools you bought to do the protecting are assets too. They are also the assets almost nobody writes down — the firewall manager, the mail gateway, the identity appliance, the backup plugin, the remote-access console, every vendor portal that reaches the whole estate. The asset inventory has the servers on it. It rarely has the thing that manages the servers.

THE DUE-DATE SORT — ONE AFTERNOON

1  PULL     the feed. Free, public, no account, no
            scanner, machine-readable:
            known_exploited_vulnerabilities.json
            (same path with .csv if you’d rather,
            or the browsable catalog page)
2  LIST     what you run — and put the SECURITY stack
            on the same list: firewall manager, mail
            gateway, identity box, backup, RMM /
            remote access, every vendor console.
3  MATCH    on the `product` field. By NAME, never by
            score. Read the version off the HOST, not
            off the dashboard. Dashboards report what
            they were told.
4  SORT     dueDate minus dateAdded. That integer is
            the urgency verdict, already made, free.
            Three beats fourteen. Fourteen beats
            not-on-the-list-at-all.
5  DATE IT  name an owner per row, write what you did
            and when. FEDERAL CIVILIAN agencies are
            BOUND by that date. You are free to COPY
            it — which is the whole point.

Step 2 is the step everybody skips, and it is the one with the ten-for-ten record behind it. Step 4 is the one that takes ten seconds and changes the order of the week: dueDate minus dateAdded is a small integer sitting in a free file, and it is more decision-useful than a number you spent an afternoon arguing about in a meeting.

The rule carries over from last issue, unchanged: every claim gets a NUMBER and a DATE. “We’re on top of patching” is a mood. “17 security-stack products inventoried Sep 24; 4 matched KEV by product name; 3 upgraded, 1 mitigated per vendor guidance and diaried; shortest published federal deadline in the set was 3 days; next pass Oct 24” is an artifact — and it is the shape of answer that cyber-insurance applications and client questionnaires keep asking for.

GB014: the security-stack inventory · the free KEV pull · the dueDate sort →

⚠️ KEV remediation dates are compulsory for federal civilian agencies only — outside that scope the date is a free published signal you may copy, never a claim of compliance. Match by product name and read version numbers off the host, not off a dashboard. For anything that was on the catalog before you patched it, record whether you looked for signs it had already been used: patching closes a door, it does not tell you who came through it. If you find evidence of that, follow your incident-response plan and engage counsel and your insurer per its terms. The kit supports vulnerability-management and audit-preparation workflows — a practical starting point to review and adapt for your organization; not legal, compliance, or audit advice.

 

The Boardroom Bridge

Asking for the afternoon without the fear budget

The talking point (a literal script for non-technical execs — steal it)

“We rank patches by severity score, which sounds rigorous and is mostly a guess about a system the scorer has never seen. There is a free federal catalog that publishes a remediation date on every vulnerability that is confirmed to be actively exploited, and that date already accounts for whether the thing is exposed and whether someone is using it right now. Those deadlines are binding on federal civilian agencies — not on us. Nothing stops us copying the sort order for free. In September that catalog gave twenty vulnerabilities three days and eight of them fourteen, and every security and remote-management product added that fortnight was in the three-day pile: the firewall manager, the mail gateway, the identity appliance, the backup plugin, the remote-access tool. Ten for ten. I want one afternoon to check ours against that list and hand you a dated page with an owner on every row. Best case it comes back empty and we’ve written down the inventory we never had. Re-ordering a queue costs nothing.”

Boards do not fund fear. They fund an afternoon that ends in a one-page dated record either way it lands. And this one is cheaper than last week’s: the data source is free, the sort is arithmetic, and the only thing being spent is the order you do things in.

 
The Security Gator  //  Quick Poll
30 Seconds
When something new drops, what actually decides what your team patches first?

Pick the honest one, not the aspirational one. Answers shape the next round of playbooks — anonymous, aggregated, no list-building tricks.

○  The CVSS score ○  Whether it’s on KEV ○  Whichever client shouts loudest ○  Whatever the scanner floated to the top
Tap your answer → one quick confirm → counted.
● Anonymous · aggregated   —   thesecuritygator.com
Next week’s Reader Q&A answers the winning option.
 

This week’s tool — AxiomLens

The afternoon gives you the sorted list. Keeping it true as the estate changes — re-running the match on a schedule, tying each row to the control it evidences, and turning that into something a board reads without translation — is the grind. That rhythm is what AxiomLens systemizes: 106 subcategories, computed coverage, evidence tied to controls, board reports written on your machine. One-time, per named user, and nothing phones home after activation. It supports compliance documentation and audit-prep workflows; a tool, not a certification, and not legal, compliance, or audit advice.

One-time license — check the store for current pricing.

Watch the walkthrough → youtu.be/namYnNbox4k
Sources: CISA Known Exploited Vulnerabilities catalog  |  CISA KEV JSON feed (read 2026-09-18, catalogVersion 2026.09.18)  |  CISA BOD 26-04 — “Prioritizing Security Updates Based on Risk” (Jun 10, 2026)
Severity figures belong to the vendors that published them — Cisco’s 10.0 and Acronis’s 7.8, each named in the sentence that carries it. CISA publishes no CVSS score in KEV; it publishes a date. Counts are arithmetic on the feed as read 2026-09-18.
 
THE SECURITY GATOR  //  BAYOU BYTES  //  EVERY TUESDAY

Reply

Avatar

or to participate