Four vulnerabilities entered CISA’s Known Exploited Vulnerabilities catalog today, and three of them come due Saturday, September 12. The one to deal with first is Cisco’s. CVE-2026-20079 is a 10.0 authentication bypass in Secure Firewall Management Center, and Cisco revised a six-month-old advisory on the same day to say active exploitation has been observed. Advisory revision, exploitation confirmation, KEV listing, and a three-day federal clock all landed together, on the box that administers the firewalls.
It is not the day’s biggest number. That belongs to Mathspace, which says 1,079,819 people were exposed after attackers reached its self-hosted Metabase. But that breach is over: the intrusion ran from August 10, the data left on August 27, the patch went on August 29, and individual notifications began September 6. There is nothing in it for a defender to do tonight. The Cisco deadline is in three days, and the appliance is reachable from the network.
The thread today is not the KEV batch, and it is the more uncomfortable one. In all nine of today’s stories, a fix already existed before the thing that finally made anyone look. Open WebUI’s 0.11.1 shipped 15 days before the 16 CVEs it closes were published inside a single hour, and its release notes say plainly that some security fixes were being withheld. AWS’s 1.1.7 reached PyPI 76 days before the bulletin disclosing the 9.6 it fixes, and 71 days before a separate bulletin credited that same release with a 6.5. Tencent patched a wormable zero-click WeChat flaw on August 21, and it still has no CVE and no advisory. Metabase’s advisory was August 6. The F5 BIG-IP rootkit Sophos took apart runs on a flaw whose federal remediation deadline passed on March 30, 2026, and Shadowserver still counts 795 vulnerable hosts. The gap this publication keeps finding is not between the flaw and the fix. It is between the fix and the record that would tell an administrator the upgrade was worth taking a window for.
After Cisco, the other two Saturday deadlines. The 9.3 NetScaler authentication bypass is harder to act on than to read about: the CVE record carries no description at all, only a mangled version range, and Citrix’s advisory, unchanged since August 19, lists its mitigations as “None.” The 2025 FortiOS heap overflow scores 9.8 in the record and 8.1 from Fortinet, and CISA names FortiSASE among the affected products while the record does not; FortiOS 6.4 has no fixed build in either source. The exploited Chrome V8 zero-day runs to September 23, which is time you will want, because Google rates it Medium and the release note CISA links to still says its security section is coming.
The two evening records are patch-soon work behind all of that: the AWS Postgres MCP server, where AWS’s advisory and AWS’s own patch comment disagree about which mode was exposed, and Open WebUI, where the 8.1 OAuth bypass only bites SQLite deployments — which is the default one.
What is still open. Fortinet’s own advisory could not be read at all from here, so its affected list, fixed builds, and any exploitation language are missing from our story rather than absent from the world. Citrix has said nothing about exploitation three weeks after publishing. Google’s release note has now been blank for two days on a flaw CISA lists as exploited. And the WeChat flaw, patched on August 21, remains invisible to every scanner in every fleet, because there is no identifier to scan for.
Sourcing note: this recap introduces no facts beyond the nine stories it links, each of which carries its own sourcing note. The KEV dates above are carried from those pages, which verified them against CISA’s own cisagov/kev-data mirror on GitHub, since cisa.gov returns 403 to automated retrieval. A re-read of that mirror during this run returned an older catalog version and truncated content, and the NVD records for CVE-2026-20079 and CVE-2026-87491 do not yet carry cisaExploitAdd or cisaActionDue — NVD lags the catalog by hours.
