Habr•September 29, 2026•🇷🇺Translated from Russian

cKEV Index Launches to Prioritize Vulnerabilities Using Urgent Patch Score Methodology

CyberOK has launched the cKEV Index, an open catalog of prioritized vulnerabilities built on the Urgent Patch Score (UPS) methodology. The project responds to the widening gap between AI-accelerated vulnerability discovery and the unchanged time required for compatibility testing, change approval, and safe deployment.

Artificial intelligence now assists attackers in reconnaissance, code analysis, exploit development, and data processing. Anthropic documented two campaigns, GTG-50014 and GTG-50029, where small teams or even single operators used AI agents to analyze Android applications, craft working exploits, and compromise at least four websites. Similar capabilities are lowering the cost of 1-day exploit creation against already disclosed vulnerabilities.

Defenders face the same pressure. CyberOK researchers released the open-source rust-in-peace framework that combines multiple AI-driven techniques for finding, reproducing, and verifying vulnerabilities in open-source projects, including the Linux kernel. Microsoft cited increased AI-assisted findings as a reason for delaying the first cumulative update of Exchange Server Subscription Edition. Oracle patched 1,434 CVEs in a single quarterly update, attributing part of the volume to expanded AI-assisted detection.

The UPS model records verifiable signals—publication dates, PoC availability, weaponized exploits, and confirmed attacks—and maps them to operational phases: Radar, Watch, Track, Prepare, Urgent Patch, and Emergency/IR. Strong signals can immediately elevate priority without traversing every stage. The public cKEV Index currently shows only the two most urgent phases together with abbreviated event histories, CVSS, EPSS, and exploitation details.

Empirical modeling based on 245 vulnerabilities added to CISA KEV in 2025 demonstrated that organizations using early UPS signals completed 35–53% of required patches before the official KEV inclusion date, even under constrained patching capacity. Teams are advised to begin with inventory mapping on broad lists and reserve detailed testing for confirmed high-urgency items affecting their environment.

Related articles

Security NEXT•Vulnerabilities & Exploits

Multiple Vulnerabilities Found in WatchGuard Access Points Including Critical Flaw

WatchGuard Technologies has disclosed three vulnerabilities affecting its WatchGuard AP access point products, one of which is rated critical. The issues were detailed in an advisory published on September 28 and involve flaws in internal API services and a diagnostic command-line interface. CVE-2026-86102 allows OS command injection that can lead to arbitrary shell command execution on the underlying operating system when an attacker has network access. CVE-2026-101891 stems from improper access controls that permit unauthenticated acquisition of valid API sessions. CVE-2026-87969 affects the diagnostic CLI and enables arbitrary OS command execution but requires administrator privileges to exploit. The findings were reported by Security NEXT.

BoletimSec•Vulnerabilities & Exploits

CISA Adds Two Critical Citrix NetScaler Flaws to Known Exploited Vulnerabilities Catalog

The CISA has added two critical vulnerabilities affecting Citrix NetScaler ADC and Gateway to its Known Exploited Vulnerabilities catalog following reports of active global exploitation. Both CVE-2026-88771 and CVE-2026-88772 carry a CVSS score of 9.5 and were patched by Citrix on September 27, the same day they were added to the catalog. The first flaw stems from improper input validation and allows unauthenticated arbitrary command execution on default installations. The second issue involves a buffer overflow that can lead to remote code execution or denial of service when DTLS is enabled on VPN virtual servers. Affected versions include 14.1-73.32, 13.1-63.21 and earlier, with fixes available in 14.1-73.37, 13.1-64.23 and later releases including FIPS variants. The issues were identified by watchTowr on September 26, and Citrix confirmed ongoing attacks against unpatched systems. Organizations are advised to apply patches immediately while preserving evidence and following full incident response procedures.

AntiMalware•Vulnerabilities & Exploits

Apple Patches Zero-Day CVE-2026-86950 in CoreGraphics Exploited in Targeted iOS Attacks

Apple has released emergency security updates for iPhone, iPad, and multiple macOS versions to address a zero-day vulnerability tracked as CVE-2026-86950. The flaw resides in the CoreGraphics framework responsible for rendering images, text, and 2D graphics. It was discovered by Meta Product Security and confirmed to have been used in sophisticated, targeted attacks against specific iOS users. The vulnerability is an out-of-bounds write that could allow arbitrary code execution when processing a specially crafted file. Apple states the attacks were highly selective rather than widespread. Patches are included in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. An erroneous CVE identifier, CVE-2026-20700, appeared in some early reports.

Security NEXT•Vulnerabilities & Exploits

Apple Releases macOS Updates to Fix CoreGraphics Vulnerability Possibly Exploited in Targeted iOS Attacks

Apple has issued security updates for multiple macOS versions to address a serious vulnerability in the CoreGraphics framework. The flaw, tracked as CVE-2026-86950, involves an out-of-bounds write that could allow arbitrary code execution when processing specially crafted files. The company also noted that the same issue may have been exploited in sophisticated, targeted attacks against older versions of iOS. CISA assigned the vulnerability a CVSS v3.1 base score of 8.8, classifying it as High severity. Patches are now available in macOS Tahoe 26.7.1, macOS Sequoia 15.8.1, and the latest macOS Golden Gate 27.0.1 release.