This Week in Change Risk — Week of Sep 14, 2026
This weekly digest is operational intelligence for change and risk owners. No affiliate links appear in this post.
Welcome to This Week in Change Risk for the week of September 14, 2026. A quieter week for KEV volume after last week’s spike, but the two Cisco entries carry the maximum severity score, so the workload landed on emergency-change tracks rather than the monthly window. Here is what mattered for change and risk owners.
KEV additions this week
CISA added four vulnerabilities to the Known Exploited Vulnerabilities catalog between September 14 and 16. Two are the headline: CVE-2026-76461, a critical SQL injection flaw in Cisco Secure Email Gateway (AsyncOS) that can lead to remote code execution, added September 14 with a September 17 remediation due date; and CVE-2026-76460, an incorrect-use-of-privileged-APIs vulnerability in Cisco Identity Services Engine rated CVSS 10.0, added September 16. Rounding out the batch are CVE-2026-58704, an improper-authorization flaw in Google Pixel, and CVE-2026-87886, a local privilege escalation in the Acronis Backup plugin for cPanel and WHM, both added September 16 with September 19 due dates. Two identity and email-gateway flaws at or near CVSS 10 mean the change ticket is not “patch at next window,” it is “emergency change now, with a rollback plan.”
Cloud incidents worth noting
GitHub logged a critical incident on September 13 from 09:16 to 10:44 UTC, during which Pull Requests were fully unavailable for part of the window while API Requests, Issues, Pages, and Actions ran degraded, per GitHub’s status history. The cause was increased database replication delays on GitHub’s collaboration database, which raised error rates on authorization endpoints and spread to dependent services. For teams whose change workflow gates merges through pull requests, an authorization-layer failure at the source-control provider is a change-freeze in disguise, and it happened without a change on your side. Cloudflare also had a rough patch earlier in the window, with Tunnel availability problems running roughly eleven hours from September 11 into September 12, per the outage tracker. The recurring lesson from our Azure outage timeline holds: an upstream provider incident belongs on your change board’s radar, not just your monitoring dashboard.
Vendor moves
PagerDuty moved its SRE Agent Tool for GitHub Code to general availability on September 15, and put AI-powered incident communications from Slack into early access on September 10, per the PagerDuty changelog. The same changelog carries a deprecation worth tracking: the transition from Postmortems to Post-Incident Reviews in the web UI is scheduled to complete by October 31, 2026, so teams with saved postmortem workflows or integrations have a migration on the clock. The weakness to weigh before adopting the SRE Agent: an AI tool that acts on source code raises the stakes on change control and audit trails, and “the agent did it” is not an acceptable line in a post-incident review. Treat agent-initiated changes as changes, with the same approval and rollback expectations you apply to a human.
Compliance and regulatory
The compliance story this week is enforcement pressure rather than new text. The EU’s overlapping regimes, NIS2 and DORA, continue to bite as member-state transposition catches up and financial-sector oversight tightens, per Reed Smith’s EU cybersecurity regulatory tracker. For change owners, the operational takeaway is unchanged from our PCI DSS 6.4.3 analysis: regulators increasingly expect that a routine deploy cannot silently introduce an unauthorized change to a regulated surface, whether that is a payment page under PCI or an incident-reporting obligation under DORA. The gap most teams still carry is evidence. Being compliant on paper and being able to show an auditor the change record, the approval, and the integrity check are three different things, and only the last one survives an audit sample.
Change-management community
The most-discussed operational pain this week was not a breach, it was a patch. Administrators reported widespread Remote Desktop Services failures on Windows Servers immediately after the September 2026 Patch Tuesday update, per community reporting, turning a routine monthly change into an unplanned firefight. This is the exact failure mode a change process is supposed to catch: a vendor update with a regression that a test ring would have surfaced before it hit production. If your patch process pushes straight to a broad server population without a canary group, this month was the reminder to add one. A tested rollback path matters just as much, because pulling a security update creates its own risk when the flaws it fixes are already being exploited.
Chart of the week
We counted CISA KEV additions per ISO week directly from the catalog JSON for the last eight weeks.

This week’s four additions are the quietest in two months and sit well below the eight-week average of 7.5, a sharp drop from last week’s 14. Do not read a slow week as a trend. The volatility itself is the planning problem: a change and patch process sized for the average will be underwater in a spike week and idle in a quiet one. Size your emergency-change capacity for the peaks, because the KEV clock does not care about your sprint boundary. Over these eight weeks the swing ran from 3 in a quiet week to 14 at the peak, a range of more than four to one, and the due dates attached to each entry did not stretch to match. That is the case for a standing emergency-change fast-path rather than a one-off scramble each time a critical entry lands.
The newsletter
If you want this digest in your inbox every Friday, subscribe to the changeriskintel newsletter and get the week’s KEV additions, cloud incidents, and change-management lessons without the noise.
Recommended reading
- Azure Outage History: A Timeline of Change-Triggered Failures
- PCI DSS 6.4.3: Payment-Page Scripts as a Change-Control Problem
- This Week in Change Risk — Week of Sep 7, 2026
Sources
- CISA Known Exploited Vulnerabilities Catalog
- NVD: CVE-2026-76461, Cisco Secure Email Gateway
- NVD: CVE-2026-76460, Cisco Identity Services Engine
- NVD: CVE-2026-87886, Acronis Backup plugin
- GitHub Status History
- PagerDuty Platform Changelog
- Reed Smith: EU Cybersecurity Regulatory Update for 2026
Published September 18, 2026.