# US regulatory and public-data digest — 7 UTC calendar dates ending 2026-09-29

> Generated 2026-09-29. Source event dates are bounded to 2026-09-23 through 2026-09-29 UTC; active weather and forward-looking Form 144 dates are the documented exceptions.
> An empty section may reflect no qualifying indexed rows or stale source coverage. Check [freshness](https://api.morvs.ai/api/v1/freshness) before treating absence as proof of no event.

## ⚠ Most-actively exploited vulnerabilities (CISA KEV)

- [CVE-2026-88771](https://api.morvs.ai/cve/CVE-2026-88771) — **Citrix NetScaler** · remediate by 2026-09-30
  Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.
- [CVE-2026-88772](https://api.morvs.ai/cve/CVE-2026-88772) — **Citrix NetScaler** · remediate by 2026-09-30
  Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of serv
- [CVE-2026-87902](https://api.morvs.ai/cve/CVE-2026-87902) — **WordPress Core** · remediate by 2026-09-28
  WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the act
- [CVE-2026-65660](https://api.morvs.ai/cve/CVE-2026-65660) — **Microsoft SharePoint** · remediate by 2026-09-28
  Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.
- [CVE-2026-67279](https://api.morvs.ai/cve/CVE-2026-67279) — **MikroTik RouterOS** · remediate by 2026-09-28
  Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerabilit

## ⚠ NHTSA park-it / park-outside vehicle recalls

_No park-it recalls in this window._

## 🏛️ Federal court filings (high-signal NOS codes)

_No notable cases filed in this window._

## 🚨 Recent DOJ press releases

_No DOJ releases in this window._

## 🔒 Newly added OFAC sanctions

_No recently dated OFAC entries._

## 💉 FDA Class I recalls (life-threatening)

_No Class I recalls in this window._

## 💰 Largest insider sells (SEC Form 4)


## Citation

> MORVS. Cross-vertical regulatory digest. Retrieved 2026-09-29T13:35:05.039Z from https://api.morvs.ai/today. Source and reuse terms vary; see https://api.morvs.ai/license.

---

*[Full feed](https://api.morvs.ai/feed.json) · [Dataset catalog](https://api.morvs.ai/datasets/) · [Cross-vertical entity timelines](https://api.morvs.ai/entity/) · [Source terms](https://api.morvs.ai/license)*