Cisco has issued patches for a maximum-severity flaw in its Identity Services Engine and ISE-PIC products that allows attackers to bypass authentication on an API endpoint and gain unauthorized administrative access, regardless of configuration. Cisco's security team confirmed the vulnerability, tracked as CVE-2026-76460, is being actively exploited and there are no workarounds available, making immediate patching the only defense.
bleepingcomputer.com
· 2026-09-17
Wiz researchers found multiple threat actors exploiting two Artifactory vulnerabilities, CVE-2026-42018 and CVE-2026-42016, to escalate from a low-privileged anonymous session to full administrator access in under five minutes in some cases. Once inside, attackers installed malicious Groovy plugins to run commands and deployed a custom Rust-based backdoor with command-and-control capabilities, alongside webshells and stolen configuration data. A separate critical flaw, CVE-2026-82329, has also been used by other attackers to mint admin tokens on unpatched instances.
bleepingcomputer.com
· 2026-09-11
Cisco has verified that attackers are actively exploiting CVE-2026-20079, a maximum-severity (CVSS 10.0) flaw in its Secure Firewall Management Center software that lets unauthenticated remote attackers bypass login and run commands as root. The company first disclosed the bug in March without evidence of exploitation, but updated its advisory this week to acknowledge PSIRT detected active attacks in August, though it hasn't shared attacker identity or attack timeline details. CISA has since added the flaw to its Known Exploited Vulnerabilities catalog, giving federal agencies until September 12 to patch.
bleepingcomputer.com
· 2026-09-09
Attackers are combining two newly disclosed MikroTik RouterOS vulnerabilities, an SSH authentication bypass (CVE-2026-67276) and a privilege escalation bug (CVE-2026-86060), to seize full control of routers with SSH exposed to the internet. Poland's CERT, which found the flaws with AI assistance, calls the combined exploit 'MikroTrick' and confirms it is being used in real-world attacks. MikroTik patched the issues in RouterOS versions released September 3, alongside a related bandwidth-test flaw that can leak memory or crash devices.
bleepingcomputer.com
· 2026-09-07
A critical vulnerability tracked as CVE-2026-82329 in JFrog's Artifactory repository manager allows attackers to bypass authentication and gain administrator-level access to affected systems. Security researchers report that exploitation attempts began soon after the flaw's public disclosure, putting unpatched deployments at immediate risk.
darkreading.com
· 2026-09-01