CVE-2026-76460(cisco / identity_services_engine)

LOWCVSS 10.0 · CRITICALCISA KEV

Signal is active with 39 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

0.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-09-19. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-648

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • identity_services_engine
  • identity_services_engine_passive_identity_connector

Threat summary

  • 46 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked at 39 mentions on most recent observed day (2026-09-17)
  • 46 total mentions across 2 days

Affected systems

Vendors
Products
identity_services_engineidentity_services_engine_passive_identity_connector

5 versions affected across 2 products

Deep dive

Activity timeline46 mentions / 2d
010202939Mentions · 2026-09-16: 7Mentions · 2026-09-17: 3909-1609-17
Referenced assets60 URLs
By indicator
Full discourse20 posts
  • The Hacker News@TheHackersNews

    ‼️ WARNING - New Cisco ISE flaw CVE-2026-76460 is under active exploitation. The CVSS 10.0 auth bypass has no workaround, and successful exploitation may lead to root-level command execution. Affected versions, fixes, and compromise checks: https://thehackernews.com/2026/09/cisco-warns-of-new-zero-day-ise-auth.html

    2312722118.2K
    2.3M followersView on X
  • CISA Cyber@CISACyber

    🛡️ We added Cisco Identity Services Engine vulnerability CVE-2026-76460 & Acronis Backup vulnerability CVE-2026-87886 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/fmmHoeHT3d

    0903387.2K
    302.4K followersView on X
  • kokumօtօ@__kokumoto

    米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに1件と2件の脆弱性を追加。 - CVE-2026-58704 (Google Pixel) - CVE-2026-76460 (Cisco ISE) - CVE-2026-87886 (Acronis Backup) 対処期限は3日後の9/19。 https://www.cisa.gov/news-events/alerts/2026/09/16/cisa-adds-one-known-exploited-vulnerability-catalog https://www.cisa.gov/news-events/alerts/2026/09/16/cisa-adds-two-known-exploited-vulnerabilities-catalog

    10040869
    7.8K followersView on X
  • 서버쟁이 놀이터@ueo0j

    📊 9/17 통합 브리핑 연방 패치 기한이 줄줄이 도래·경과했다. 메일 게이트웨이·NAC·백업·RMM·가상화·방화벽 관리 — "보안을 위해 존재하는 장비"가 집중 표적이다. Cisco SEG는 오늘 마감, vCenter는 랜섬웨어 플래그까지 붙었다. —— 오늘 먼저 —— ① Cisco SEG CVE-2026-76461 — 연방 기한 오늘 메일 1통으로 미인증 root(SQL 인젝션). SEG·SEWM 가상·물리 모두, 설정 무관. Shadowserver 노출 400대+. 미패치는 침해 전제 + IOC 조사. ② VMware vCenter CVE-2026-59310 — 랜섬웨어·27일 경과 Syslog 디렉터리 트래버설→무인증 RCE. knownRansomwareCampaignUse: Known. 47개국 361+ IP 침해 흔적. 7월 패치 실적용 + 외부 노출 여부 확인. ③ ScreenConnect CVE-2026-84869 — 패치만으로 미완 26.6.5 업그레이드 + 호스트 클라이언트 재설치 + 액세스 에이전트 갱신. 8/20부터 웜형 전파. 기한 3일 경과 — IOC까지 한 묶음. —— AI —— ──────── ▣ Salesforce Koa·AIforce — 모델은 안으로, 인터페이스는 밖으로 핵심: Koa는 CRM 특화 추론 모델(NVIDIA Nemotron 3 Super 후속학습, 고객 데이터 미사용·합성 데이터만). AIforce는 앱을 열지 않고 데이터·권한·거버넌스에 접근(Claudeforce MCP 베타·Slackforce·Coworker). 미국 리전 정식은 2026 겨울. 왜 중요한가: 차별화 지점이 모델 성능이 아니라 데이터·권한·감사 계층. 사내 SaaS를 AI에 붙일 때 벤더 MCP의 권한·감사 범위를 먼저 확인. Koa "오류 3배"는 자체 벤치마크 — 독립 검증 없음. https://www.salesforce.com/news/press-releases/2026/09/15/koa-reasoning-model/ ──────── ▣ AI 감속 논쟁 — Dreamforce에서 젠슨 황과 공개 충돌 핵심: Amodei 감속 제안에 Altman·Musk 동조 → 9/14 반도체 지수 5.9%↓. Dreamforce에서 젠슨 황이 "AI 규제는 필요 없다, 안전은 우리에게" 발언. 보안주는 급등(SentinelOne ~16% 등). 왜 중요한가: 안전 담론이 가격에 직접 반영된 사례. 하루 등락을 추세로 읽으면 안 됨(유가·BofA 경고 겹침). 규제 대상 CEO 입장 표명이지 정책 변화가 아님. https://www.cnbc.com/2026/09/15/nvidia-and-anthropic-ceos-diverge-on-ai-safety-at-dreamforce.html ──────── ▣ Anthropic·OpenAI — 외부 안전 평가자 사내 상주 추진 핵심: 제3자 평가자를 프런티어 랩 내부에 두고 사고 보고·공개, 편집권은 기업이 갖지 않는 구조 제안. Meta·Google DeepMind·SpaceX AI는 미확약. METR·Apollo 등 논의 중. 왜 중요한가: CA SB 53·SB 813과 맞물린 자율 규제 단계. 체크포인트 접근·NDA로 "진짜 독립성" 논쟁 남음. 젠슨 황 발언과 정면 대비. https://techcrunch.com/2026/09/16/anthropic-and-openai-want-to-embed-safety-evaluators-will-they-really-be-independent/ ──────── ▣ 에이전트 권한 — Google Home 물리 제어·OpenAI 후원 에이전트 핵심: Google Home이 AI 에이전트의 스마트홈 직접 제어를 개방. OpenAI는 Sponsored Agents(라벨링된 후원 대화)와 Ads Manager 플러그인 테스트(HubSpot·Shopify). Anthropic은 챗·Cowork·Artifacts를 단일 창으로 통합. 왜 중요한가: 대화형 AI 수익이 배너에서 에이전트 대화 자체로 이동. 물리 기기·광고·어시스턴트 경계가 동시에 넓어짐 — 권한 위임·프롬프트 인젝션 피해 범위 확대. https://techcrunch.com/2026/09/16/your-ai-agents-can-now-control-your-google-home-devices/ —— 클라우드·데이터센터·인프라 —— ──────── ▣ 🔴 AWS 중동 리전 — 일부 자원 영구 복구 불가, 멀티 AZ 전제 붕괴 핵심: 바레인(me-south-1) 전체 접근·복구 불가. UAE(me-central-1) mec1-az2만 있던 데이터는 영구 접근 불가. 3~4월 물리적 시설 피해. AWS: "멀티AZ 설계 범위를 초과." 피해 DC 재개 없음. 왜 중요한가: 오늘 인프라 1순위. "멀티 AZ=안전" 가정의 실물 반례. 단일 리전 데이터 목록화·크로스리전 백업·주권 고정 워크로드 점검. 권고는 타 리전 마이그레이션. https://www.theregister.com/off-prem/2026/09/16/aws-says-wartime-damage-means-some-middle-east-cloud-resources-are-gone-for-good/5296830 ──────── ▣ Salesforce 글로벌 장애 — Dreamforce 중, "복구 완료"는 과함 핵심: 내부 로그인 서비스 응답 대기로 자원 고갈. 미·일·인도·영·프·독 등 수백 인스턴스, Hyperforce 특히 타격. 시작 약 07:50 UTC. 재검증 시점엔 완전 해소로 표시되지 않음(잔여를 Hyperforce 일부로 축소). 왜 중요한가: 인증 서비스 하나가 SaaS 전체 단일 실패 지점. 임계 경로면 10시간 대체 절차·Hyperforce 여부·상태 페이지를 직접 확인. 원본 "복구 완료"로 종결 금지. https://www.theregister.com/saas/2026/09/16/salesforce-staggers-back-to-feet-after-global-outage/5296800 ──────── ▣ AI 인프라 병목 — 칩→전기: AEMA 출범·Google 핀란드 원전 PPA 핵심: Emerald AI·Google·NVIDIA가 AEMA(AI Energy Management Alliance) 창립 — DC 전력 동적 조절·계통 접속 가속 목표. Google은 핀란드에 최소 €130억(Hamina 확장+신규 DC), Fortum Loviisa 원전 출력 최대 50%를 22년 구매. 왜 중요한가: 병목이 GPU에서 계통 접속으로 이동했음을 업계가 공식 인정. 원전 PPA가 하이퍼스케일 입지 요건. AEMA는 연합 결성이지 접속 성과는 아님. https://blogs.nvidia.com/blog/ai-energy-management-alliance/ —— 보안·규제 —— ──────── ▣ NIST·CISA — 토큰·어서션 위조·탈취 방어 권고 핵심: 하이브리드/멀티클라우드 SSO·페더레이션·API의 신원 어서션·액세스 토큰·암호 메커니즘 보호 구현 지침. Secure by Design, 연방·CSP 주 대상. 왜 중요한가: 최근 클라우드 침해의 상당수가 취약점보다 토큰 탈취·위조. 화제성은 낮지만 실제 침해 경로의 중심. SSO 조직은 설계 점검 기준으로 즉시 사용 가능. https://www.cisa.gov/resources-tools/resources/protecting-tokens-and-assertions-forgery-theft-and-misuse-implementation-recommendations-agencies ──────── ▣ CISA 사이버 디코이 가이드 — 침해 전제 탐지 핵심: 트립와이어·브레드크럼·허니토큰 등 기만 기술로 침해 후 활동 탐지. MITRE Engage·ATT&CK 매핑. LOTL·합법 자격증명 공격자 겨냥, 고신뢰 경보 수단으로 위치. 왜 중요한가: 경계 방어→침해 전제 내부 탐지를 규제기관이 문서로 지지. 관리 plane이 뚫리는 오늘 패턴과 같은 방향. 소규모 팀도 단계 도입 가능. https://www.cisa.gov/resources-tools/resources/using-cyber-decoys-strengthen-detection-and-response ──────── ▣ 스페인 데이터보호청 — 첫 "AI 기반 침해" 신고 접수 핵심: LLM 기반 AI 에이전트를 사용한 공격이 스페인 당국에 정식 신고. 규제기관 접수 첫 사례. 왜 중요한가: GDPR 침해 신고에 "AI 에이전트 사용"이 실제로 기록되기 시작. EU 대상 서비스는 침해 대응 문서·보고 양식 선점검. https://www.bleepingcomputer.com/news/security/spains-data-agency-gets-first-report-of-ai-powered-data-breach/ ──────── ▣ CISA BOD 26-04 — "모든 CVE 균등 패치"의 종료 핵심: KEV 추가 알림에서 BOD 26-04(위험 기반 보안 업데이트 우선순위) 재인용. 공개 노출 자산의 KEV 고위험 신속 조치·패치 전 침해 점검이 기대치. 민간에도 동일 우선순위 권고. 왜 중요한가: KEV·실악용 중심 운영이 연방 표준으로 고착. 상단 기한 대조표가 그 운영 모델의 실제 적용 형태. https://www.cisa.gov/news-events/alerts/2026/09/16/cisa-adds-one-known-exploited-vulnerability-catalog —— 취약점·해킹 —— ──────── ▣ 🔴 Cisco Secure Email Gateway CVE-2026-76461 — 오늘 마감 핵심: AsyncOS 메일 파싱 SQL 인젝션→하부 OS root 명령. 미인증·무상호작용. SEG·SEWM 설정 무관 취약. Cisco PSIRT가 9월 실악용 확인. KEV 기한 2026-09-17=오늘. 노출 400대+. 왜 중요한가: CVSS급 최상위·메일 1통·우회 없음·실악용·기한 오늘이 동시. 보유 여부→패치→미패치는 IOC까지. AsyncOS 최근 두 번째 제로데이. https://www.bleepingcomputer.com/news/security/new-cisco-secure-email-zero-day-exploited-to-execute-commands-as-root/ ──────── ▣ 🔴 VMware vCenter CVE-2026-59310 — 랜섬웨어 전환 확인 핵심: Syslog 디렉터리 트래버설→무인증 RCE. Broadcom 7/29 패치→KEV 8/18→기한 8/21(27일 경과). 카탈로그 knownRansomwareCampaignUse: Known. 47개국 361+ IP, 노출 vCenter 450대+. 왜 중요한가: "7월에 패치했다" 착각 조직이 오늘의 리스크. vCenter 장악=가상화 계층 일괄 암호화. 빌드 번호로 실적용+외부 노출 차단. https://www.bleepingcomputer.com/news/security/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-gangs/ ──────── ▣ 🔴 ScreenConnect CVE-2026-84869 — 웜형, 8/20부터 악용 핵심: 권한 검증 누락→활성 세션에서 Host 확인 없이 파일 전송·실행(CVSS 9.9). 수정 26.6.5 + 호스트 클라이언트 재설치 + 액세스 에이전트 갱신. 서버 자체는 비대상. 임시 완화: TransferFiles 비활성. KEV 기한 9/14 경과. 왜 중요한가: RMM 침해=관리 엔드포인트 즉시 확산. VBScript 4개로 지속성·웜 전파. 패치 여부와 무관하게 IOC 조사. https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin ──────── ▣ 🟠 Google Pixel 모뎀 CVE-2026-58704 — KEV 기한 9/19 핵심: 셀룰러 모뎀 권한 우회/상승(CVSS ~8.0). 사용자 상호작용 불필요, 인접 네트워크+기본 권한. Google "제한적·표적 악용 가능성." 패치 레벨 2026-09-05 이상. 9월 Pixel 불레틴 110건. 왜 중요한가: 5개 원본이 모두 보고한 유일한 항목. 물리적 근접만으로 무선 공격 — 임원·고위험군 단말 우선. MDM/BYOD Pixel 패치 강제. https://www.bleepingcomputer.com/news/security/google-fixes-actively-exploited-android-zero-day-on-pixel-devices/ ──────── ▣ 🟠 Cisco ISE·Acronis Backup — KEV 기한 9/19 핵심: CVE-2026-76460(ISE 권한 API 오사용), CVE-2026-87886(Acronis 부적절한 기본 권한). 둘 다 실악용·KEV 등재 9/16. Acronis cPanel 플러그인 권한 상승도 실악용 정황. 왜 중요한가: NAC·백업이 동시에 표적. ISE 장악=횡적 이동, 백업은 랜섬 1순위. vCenter와 묶어 관리 plane 일괄 점검. https://www.cisa.gov/news-events/alerts/2026/09/16/cisa-adds-two-known-exploited-vulnerabilities-catalog ──────── ▣ 🟠 Check Point VPN CVE-2026-85102/85103 — "임박", KEV 미등재 핵심: 둘 다 CVSS 9.8. 인증서 신뢰 검증 미비·ASN.1 힙 오버플로→RCE. Gateway+Management Server 영향. 공개 PoC·확인된 실악용 없음·KEV 없음. 네덜란드 NCSC "곧 시도 예상." LivePatch Take 24 등. 왜 중요한가: 인터넷 노출 VPN은 초기 침투 1순위 — 패치 창이 짧음. 단 "악용 중"으로 보고하면 과장. LivePatch 활성화 여부를 직접 확인. https://support.checkpoint.com/results/sk/sk1000117 ──────── ▣ Microsoft 9월 패치 — 기준값 974건, 0-day 2건·KB5124008 회귀 핵심: 집계 기준 차이로 966~997(기준값 974, Tenable 964는 MS 자체 CVE만). 실악용 0-day CVE-2026-85880(ALPC)·CVE-2026-81963(Update Stack), KEV 기한 9/22. KB5124008 적용 후 일부 도메인 trust/secure channel 장애 보고. 왜 중요한가: 역사상 최대 규모. 패치와 회귀를 같이 봐야 함. Critical·외부노출(DNS·Kerberos 등) 우선. 건수 단정 인용 금지. https://www.securityweek.com/microsoft-patches-record-974-vulnerabilities-including-two-exploited-zero-days/ ──────── ▣ 🔴 브라우저 확장 하나로 AI 어시스턴트 장악 핵심: webpage modification+declarativeNetRequest 권한만으로 신뢰된 AI 페이지에 코드 주입(Chrome Gemini Live·Perplexity Comet·Edge·Opera Neon·Claude in Chrome). Chrome 143.0.7499.192·Edge 150.0.4078.48 패치. Comet·Neon·Claude 확장은 패치 시점 비공개. 실악용 보고 없음(연구 단계). 왜 중요한가: 확장 설치 정책=AI 에이전트 보안 경계. 허용목록 운영. Chrome을 올릴 때 V8 KEV(CVE-2026-85046 내일 마감·CVE-2026-87491)도 함께. https://thehackernews.com/2026/09/one-extension-could-hijack-ai.html ──────── ▣ 🟠 Shai-Hulud — AI 코딩 세션이 공급망 침투 경로로 실증 핵심: AI 코딩 어시스턴트 세션 탈취→오염 PyPI→GitHub OAuth→내부 레포 ~100개에 웜 배포→사내 네임스페이스 신뢰로 2차 감염(Mandiant). Artifactory CVE-2026-42016/42018(기한 9/25)과 겹치면 빌드 산출물 오염 경로가 양쪽에서 열림. 왜 중요한가: 신규 위협 카테고리. AI 추천 의존성 체크섬·허용목록, OAuth 격리, 내부 프록시 경유, 사내 네임스페이스도 신뢰 경계로 취급. https://thehackernews.com/2026/09/attacker-hijacks-ai-coding-assistant.html ──────── ▣ 🔴 기한 경과 KEV — MikroTik·GitLab·Cisco FMC 핵심: RouterOS CVE-2026-86060/67277(기한 9/13, MikroTrick 무인증 장악). GitLab CVE-2026-85706(기한 9/14). Cisco Secure FMC CVE-2026-20079(기한 9/12). 뒤 2건은 모델 원본 5건 모두 누락 — KEV 카탈로그 대조에서만 발견. 왜 중요한가: 소스·CI 자격증명(GitLab)·방화벽 관리 plane(FMC)·경계 라우터. 기한 경과=침해 전제 조회. 다중 모델 취합이 1차 카탈로그를 대체하지 못함. https://www.cisa.gov/known-exploited-vulnerabilities-catalog —— 개발자·엔터프라이즈 —— ──────── ▣ Java 27 — Compact Object Headers 기본 ON (non-LTS) 핵심: 객체 헤더 96→64비트, SPECjbb2015 기준 힙 22%·CPU 8% 절감. GC 기본 G1(작은 컨테이너도 Serial→G1). TLS 1.3에 ML-KEM 하이브리드(JEP 527). 출시 2026-09-15. 왜 중요한가: 튜닝 없이 메모리 절감. non-LTS라 검증용. 메모리 빡빡한 워크로드는 G1 전환 벤치 필수. https://openjdk.org/jeps/534 ──────── ▣ Homebrew 7.0.0 — brew vulns·샌드박스 강화 핵심: brew vulns+OSV 연동 advisory DB. 홈 디렉터리 기본 차단, 네트워크 다운로드·오프라인 설치 분리. Intel Mac은 Tier 3 강등, macOS 10.15 지원 종료. 왜 중요한가: 패키지 매니저가 SBOM/취약점 가시성 내재화 — Shai-Hulud류 공급망 대응 실무 도구. CI에서 샌드박스·Intel 러너 영향 먼저 검증. https://brew.sh/2026/09/13/homebrew-7.0.0/ ──────── ▣ Kubernetes v1.37 — Memory QoS·Pod Resource Managers 기본 ON 핵심: Pod-Level Resource Managers·Memory QoS가 Beta로 기본 활성화. CSI Changed Block Tracking API Beta. Bind Mount/EmptyDir 권한으로 컨테이너 저장소 하드닝. 왜 중요한가: 옵트인이 아니라 기본값 변경. 업그레이드 순간 메모리 회수 동작이 바뀔 수 있음. Acronis KEV와 묶어 백업 스택 점검. https://kubernetes.io/blog/2026/09/14/kubernetes-v1-37-memory-qos-graduates-to-beta/ ──────── ▣ GitHub — Copilot 예산을 FinOps·IAM 문제로 재정의 핵심: Copilot 예산 증액 요청 GA(관리자 승인·조정). Code Scanning AI Scan이 CodeQL default setup 없이도 PR에서 사용 가능. classic PAT/SSH의 조직별 SSO authorization 자동화. 왜 중요한가: AI 개발도구가 "허용 여부"에서 사용자별 예산 정책으로 이동. AI Scan은 CodeQL 미도입 레포에 즉시 적용. 토큰 보호 권고와 같은 축. https://github.blog/changelog/2026-09-16-copilot-budget-increase-requests-are-generally-available/ 기한이 산 것은 Chrome V8(내일)·Pixel·ISE·Acronis(9/19)·Windows 0-day(9/22)·Artifactory(9/25)뿐이고, SEG는 오늘·ScreenConnect·MikroTik·GitLab·FMC·vCenter는 이미 지났다. 관리 plane부터 열어라. #IT브리핑 #Cisco #CISA #KEV #VMware #ScreenConnect #AWS #Salesforce #CheckPoint #Microsoft #Pixel #Artifactory #Homebrew #Kubernetes #AI에이전트

    00030366
    70 followersView on X
  • lee1981@lee1981b

    🔥 CyberForge CVE of the Day #054 🚨 CVE-2026-76460 — Cisco ISE Authentication Bypass The system deciding who belongs on your network needs its own identity checks to hold. This API boundary does not. Cisco's published CVE record describes a remote, unauthenticated route into Identity Services Engine through an insufficiently protected API. A crafted request can bypass the web-management authentication boundary without user interaction. Cisco PSIRT confirms active exploitation. The Cisco CNA's CVSS v3.1 score is 10.0 Critical. CISA added the vulnerability to KEV on 16 September 2026. ⚠️ Treat reachable vulnerable nodes as an urgent patching and compromise-assessment priority. 🎯 The quick hit: 🔹 Affected products: Cisco ISE and ISE-PIC. 🔹 The flaw: an API accepts access that should require authentication. 🔹 The response: inventory every node, constrain reachability, preserve evidence and install the correct branch fix. 🔹 The recovery question: did an intruder alter the system before remediation? 🔑 Key details: ⭐ Severity: Critical 📊 CVSS v3.1: 10.0 — Cisco CNA 🧮 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 🧠 Weakness: CWE-648 — Incorrect Use of Privileged APIs 🎯 Targets: Cisco ISE and ISE Passive Identity Connector 🧩 Vulnerable boundary: Network caller → privileged API access 🌐 Attack vector: Network ⚙️ Attack complexity: Low 🔓 Privileges required: None 👆 User interaction: None 🔀 Scope: Changed ⚔️ Confirmed impact: Authentication bypass and unauthorised device access 💥 CVSS impact: High confidentiality, integrity and availability impact 👤 Execution context: Cisco warns root command execution may follow exploitation 🛡️ Fix: Branch-specific releases listed below 🔑 Additional remediation: Assess compromise; recovery and secret review as appropriate 🚨 Active exploitation: Confirmed by Cisco PSIRT; CISA KEV listed 🧪 Reproduction: No credible CVE-specific public PoC established in our search 📋 CISA KEV: Added 2026-09-16; due 2026-09-19 📉 EPSS: No score returned by FIRST at review time 🗓️ Earliest confirmed attacks: Not dated in the reviewed official evidence 🩹 Vendor patch/hotfix: Fixed matrix published 2026-09-16 📜 Vendor bulletin: cisco-sa-ISE-ABP-VNSW7Tn5 🏷️ Researcher name: None attributed in our reviewed evidence 🔬 Campaign research: No detailed public campaign established in this review Status checked: 17 September 2026. The published score is v3.1; a v4.0 score is not supplied in the reviewed CNA record. 🧬 What actually went wrong? A privileged API should verify identity before allowing protected operations, including requests that never pass through the login page. The CNA describes insufficient authentication control on an API endpoint. The failure gives a remote caller unauthorised access to the device through a crafted request. 1️⃣ Untrusted input arrives The attacker reaches the affected API without valid credentials. 2️⃣ The authentication boundary fails The operation accepts a request without enforcing the expected identity check. 3️⃣ Protected access follows The caller gains access outside the intended management login process. CWE-648 does not identify the exact coding error. The URI, parameters and implementation remain undisclosed. ⚔️ The practical attack chain: 1️⃣ Reach a vulnerable API from the attacker's network position. 2️⃣ Submit the crafted request described by the CNA. 3️⃣ Bypass the API's authentication control. 4️⃣ Gain unauthorised access to the device. 5️⃣ Investigate what followed; do not assume a specific payload or persistence mechanism. Steps 2–4 are the disclosed mechanism. Reachability analysis and follow-on investigation are CyberForge guidance. No required companion CVE or weaponised reproduction is established here. 👤 Execution context — what the attacker actually gets. Cisco's operational warning extends to possible root command execution and concealment of local evidence. The public material does not explain every intermediate step from the bypass to that outcome. CyberForge interpretation: Investigate appliance integrity, stored secrets, persistence and telemetry trust when assessing recovery. The wider scope depends on integration permissions, accessible credentials, segmentation and connected services. Not established: universal domain-administrator access, theft, ransomware, persistence or lateral movement. CVSS scope change does not prove an observed pivot. 📦 Affected products and versions: Cisco's advisory covers ISE and ISE-PIC regardless of configuration. The CNA enumerates the following affected ISE builds: 🔴 Cisco ISE — explicitly listed affected builds 🔹 3.1: patches 8–11 🔹 3.2: patches 7–10 🔹 3.3: patches 1–11 🔹 3.4: base 3.4.0 and patches 1–6 🔹 3.5: base 3.5.0 and patches 1–3 🔴 Cisco ISE-PIC — explicitly listed affected builds 🔹 Base 3.4.0 and 3.5.0 appear in the CNA record. Unlisted versions have unknown status in the CNA record. Omission does not certify an older build as safe; use Cisco's fix matrix. 🟢 First fixed releases — ISE / ISE-PIC 🔹 3.1 → 3.1 Patch 12 🔹 3.2 → 3.2 Patch 11 🔹 3.3 → 3.3 Patch 12 🔹 3.4 → 3.4 Patch 7 🔹 3.5 → 3.5 Patch 4 For 3.0, Cisco directs migration to a supported fixed release. Its maintenance footnote mentions 3.0 despite the marker appearing beside the 3.5 row; it does not change the 3.5 fix above. Inventory advice: Check every node, including standby and disaster-recovery systems. Record role, management address and installed patches. 🕰️ Timeline / exploitation window: 🟢 16 September, 16:00 UTC: Cisco advisory published with the fixed-release matrix. 🔴 16 September: CISA added CVE-2026-76460 to KEV. 🔴 16 September, 20:12 UTC: The official CVE record was published, including Cisco's acknowledgement of active exploitation. 🔎 17 September: CyberForge review; official CVE, vendor and KEV evidence checked. FIRST returned no EPSS row. 📋 19 September: Due date recorded in the KEV entry. Operational conclusion: Disclosure time is not the start of a proven attack window. Establish how long each node was vulnerable and reachable, then hunt as far back as retained evidence and exposure history justify. 👁️ Defender hunting guide: Cisco log guidance and CyberForge investigation suggestions follow. No complete campaign IOC set was established. 1️⃣ Establish exposure per node Record versions, patches, API reachability, ACL history and remediation times. Include VPN, administration-network and jump-host access where present. 2️⃣ Review API access telemetry Cisco provides this non-exhaustive username check for every node: show logging application ise-kong/access.log | include dummyuser Cisco's historical-log route uses a support bundle with debug logs and shared-key encryption. After decryption, the access logs are under: ./ise/logs/apigateway/access.log.<date>.gz CyberForge advice: Preserve exports before filtering. The username is one lead; its absence cannot exclude variants, expired logs or tampering. Correlate timestamps, sources and request metadata with administrators, automation and change windows. The log path is not a vulnerable endpoint. 3️⃣ Assess configuration and appliance integrity Analyst suggestions: Compare configuration with approved changes. Investigate unexplained accounts, policies, logging changes and integrations. Use supported collection methods or TAC assistance. Investigate unexpected processes, files and persistence where forensic access permits; avoid ad hoc tooling that could alter evidence. 4️⃣ Correlate independent network evidence Cisco recommends off-device network and firewall review. CyberForge extension: Use flow, DNS and proxy records where available to investigate unusual destinations or transfers around suspicious API activity. Distinguish approved updates, backups and monitoring from unexplained connections. Correlate source node, destination, time and transfer volume with the API evidence. 5️⃣ Review identities and connected secrets Analyst suggestions: Map credentials and keys that the node could access, then examine their use in connected systems. Check for unexpected account changes, new administration sources and activity continuing after remediation. 🩹 Emergency remediation order: 1️⃣ Preserve evidence while containing exposure Capture logs and configuration history with incident responders while containing malicious access. Record defender changes for the investigation timeline. 2️⃣ Deploy the appropriate supported fix Use official Cisco software and the branch matrix above. Confirm prerequisites, compatibility and deployment order; track completion per node. 3️⃣ Verify the running state Confirm each node's installed release, patch level, service health and access controls after maintenance. A downloaded patch is not a verified fix. 4️⃣ Recover suspected compromised nodes Cisco recommends re-imaging affected nodes when malicious activity is suspected, restoring configuration if needed. CyberForge extension: assess backup trust and review what will be restored; otherwise unauthorised settings could return with an apparently successful recovery. 5️⃣ Review and replace exposed secrets This is an analyst recommendation based on access and findings, not a blanket vendor claim that every key was stolen. Coordinate revocation or rotation from a trusted administration path with containment and recovery. Avoid introducing replacement secrets into a still-untrusted node; preserve essential service dependencies. 6️⃣ Validate recovery and continue monitoring Reconcile configuration with the approved baseline, check integrations and monitor further activity. Document unresolved evidence gaps and residual risk. 🧱 Temporary exposure reduction. Cisco offers no workaround that fixes the flaw. Infrastructure ACLs can temporarily restrict incoming traffic to required management and control-plane flows. CyberForge implementation checks: ✅ Identify required flows before changing rules so authentication services remain available. ✅ Apply restrictions to every relevant node and address, including alternate management paths. ✅ Review broad VPN or “trusted network” allowances that grant unnecessary reachability. ✅ Confirm the effective access policy using approved methods and existing telemetry. ✅ Time-limit exceptions and assign an owner to remove them. 🚑 When vulnerability management becomes incident response. Escalate for investigation when API anomalies, unauthorised configuration changes or unexplained network activity suggest access beyond routine administration. 🔴 Unexplained privileged-account or policy changes 🔴 Correlated API and outbound-traffic anomalies 🔴 Evidence of persistence or altered logging 🔴 Connected credentials behaving abnormally after patching These are investigation criteria, not observed campaign behaviours. Coordinate isolation, evidence preservation and credential response. Exposure alone proves neither exfiltration nor ransomware. 📊 CISA KEV and EPSS context. At review on 17 September: 🔹 KEV includes this CVE, added 16 September, due 19 September. 🔹 The retrieved catalogue flags forensic triage Yes and ransomware use Unknown. 🔹 FIRST returned no EPSS record. That means unavailable, not zero probability. The CNA record also carries CISA's SSVC assessment: exploitation active, automatable yes, technical impact total. Direct exploitation evidence already establishes urgency. A missing forecast provides no reason to wait. The catalogue due date is an action date in that programme, not a safe period for other organisations to remain exposed. 🧾 Evidence separation. Vendor-confirmed: API authentication bypass, affected product scope, published fixes and active exploitation. Cisco also provides detection and recovery guidance and warns of possible root-level consequences. Researcher-reported / reproduced: No independently validated CVE-specific public reproduction was established in this review. A generic exploit-collection search result does not prove one exists. CyberForge interpretation: Prioritise reachable identity infrastructure, investigate every node, correlate independent telemetry and assess secrets according to the access actually obtained. Not established: exact vulnerable URI or parameter, implementation-level patch details, mandatory companion CVE, earliest attack date, actor attribution, victim count or a complete IOC set. Independent NVD content could not be retrieved during the report research; scoring here is Cisco CNA scoring. 🔥 CyberForge verdict: CVE-2026-76460 is an actively exploited break in a sensitive authentication boundary. The operational challenge is to close the exposure while determining whether the system's configuration and connected trust relationships remain sound. The correct order is: 1️⃣ Contain reachability and preserve available evidence. 2️⃣ Install the appropriate fix and verify every node. 3️⃣ Hunt the actual exposure period. 4️⃣ Recover suspected compromised nodes through the vendor-supported path. 5️⃣ Revoke or rotate exposed secrets in coordination with recovery. 6️⃣ Monitor connected systems for continued abuse. Repair the trust boundary, then establish whether anyone crossed it before the repair. 🔗 Cisco advisory, fixes and recovery guidance: https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-ISE-ABP-VNSW7Tn5.html 🔗 Official CVE record — Cisco CNA / CISA ADP: https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/76xxx/CVE-2026-76460.json 🔗 CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76460 🔗 FIRST EPSS: https://api.first.org/data/v1/epss?cve=CVE-2026-76460 🔗 NVD record — reference link: https://nvd.nist.gov/vuln/detail/CVE-2026-76460 #CyberSecurity #CVE #Cisco #ThreatHunting #BlueTeam #CyberForge

    00020163
    625 followersView on X
  • sunil kumawat@Sunil_kumawat17

    CVSS 10. Unauthenticated. Actively exploited. CISA KEV due Sep 19. Cisco ISE API auth bypass (CVE-2026-76460) lets a remote attacker skip the web management login. Cisco says successful exploitation can mean root. If you run ISE or ISE-PIC, this is not a Monday patch.

    1001052
    17 followersView on X
  • ITトレンド@it_trend

    Ciscoは「ISE」の42件の脆弱性を公開し、特に認証回避の「CVE-2026-76460」が悪用されています。米CISAも警告を発しており、速やかな修正適用が求められます。 https://it-trend.jp/news/01-232

    10001103
    2.5K followersView on X
  • Daily CyberSecurity@Daily_CyberSec

    An exploited Cisco ISE vulnerability (CVE-2026-76460) allows remote root access. Patch this critical Cisco ISE vulnerability to secure networks. #Cisco #CiscoISE #CVE202676460 #Cybersecurity #InfoSec https://securityonline.info/cisco-ise-vulnerability-exploited/

    00002374
    12.9K followersView on X
  • Cyberdark Impact@kenebeii

    【サイバーセキュリティ動向分析】 1. Cisco ISEの認証バイパス脆弱性(CVE-2026-76460、CVSS 10.0)が実害用 背景 Cisco Identity Services Engine(ISE)は、企業や官公庁のネットワークで「誰が、どの端末で、どこまで入れるか」を制御する中核製品だ。ゼロトラストやネットワークアクセス制御の心臓部にあたる。9月16日、CiscoはAPIエンドポイントの認証制御が不十分である脆弱性CVE-2026-76460を公表した。未認証の遠隔攻撃者が細工したリクエストを送るだけで、ウェブ管理画面の認証を迂回し機器へ不正アクセスできる。設定内容に依存せず、ISEおよびISE-PICの双方が対象になる。CiscoのPSIRTは実害用を確認しており、米CISAは既知悪用脆弱性カタログ(KEV)へ追加し、米連邦機関には9月19日までの対応を求めている。回避策はなく、管理・制御プレーン通信をインフラACLで絞る緩和策しかない。修正版は3.1 Patch 12、3.2 Patch 11、3.3 Patch 12、3.4 Patch 7、3.5 Patch 4。ISE 3.0は保守終了のため移行が必要になる。 影響 ISEが乗っ取られると、ネットワーク全体の認証・認可ポリシーが攻撃者の手に渡る。正規ユーザーのなりすまし、端末の不正登録、セグメント間の横展開、管理プレーン経由でのさらなる侵入が可能になる。ゼロトラストの前提そのものが崩れるため、被害は単一サーバーの侵害にとどまらない。同時期にISE関連の別脆弱性も複数公表されており、認証基盤が集中標的になっている構図が鮮明だ。 対策 直ちに修正パッチへ上げ、パッチ前の期間は管理インターフェースを信頼できる管理網以外から到達不能にする。インターネット公開は原則禁止する。パッチ適用後は、想定外の管理者セッション、新規ネットワークアクセスポリシー、異常なAPI呼び出し、未知のエンドポイント登録をログと監査で洗い出す。CISAがフォレンジック対応を求めている通り、すでに侵害されていた可能性を前提に調査する。ISE-PICは販売終了が進んでおり、長期的にはサポート対象リリースへの統合計画も必要になる。 2. 画像共有サービスGyazoでユーザー情報約2,362万件と画像メタデータ約4.9億件が流出 背景 京都のHelpfeelが運営するGyazoは、スクリーンショットやGIF、動画を手早く共有できる国内発の定番サービスで、開発者やクリエイター、メディア関係者の利用が多い。同社発表によると、2026年9月11日、画像アップロードサーバーの脆弱性を突かれ、システム上で任意コマンドを実行された。同日夜に不審挙動を検知し、12日未明までに侵入経路を遮断、脆弱性も修正した。その後の調査で、第三者がデータベースへアクセスし情報を持ち出したことが判明した。ユーザー情報は約2,362万件で、氏名・ニックネーム、メールアドレス、パスワードハッシュ、利用者ID、端末ID、ログインセッションID、X連携トークン、Google SSOのメール、プロフィール、利用言語、登録・最終ログイン日時、契約プラン、課金ステータス、利用統計などが含まれる。匿名アカウントも件数に含まれるため、実人数は調査中。決済カード番号は含まれない。画像メタデータは、主に2019年1月以前の約4.9億件(全体の約14.4%)に加え、条件を絞って取得された約240万件。画像ID、アップロード元IP、User-Agent、EXIF位置情報、OCRテキスト、タイトル、取得元URL、非公開画像パスフレーズのハッシュなどが対象。画像本体の消失は確認されていないが、画像IDはURLの構成要素であるため、非公開画像の閲覧リスクは完全には否定できない。同社は一部画像の閲覧を一時停止し、認証情報の無効化も実施した。HelpfeelおよびCosenseへの波及は現時点で確認されていない。 影響 パスワードハッシュとセッションID、外部連携トークンが揃うと、パスワード再利用先への侵入、セッション乗っ取り、Xアカウント連携の悪用につながる。OCRテキストとEXIFは、画面に写った社内情報、住所、会議資料、個人の位置情報を別経路で暴露しうる。画像IDによる非公開画像の覗き見は、業務機密や私的画像の二次被害を生む。フィッシングやなりすましの材料としても使いやすい。国内サービスとしては規模が大きく、利用者の職種を考えると企業情報の間接漏えいも無視できない。 対策 利用者は直ちにGyazoのパスワードを変更し、同じまたは類似のパスワードを使う他サービスも変更する。X連携やGoogle SSOを使っている場合は連携を見直し、必要ならトークン無効化と再接続を行う。不審なログイン通知、パスワードリセット、サポートを装ったメールやDMには応じない。非公開画像を業務で使っていた組織は、該当画像の内容を洗い出し、社外秘情報が写っていないか確認する。Helpfeel側は認証情報の無効化と一部閲覧停止を進めているが、利用者側のパスワード変更と監視が二次被害防止の中心になる。 3. スペインデータ保護当局が「AIエージェントによる初の個人データ侵害届出」を公表 背景 スペインデータ保護庁(AEPD)は、広く知られた大規模言語モデルを基盤とするAIエージェントが、人間の細かな操作をあまり介さずに攻撃の複数段階を連鎖させた、とする届出を初めて受けたと明らかにした。被害組織側の申告によれば、エージェントは汎用ファイルの脆弱性探索から始まり、ログインに成功し、アプリ内の弱点を自律的に探し、個人データの改変と請求書へのアクセスまで到達した。当局は、使用モデル名も被害組織名も公表していない。特定モデルや提供者のインフラが侵害されたわけではなく、第三者が汎用エージェントを攻撃手段として使った点が本質だと強調している。調査は継続中で、一件だけで傾向を断言できないとも留保している。それでも規制当局の公式記録に「エージェントが攻撃工程を連鎖させた」と載った意味は大きい。 影響 従来のAI悪用は、フィッシング文面の量産や偵察の補助が中心だった。今回は、目標を与えられたエージェントが探索・侵入・データ操作までつなぐ「エージェント型攻撃」が、実世界の個人データ侵害届出として現れた。速度と反復性が人間の運用を上回り、脆弱な認証、過剰な権限、未修正のアプリ欠陥が短時間で突かれる。EU一般データ保護規則の安全管理・侵害通知義務の解釈にも影響し、データ保護責任者は「人が監視しているから足りる」では説明しにくくなる。 対策 認証は多要素化し、エージェントや自動化ツールに広い権限を与えない。アプリは入力検証と権限分割を徹底し、請求書や個人データへの書き込みは別途承認を要する設計にする。異常なログイン後の短時間での脆弱性スキャン、一括参照、一括更新を検知する。シャドーAI(承認外のエージェント接続)を棚卸しし、外部モデルへのデータ送信とツール実行権限を制限する。インシデント対応計画には「人間が介在しない高速連鎖」を前提とした遮断手順を入れる。 4. イラン国家関与の監視マルウェア「CHOSEN BRICK」を英米蘭が共同警告 背景 英国国家サイバーセキュリティセンター、米連邦捜査局、オランダ一般情報保安庁は、イラン国家関与の攻撃者が2025年以降、反体制派、活動家、ジャーナリストを狙うWindows向けマルウェア「CHOSEN BRICK」を使っていると警告した。標的は英米蘭を含む各国に及ぶ。手法の中心はソーシャルエンジニアリングで、WhatsAppやTelegramなどで関係を築き、Pictory、RunwayML、Norton Antivirus、Telegram、Adobe Flash Player、KeePassなどの正規ソフト、あるいは偽のMRI検査結果を装ったファイルを開かせる。企業端末でブロックされると私用端末へ誘導する例もある。マルウェアはWindows専用で、スタートアップのレジストリ(主に現在のユーザーのRunキー)で再起動後も残る。Microsoft Defenderに除外を追加して隠蔽し、指揮命令はTelegram経由。感染端末ごとに別ボットを割り当て、相互追跡を難しくする。機能はプロセス・システム情報の収集、画面キャプチャ、マイク録音、ブラウザ上のWhatsApp・Telegramデータの取得、メール窃取、追加マルウェアの導入、ファイル削除、端末ワイプに及ぶ。一部被害者の個人情報は親イラン系リークサイトに掲載され、嫌がらせや安全上のリスクにつながっている。FBIはイラン情報保安省の関与を指摘している。 影響 技術的な横展開能力は限定的でも、個人の連絡先・位置推定・会話・画面・音声がまとめて奪われる。漏洩情報が公開されれば、関係者全体の安全が損なわれる。企業端末から私用端末へ誘導されるため、組織の境界防御だけでは足りない。ジャーナリストや人権関連団体、中東情勢に関わる組織は、業務端末だけでなく個人端末が標的になる。 対策 見知らぬ、あるいは急に親密になった相手からの実行ファイルは開かない。正規ソフトでも公式配布元以外からは入れない。Windowsの起動登録、Defender除外、未知のTelegramボット通信を監視する。メッセージアプリでのファイル受信ポリシーを厳しくし、業務用と私用を分ける。標的になりうる個人は端末のフルディスク暗号化、最新パッチ、多要素認証、不審なマイク・画面キャプチャの兆候確認を徹底する。感染が疑われる場合は端末を隔離し、専門機関へ相談する。 5. 遠隔支援ソフトConnectWise ScreenConnectのクライアント脆弱性が実害用 背景 CVE-2026-84869は、ScreenConnectクライアントの認可欠如・権限管理不備で、CVSS 9.9。稼働中のリモートセッションで、ホスト側の確認なしにファイル転送と実行が可能になる場合がある。サーバー自体は対象外で、影響は26.6.5より前のクライアント。ConnectWiseは9月8日に26.6.5を出し、CISAはKEVに追加した。Huntressなどの観測では、改変クライアントやセッションを使い、VBScriptを接続先へ送り永続化と拡散を図る動きが8月下旬以降に確認されている。ソーシャルエンジニアリングで正規でないクライアントを入れさせる事例もある。 影響 MSPやヘルプデスクが日常的に使う製品だけに、一度セッションを握られると、接続先へ次々と不正ファイルを実行できる。ランサムウェアやバックドアの配布経路になりやすく、「正規の遠隔支援」に紛れるため検知が遅れやすい。 対策 オンプレミスは26.6.5以降へ上げ、ホストクライアントとアクセスエージェントを再インストールする。クラウド側サーバーは更新済みでも、クライアント更新を怠ると残る。暫定でファイル転送権限を無効化する。未知のScreenConnectクライアント、異常なファイル転送、新規のVBScript実行を監視する。従業員には正規ポータル以外の遠隔支援ソフト導入を禁じる。 6. Check Point管理・ログサーバーの未認証ルート実行脆弱性 背景 Check Pointは、Security ManagementおよびLog Serverのログイン処理におけるスタックバッファオーバーフローCVE-2026-91843について緊急修正を出した。未認証の遠隔攻撃者が任意コードをルート権限で実行しうる、という内容だ。境界防御製品の管理面が直接狙われる類型で、ファイアウォール本体より管理コンソールの露出が問題になる。 影響 管理サーバーが落ちれば、ポリシー改ざん、ログ消去、配下ゲートウェイの一括侵害につながる。攻撃者は「守る側の目」を消してから内部へ進める。 対策 ベンダー修正を最優先で適用する。管理・ログサーバーをインターネットから隔離し、管理専用ネットワークと多要素認証、接続元制限を徹底する。修正前後の不審なログイン失敗、異常プロセス、設定変更を監査する。 7. Windows 11セキュリティ更新KB5124008が一部環境でActive Directoryの信頼関係を破壊 背景 Microsoftは、Windows 11向け更新KB5124008が一部の企業端末でActive Directoryのドメイン信頼を壊し、正当なドメイン資格情報でもログオンできない事例を調査している。セキュリティ修正が認証基盤の副作用を起こす、典型的なパッチ運用リスクだ。9月の大規模パッチサイクルと重なり、適用急ぐ現場ほど影響が出やすい。 影響 ドメイン参加端末でログオン不能になれば、業務停止、リモートワーク不能、ヘルプデスク逼迫が起きる。急ぎの切り戻しが、別の脆弱性放置につながる恐れもある。 対策 本番一斉適用前に、ドメイン参加の代表構成で検証する。既に被害が出た場合は既知の回避手順や更新の一時停止、影響端末の切り戻しを検討しつつ、ログオン不能の範囲を把握する。パッチ品質と脆弱性放置のトレードオフを、変更管理プロセスに明示する。 8. その他、同日前後に押さえるべき動き Google Pixelの悪用確認ゼロデイ 9月のPixel向け修正は約110件で、モデム周辺の権限昇格CVE-2026-58704が標的型攻撃で使われていた。基地局や電波近傍からの攻撃になりうる領域で、Pixel利用者は9月パッチを直ちに入れる。 米司法当局によるNightmareStresserドメイン差し押さえ DDoS代行サービスNightmareStresser関連ドメインが差し押さえられた。攻撃の「注文窓口」を潰す摘発だが、類似サービスはすぐ代替される。重要サービス側はDDoS耐性と契約上の緩和策を維持する。 米電力会社CenterPoint Energyの顧客情報漏えい インターネットに面した社内システム経由で、一部顧客の個人情報が第三者に渡ったと開示された。重要インフラの顧客接点が狙われる流れは続いており、外部公開面の棚卸しと顧客通知・監視が必要になる。 ロート製薬の通販関連システム 9月10日に通販システムの不正アクセス可能性を確認し、その後の調査で顧客対応用の通話音声データと付随情報、顧客管理システムの情報が取得された可能性があると公表した。件数は調査中。主要業務への影響は確認されていないが、音声は内容そのものが機微だ。顧客は同社や通販を装う不審な電話・メール・SMSに応じない。組織側は通話録音・CRMのアクセス権限、外部公開面、委託先を再点検する必要がある。 Oracleの9月セキュリティ更新 複数製品ファミリーで大規模修正が出ており、認証不要で遠隔悪用可能な重大件も含まれる。データベース、ミドルウェア、Java関連を抱える組織は適用計画を前倒しする。 横断的に見える傾向 第一に、認証と遠隔管理が集中砲火を受けている。ISE、ScreenConnect、Check Point管理面は、いずれも「守るための入口」が入口になる。第二に、国内ではアップロード面の脆弱性から大規模なアカウント情報とメタデータが流出する古典的パターンが、依然として最大級の実害を出す。第三に、攻撃側の自動化がエージェント段階に入り、防御側も人間の目だけに頼れなくなっている。第四に、国家関与の監視は高度なゼロデイより、信頼関係を作って実行ファイルを開かせる手法を使い続けている。 今日時点で優先すべき実務は明確だ。ISEとScreenConnectとCheck Point管理面の緊急パッチ、Gyazo利用者の認証情報ローテーション、Pixelを含む端末更新、遠隔支援ソフトと通話録音・CRMの露出点検、そして「正規の会話」や「正規のAIツール」を装った侵入への警戒である。脆弱性の数そのものより、認証を握る製品と、人が信頼して開くファイルが、いま最も高いリスク面になっている。 Explain AI agent attack chains Zero Trust network architecture Summarize cyber news daily

    000101.8K
    837 followersView on X
  • The CyberSec Guru@thecybersecguru

    🚨 BREAKING: Cisco ISE CVE-2026-76460 is being actively exploited in the wild. Full technical breakdown, IOCs & remediation: https://thecybersecguru.com/news/cisco-ise-cve-2026-76460-authentication-bypass/ The CVSS 10.0 flaw allows unauthenticated remote attackers to bypass authentication through an API endpoint and gain access to Cisco ISE. Successful exploitation can lead to root-level command execution. ⚠️ No workaround is available. Affected: Cisco ISE + ISE-PIC 🔎 Hunt for suspicious usernames in ise-kong/access.log. Patches are available now.

    0001087
    1.6K followersView on X
  • TwitGri@TwitGri

    ⚠️ Cisco ISE : CVE-2026-76460 (CVSS 10) est activement exploitée. Un attaquant distant non authentifié peut contourner l’authentification et obtenir un accès root. Patches : 3.1 P12, 3.2 P11, 3.3 P12, 3.4 P7, 3.5 P4. #Cyber #Cisco

    1000036
    36 followersView on X
  • sunil kumawat@Sunil_kumawat17

    @ThreatAft Correct: CVE-2026-76460 is actively exploited and in CISA KEV. Cisco says successful exploitation can mean root, so exposed ISE management should be treated as potentially owned—not just patched.

    1000040
    17 followersView on X
  • ThreatAft@ThreatAft

    🚨 CISCO SEPTEMBER 2026 HARDENING — 20+ CVEs, CVSS 10.0 ×4 Cisco ISE: 4 critical flaws + 7 more CVE-2026-76460 ACTIVELY EXPLOITED — CISA KEV NO WORKAROUNDS. PATCH NOW. → https://threataft.com/articles/cisco-september-2026-hardening-mass-disclosure #Cisco #CVE #CVSS10 #PatchNow #CyberSecurity #CyberSecurity #ThreatIntel

    1000060
    43 followersView on X
  • P.K. Sharma@_pksharma

    Two exploited flaws, one US federal deadline: Saturday 19 September. They are not the same job. On 16 September CISA added Cisco ISE (CVE-2026-76460) and the Acronis Backup plugin for cPanel & WHM (CVE-2026-87886) to its Known Exploited Vulnerabilities catalogue. 🔐 Cisco ISE: CVSS 10.0. No login needed, just network reach to an API endpoint. Cisco says attackers "may obtain command execution with root privileges" and could then hide the evidence. On the box that decides who joins your network. 🗄️ Acronis: CVSS 7.8, a "local" privilege escalation. Sounds contained, but on shared hosting local accounts are what the provider sells. The fix was out on 11 September, four days before the advisory named it. 🕳️ The gap: at 07:39 UTC on 17 September the Acronis CVE was still Reserved at http://CVE.org and missing from NVD. NVD-fed tooling will not flag it. ⏱️ For UK organisations the three-day date binds nobody. Cyber Essentials allows at most 14 days from release: 30 September for Cisco, 25 September for Acronis. A ceiling, not a target. What to do this week: • Collect ISE support bundles and firewall logs from every node, run Cisco's access log check, then upgrade (3.1 P12, 3.2 P11, 3.3 P12, 3.4 P7, 3.5 P4) • Find every cPanel or Plesk server with the Acronis plugin, including ones your host runs, and confirm build 1.9.3.1021 or 1.8.11.638 • Add CVE-2026-87886 to your tracker by hand The question for next week's review: who could reach these systems before the fixes existed? Full briefing: https://www.pk-sharma.com/briefing/cisco-ise-acronis-cpanel-kev-three-day-deadline #CyberSecurity #VulnerabilityManagement #CISA #CyberEssentials #ThreatIntelligence

    000003
    176 followersView on X
  • The Daily Tech Feed@dailytechonx

    Critical alert: A 10.0 zero-day in Cisco ISE/ISE-PIC (CVE-2026-76460) is being actively exploited. Remote, unauthenticated attackers can bypass API authentication, gain root-level control, and compromise entire network identity backbones. Updates now released for ISE 3.1-3.5; version 3.0 is unsupported and should be upgraded. Monitor management interface access, review logs for unusual API activity, and apply network access filters. Strong action required. #CybersecurityNews #ISE #Cisco #ZeroDay #NetworkSecurity #CVE2026 #ZeroDay #Cisco #ISE #NetworkSecurity #CVE2026 #CybersecurityNews https://thedailytechfeed.com/cisco-ise-faces-critical-cve-2026-76460-zero-day-under-active-exploit/

    0000010
    722 followersView on X
  • Orion84@Orion84x

    Cisco ISE CVSS 10 auth bypass (CVE-2026-76460) is being exploited NOW. Unauth remote hit on management API; CISA KEV, short patch clock. If you run ISE/ISE-PIC: patch to fixed 3.x builds today and hunt access.log. #CyberSecurity #CVE #ZeroDay Link: https://www.bleepingcomputer.com/news/security/cisco-warns-of-identity-service-engine-zero-day-exploited-in-attacks/

    0000012
    7 followersView on X
  • Looptech Co.@l8ptech

    🚨 Authentication Bypass في Cisco ISE: ثغرة حرجة تستدعي التحديث الفوري أصدر المركز الوطني الإرشادي للأمن السيبراني تنبيهًا بشأن الثغرة CVE-2026-76460 في Cisco ISE، والتي قد تسمح بتجاوز المصادقة والوصول غير المصرح به إلى واجهة الإدارة. 🔗 اقرأ المزيد: https://zurl.co/EaEqv https://t.co/EqtMPDF2xt

    0000017
    2.1K followersView on X
  • Shah Sheikh@shah_sheikh

    Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460): Two days after it warned customers about an actively exploited email gateway zero-day, Cisco confirmed one more flaw is being targeted: CVE-2026-76460, an… https://www.helpnetsecurity.com/2026/09/17/cisco-ise-vulnerability-exploited-cve-2026-76460/?utm_source=dlvr.it&utm_medium=twitter https://t.co/OECHiMlytr

    0000028
    2.3K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews

    Cisco issued emergency patches for a critical Cisco ISE zero-day, CVE-2026-76460. Active exploitation can bypass authentication, gain root access, and hide compromise. #Cisco #ISE #CISA https://www.hendryadrian.com/active-exploitation-triggers-emergency-patch-for-cisco-ise-zero-day/

    00000104
    4.7K followersView on X
  • Help Net Security@helpnetsecurity

    Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) - https://www.helpnetsecurity.com/2026/09/17/cisco-ise-vulnerability-exploited-cve-2026-76460/ - @Cisco #AccessControl #Enterprise #Exploit #IdentityVerification #Cybersecurity #CybersecurityNews https://t.co/vRX32nWdl4

    00000179
    60.2K followersView on X
CPE platform detail92 entries

92 of 92 entries

PartVendorProductVersionTarget SWTarget HW
Appciscoidentity_services_engine3.1.0--
Appciscoidentity_services_engine3.1.0--
Appciscoidentity_services_engine3.1.0--
Appciscoidentity_services_engine3.1.0--
Appciscoidentity_services_engine3.1.0--
Appciscoidentity_services_engine3.1.0--
Appciscoidentity_services_engine3.1.0--
Appciscoidentity_services_engine3.1.0--
Appciscoidentity_services_engine3.1.0--
Appciscoidentity_services_engine3.1.0--
Appciscoidentity_services_engine3.1.0--
Appciscoidentity_services_engine3.1.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.5.0--
Appciscoidentity_services_engine3.5.0--
Appciscoidentity_services_engine3.5.0--
Appciscoidentity_services_engine3.5.0--
Appciscoidentity_services_engine_passive_identity_connector3.1.0--
Appciscoidentity_services_engine_passive_identity_connector3.1.0--
Appciscoidentity_services_engine_passive_identity_connector3.1.0--
Appciscoidentity_services_engine_passive_identity_connector3.1.0--
Appciscoidentity_services_engine_passive_identity_connector3.1.0--
Appciscoidentity_services_engine_passive_identity_connector3.1.0--
Appciscoidentity_services_engine_passive_identity_connector3.1.0--
Appciscoidentity_services_engine_passive_identity_connector3.1.0--
Appciscoidentity_services_engine_passive_identity_connector3.1.0--
Appciscoidentity_services_engine_passive_identity_connector3.1.0--
Appciscoidentity_services_engine_passive_identity_connector3.1.0--
Appciscoidentity_services_engine_passive_identity_connector3.1.0--
Appciscoidentity_services_engine_passive_identity_connector3.2.0--
Appciscoidentity_services_engine_passive_identity_connector3.2.0--
Appciscoidentity_services_engine_passive_identity_connector3.2.0--
Appciscoidentity_services_engine_passive_identity_connector3.2.0--
Appciscoidentity_services_engine_passive_identity_connector3.2.0--
Appciscoidentity_services_engine_passive_identity_connector3.2.0--
Appciscoidentity_services_engine_passive_identity_connector3.2.0--
Appciscoidentity_services_engine_passive_identity_connector3.2.0--
Appciscoidentity_services_engine_passive_identity_connector3.2.0--
Appciscoidentity_services_engine_passive_identity_connector3.2.0--
Appciscoidentity_services_engine_passive_identity_connector3.2.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.4.0--
Appciscoidentity_services_engine_passive_identity_connector3.4.0--
Appciscoidentity_services_engine_passive_identity_connector3.4.0--
Appciscoidentity_services_engine_passive_identity_connector3.4.0--
Appciscoidentity_services_engine_passive_identity_connector3.4.0--
Appciscoidentity_services_engine_passive_identity_connector3.4.0--
Appciscoidentity_services_engine_passive_identity_connector3.4.0--
Appciscoidentity_services_engine_passive_identity_connector3.5.0--
Appciscoidentity_services_engine_passive_identity_connector3.5.0--
Appciscoidentity_services_engine_passive_identity_connector3.5.0--
Appciscoidentity_services_engine_passive_identity_connector3.5.0--

Explore more