Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: actively-exploited (105 articles)Clear

Exploited Cisco ISE zero-day scores a perfect ten and hands attackers root

Cisco warned that attackers are exploiting a critical zero-day in its Identity Services Engine, the platform that decides which devices are allowed onto a network. Tracked as CVE-2026-76460 and scored 10.0, the flaw is an authentication bypass caused by insufficient authentication controls on an API endpoint, so an unauthenticated attacker can send a crafted request, bypass the management interface, and ultimately gain root. It affects ISE and its Passive Identity Connector regardless of configuration, with no workaround beyond restricting network access. Because a rooted appliance sitting at the network's front door can be used to erase evidence, Cisco urges checking external logs. CISA set a three-day federal patch deadline.

Check
Patch Cisco ISE and its Passive Identity Connector to a fixed release immediately, since there is no workaround and exploitation is active, and restrict who can reach the appliance until patched.
Affected
Organizations running Cisco ISE or ISE Passive Identity Connector in any configuration (CVE-2026-76460); an unauthenticated attacker can bypass authentication through an API endpoint and gain root, exploitation confirmed in the wild.
Fix
Patch now, restrict access with infrastructure access lists, cross-check external network and firewall logs since a rooted device can hide its own indicators, and treat any exposed unpatched ISE as likely compromised.

Exploited Issabel PBX flaw uses a shared hardcoded key to run commands unauthenticated

Attackers are exploiting a critical flaw in Issabel Framework, the web interface for the open-source Asterisk-based phone system. Tracked as CVE-2026-89026 and scored 9.8, the flaw stems from a hardcoded token-signing key that is identical across every installation, so an unauthenticated attacker can forge a valid access token, call the system's call-origination endpoint, and make Asterisk run arbitrary operating-system commands. Researchers at VulnCheck flagged it, and the Shadowserver Foundation first saw exploitation on September 9. A patch released on August 1 replaces the shared key with a unique per-installation key. Exposed, unpatched phone systems should be treated as urgent given the low barrier to attack.

Check
Update Issabel Framework to the patched version that replaces the shared signing key, and take the phone system's web interface off the public internet, restricting it to trusted management networks.
Affected
Organizations running internet-exposed Issabel Framework phone systems (CVE-2026-89026); because the signing key is identical everywhere, an unauthenticated attacker can forge a token and run operating-system commands, and exploitation is underway.
Fix
Patch to remove the hardcoded key, restrict and monitor access to the PBX web and management interfaces, hunt for forged-token requests and unexpected command execution, and rotate credentials if compromise is suspected.

Exploited Cisco email gateway flaw lets a crafted email run commands as root

Cisco warned that attackers are exploiting a critical zero-day in its Secure Email Gateway appliances that lets them run commands as root just by sending a crafted email. Tracked as CVE-2026-76461 and scored 9.8, the flaw is a SQL injection in the appliance's email-parsing logic, so an unauthenticated attacker needs no access to the management interface at all. It affects physical and virtual gateways in any configuration, and Cisco confirmed it was exploited as a zero-day before disclosure. CISA added it to its exploited-vulnerabilities catalog with a three-day federal deadline. Because successful attacks grant root, intruders can erase their own tracks, so Cisco urges inspecting mail logs for suspicious activity.

Check
Patch Cisco Secure Email Gateway appliances immediately given active exploitation, and inspect mail and network logs for suspicious SQL statements and signs of compromise, despite the risk that root access erased indicators.
Affected
Organizations running physical or virtual Cisco Secure Email Gateway appliances in any configuration (CVE-2026-76461); an unauthenticated attacker can send a crafted email to run commands as root, exploited in the wild.
Fix
Apply the fixed AsyncOS releases now, hunt for compromise using Cisco's indicators while assuming a rooted device may hide them, and apply the four other critical email-gateway fixes shipped the same day.

Attackers forge admin tokens through a WSO2 API Manager JWT bypass flaw

Attackers are exploiting a JWT authentication-bypass flaw in WSO2 products, including its widely used API Manager and Identity Server. Tracked as CVE-2026-5430 and rated 9.8, the flaw is an algorithm-confusion bug: the token validator accepts JWTs signed with algorithms other than the ones it is configured to trust, so an attacker can craft a forged token that passes validation. That lets them mint tokens as an administrator and take over the deployment, gaining control over the APIs and identities the platform manages. Because WSO2 sits at the center of API and identity infrastructure, a takeover can cascade to everything behind the gateway. Active exploitation attempts have been observed against exposed instances.

Check
Apply WSO2's fixes for the JWT authentication-bypass flaw across API Manager, Identity Server, and other affected products, and keep the Carbon management console and admin interfaces off the public internet.
Affected
Organizations running affected WSO2 products such as API Manager or Identity Server (CVE-2026-5430); an attacker can forge a JWT with an unsupported algorithm to bypass authentication, become an administrator, and take over.
Fix
Patch to fixed WSO2 versions, restrict management interfaces to trusted networks, enforce strict JWT algorithm validation, monitor for forged-token and anomalous admin activity, and rotate keys and tokens if compromise is suspected.

Critical GitLab flaw lets one request read any file from self-hosted servers

CISA warned that attackers are exploiting a critical flaw in self-managed GitLab servers, adding it to its exploited-vulnerabilities catalog with a forensic-triage requirement. Tracked as CVE-2026-85706 and scored 10.0, it is a path-traversal bug in GitLab's repository commits API caused by improper path confinement and missing authentication, letting an unauthenticated attacker read any file on the server with a single crafted request. Exposed files can include SSH keys, database credentials, deploy tokens, CI/CD variables, and source code. GitLab patched it on September 10, and researchers observed in-the-wild probing within about a day. GitLab.com is unaffected; the risk is concentrated on the many self-managed instances organizations run.

Check
Upgrade self-managed GitLab to 19.1.8, 19.2.6, 19.3.2, or later immediately, then rotate secrets the server could expose, including access tokens, deploy tokens, CI/CD variables, SSH keys, and cloud credentials.
Affected
Organizations running self-managed GitLab CE or EE from 18.7 up to the patched releases (CVE-2026-85706); an unauthenticated attacker can read arbitrary files, including secrets and source, in one request.
Fix
Patch now, rotate all potentially exposed secrets, review commits-API and web-server logs for unauthenticated requests with traversal patterns and unusual file access, and treat exposed unpatched instances as possibly already breached.

CISA flags exploited Cisco, Citrix, Fortinet, and WatchGuard edge flaws

CISA added several actively exploited flaws in internet-facing security appliances to its catalog, ordering federal agencies to patch by September 12. The most severe, CVE-2026-20079 scored 10.0, is an authentication bypass in Cisco Secure Firewall Management Center that lets an unauthenticated attacker run scripts and gain root on the device; Cisco confirmed exploitation since August. A Citrix NetScaler authentication bypass, CVE-2026-19490, saw a surge of attacks on September 8, and a Fortinet FortiOS flaw, CVE-2025-25249, is being used to deliver a remote access trojan. Separately, CISA warned that a critical WatchGuard Firebox firewall flaw is now being exploited in ransomware attacks. Edge appliances remain prime targets.

Check
Immediately patch internet-facing Cisco Secure FMC, Citrix NetScaler, Fortinet FortiOS, and WatchGuard Firebox devices to fixed versions, prioritizing anything reachable from the internet, and hunt exposed appliances for signs of compromise.
Affected
Organizations running affected Cisco Secure FMC, Citrix NetScaler, Fortinet FortiOS, or WatchGuard Firebox appliances (CVE-2026-20079, CVE-2026-19490, CVE-2025-25249); all are exploited, from unauthenticated root access to RAT and ransomware deployment.
Fix
Patch these appliances now given the short federal deadline and active exploitation, restrict management interfaces from the internet, monitor for auth-bypass and script-execution activity, and treat any exposed unpatched device as compromised.

N-able ships fourth N-central hotfix in five weeks for exploited pre-auth flaw

N-able released its fourth hotfix in five weeks for its N-central remote monitoring and management platform, this time for a flaw that gives an unauthenticated attacker full "god-mode" access to the console. Tracked as CVE-2026-86218 and scored 10.0, the pre-authentication remote code execution zero-day is being exploited and supersedes all earlier hotfixes, so on-premises systems still on the third hotfix remain vulnerable and must apply the fourth. Hosted instances have already been patched. Researchers also disclosed a separate chain that lets attackers bypass access controls to create unauthorized administrator accounts. Because N-central manages many downstream endpoints, a compromise can cascade across every customer it serves.

Check
Apply N-central hotfix 4 immediately on any on-premises server, since prior hotfixes do not cover this flaw, then audit the console's user list for unauthorized administrator accounts.
Affected
Organizations and managed-service providers running on-premises N-able N-central (CVE-2026-86218); an unauthenticated attacker can execute code and gain full control of the console, and from there potentially reach every managed endpoint.
Fix
Patch to the latest hotfix, strictly limit inbound access to the N-central console, audit for rogue admin accounts and recent changes, monitor managed endpoints, and treat any exposed unpatched server as compromised.

Exploited MikroTik flaw chain gives full router control over exposed SSH

Poland's CERT warned that attackers are exploiting a chain of MikroTik RouterOS flaws, dubbed MikroTrick, to take full administrative control of internet-exposed routers over SSH without valid credentials. The key flaw, CVE-2026-67276 and scored 9.2, is an authentication bypass in how RouterOS checks RSA public keys: an attacker who knows a valid username and the public key can forge a key and log in without the private one. A second flaw then escalates the session to full administrator. MikroTik shipped fixes on September 3, but exploitation began around September 2, and roughly 300,000 devices remain exposed. Compromised edge routers make ideal footholds, so exposed devices should be treated as breached.

Check
Update RouterOS to a fixed release now, take SSH off the internet by restricting it to a management network or VPN, and hunt exposed devices for a rogue user named dash-two.
Affected
Internet-exposed MikroTik RouterOS devices with SSH enabled (CVE-2026-67276); an unauthenticated attacker can bypass SSH authentication and escalate to full administrator, and about 300,000 devices are still exposed and being targeted.
Fix
Patch RouterOS, keep SSH and management interfaces off the public internet, rotate all router and downstream credentials and SSH keys, disable unused services, and rebuild any device confirmed compromised.

Attackers chain two SonicWall VPN zero-days for unauthenticated remote code execution

SonicWall warned that attackers are actively exploiting two zero-day flaws in its SMA 1000 series remote-access VPN appliances, which can be chained for unauthenticated remote code execution. The first, CVE-2026-83548, scored 10.0, is a pre-authentication server-side request forgery flaw in the user-facing portal that lets an unauthenticated attacker abuse the appliance as a proxy and reach sensitive functions. The second, CVE-2026-83549, is a command-injection flaw in the admin console. SonicWall confirmed active exploitation and shipped hotfixes with no workarounds. Because these gateways aggregate remote users' credentials and tie into directory services, compromising one means compromising the authentication system itself. It is the third SMA 1000 zero-day campaign in under a year.

Check
Apply the SonicWall SMA 1000 hotfixes immediately since there are no workarounds and exploitation is active, then hunt the appliance for compromise, including rogue sessions, credential theft, and unexpected outbound requests.
Affected
Organizations running SonicWall SMA 1000 models 6210, 7210, or 8200v on affected versions (CVE-2026-83548, CVE-2026-83549); the flaws chain to unauthenticated remote code execution on an appliance that holds credentials and session state.
Fix
Patch to the fixed hotfix releases now, treat any exposed unpatched appliance as compromised, rotate credentials and session secrets it handled, review logs for exploitation, and limit portal exposure to the internet.

Exploited Sangoma Switchvox flaw gives unauthenticated attackers reverse shells

Attackers are exploiting a critical flaw in Sangoma Switchvox, a widely used enterprise VoIP phone-system platform, to run code on servers without any credentials. Tracked as CVE-2026-9586 and scored 9.3, it is an unauthenticated SQL injection in an internet-facing endpoint that concatenates user-controlled input directly into database queries, letting an attacker execute commands as the database superuser and drop a reverse shell. Researchers at Horizon3 saw exploitation begin on August 30 and warn that most of the roughly 4,000 internet-exposed Switchvox systems may already have been targeted. Sangoma patched the flaw in version 8.4.0.2 back in July, but many systems remain unpatched and reachable.

Check
Update Sangoma Switchvox to 8.4.0.2 or later immediately, and because exploitation is active, review logs for the published indicators, reverse-shell activity, and process-enumeration commands on exposed systems.
Affected
Organizations running internet-exposed Sangoma Switchvox before 8.4.0.2 (CVE-2026-9586); an unauthenticated attacker can inject SQL, execute commands as the database superuser, gain a reverse shell, and take over the phone system.
Fix
Patch to 8.4.0.2, take the management interface off the public internet, hunt for reverse shells and unauthorized database changes, rotate credentials, and treat any exposed unpatched instance as potentially already compromised.