Cisco warned that attackers are exploiting a critical zero-day in its Identity Services Engine, the platform that decides which devices are allowed onto a network. Tracked as CVE-2026-76460 and scored 10.0, the flaw is an authentication bypass caused by insufficient authentication controls on an API endpoint, so an unauthenticated attacker can send a crafted request, bypass the management interface, and ultimately gain root. It affects ISE and its Passive Identity Connector regardless of configuration, with no workaround beyond restricting network access. Because a rooted appliance sitting at the network's front door can be used to erase evidence, Cisco urges checking external logs. CISA set a three-day federal patch deadline.
Attackers are exploiting a critical flaw in Issabel Framework, the web interface for the open-source Asterisk-based phone system. Tracked as CVE-2026-89026 and scored 9.8, the flaw stems from a hardcoded token-signing key that is identical across every installation, so an unauthenticated attacker can forge a valid access token, call the system's call-origination endpoint, and make Asterisk run arbitrary operating-system commands. Researchers at VulnCheck flagged it, and the Shadowserver Foundation first saw exploitation on September 9. A patch released on August 1 replaces the shared key with a unique per-installation key. Exposed, unpatched phone systems should be treated as urgent given the low barrier to attack.
Cisco warned that attackers are exploiting a critical zero-day in its Secure Email Gateway appliances that lets them run commands as root just by sending a crafted email. Tracked as CVE-2026-76461 and scored 9.8, the flaw is a SQL injection in the appliance's email-parsing logic, so an unauthenticated attacker needs no access to the management interface at all. It affects physical and virtual gateways in any configuration, and Cisco confirmed it was exploited as a zero-day before disclosure. CISA added it to its exploited-vulnerabilities catalog with a three-day federal deadline. Because successful attacks grant root, intruders can erase their own tracks, so Cisco urges inspecting mail logs for suspicious activity.
Attackers are exploiting a JWT authentication-bypass flaw in WSO2 products, including its widely used API Manager and Identity Server. Tracked as CVE-2026-5430 and rated 9.8, the flaw is an algorithm-confusion bug: the token validator accepts JWTs signed with algorithms other than the ones it is configured to trust, so an attacker can craft a forged token that passes validation. That lets them mint tokens as an administrator and take over the deployment, gaining control over the APIs and identities the platform manages. Because WSO2 sits at the center of API and identity infrastructure, a takeover can cascade to everything behind the gateway. Active exploitation attempts have been observed against exposed instances.
CISA warned that attackers are exploiting a critical flaw in self-managed GitLab servers, adding it to its exploited-vulnerabilities catalog with a forensic-triage requirement. Tracked as CVE-2026-85706 and scored 10.0, it is a path-traversal bug in GitLab's repository commits API caused by improper path confinement and missing authentication, letting an unauthenticated attacker read any file on the server with a single crafted request. Exposed files can include SSH keys, database credentials, deploy tokens, CI/CD variables, and source code. GitLab patched it on September 10, and researchers observed in-the-wild probing within about a day. GitLab.com is unaffected; the risk is concentrated on the many self-managed instances organizations run.
CISA added several actively exploited flaws in internet-facing security appliances to its catalog, ordering federal agencies to patch by September 12. The most severe, CVE-2026-20079 scored 10.0, is an authentication bypass in Cisco Secure Firewall Management Center that lets an unauthenticated attacker run scripts and gain root on the device; Cisco confirmed exploitation since August. A Citrix NetScaler authentication bypass, CVE-2026-19490, saw a surge of attacks on September 8, and a Fortinet FortiOS flaw, CVE-2025-25249, is being used to deliver a remote access trojan. Separately, CISA warned that a critical WatchGuard Firebox firewall flaw is now being exploited in ransomware attacks. Edge appliances remain prime targets.
N-able released its fourth hotfix in five weeks for its N-central remote monitoring and management platform, this time for a flaw that gives an unauthenticated attacker full "god-mode" access to the console. Tracked as CVE-2026-86218 and scored 10.0, the pre-authentication remote code execution zero-day is being exploited and supersedes all earlier hotfixes, so on-premises systems still on the third hotfix remain vulnerable and must apply the fourth. Hosted instances have already been patched. Researchers also disclosed a separate chain that lets attackers bypass access controls to create unauthorized administrator accounts. Because N-central manages many downstream endpoints, a compromise can cascade across every customer it serves.
Poland's CERT warned that attackers are exploiting a chain of MikroTik RouterOS flaws, dubbed MikroTrick, to take full administrative control of internet-exposed routers over SSH without valid credentials. The key flaw, CVE-2026-67276 and scored 9.2, is an authentication bypass in how RouterOS checks RSA public keys: an attacker who knows a valid username and the public key can forge a key and log in without the private one. A second flaw then escalates the session to full administrator. MikroTik shipped fixes on September 3, but exploitation began around September 2, and roughly 300,000 devices remain exposed. Compromised edge routers make ideal footholds, so exposed devices should be treated as breached.
SonicWall warned that attackers are actively exploiting two zero-day flaws in its SMA 1000 series remote-access VPN appliances, which can be chained for unauthenticated remote code execution. The first, CVE-2026-83548, scored 10.0, is a pre-authentication server-side request forgery flaw in the user-facing portal that lets an unauthenticated attacker abuse the appliance as a proxy and reach sensitive functions. The second, CVE-2026-83549, is a command-injection flaw in the admin console. SonicWall confirmed active exploitation and shipped hotfixes with no workarounds. Because these gateways aggregate remote users' credentials and tie into directory services, compromising one means compromising the authentication system itself. It is the third SMA 1000 zero-day campaign in under a year.
Attackers are exploiting a critical flaw in Sangoma Switchvox, a widely used enterprise VoIP phone-system platform, to run code on servers without any credentials. Tracked as CVE-2026-9586 and scored 9.3, it is an unauthenticated SQL injection in an internet-facing endpoint that concatenates user-controlled input directly into database queries, letting an attacker execute commands as the database superuser and drop a reverse shell. Researchers at Horizon3 saw exploitation begin on August 30 and warn that most of the roughly 4,000 internet-exposed Switchvox systems may already have been targeted. Sangoma patched the flaw in version 8.4.0.2 back in July, but many systems remain unpatched and reachable.