Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: root (3 articles)Clear

Exploited Cisco ISE zero-day scores a perfect ten and hands attackers root

Cisco warned that attackers are exploiting a critical zero-day in its Identity Services Engine, the platform that decides which devices are allowed onto a network. Tracked as CVE-2026-76460 and scored 10.0, the flaw is an authentication bypass caused by insufficient authentication controls on an API endpoint, so an unauthenticated attacker can send a crafted request, bypass the management interface, and ultimately gain root. It affects ISE and its Passive Identity Connector regardless of configuration, with no workaround beyond restricting network access. Because a rooted appliance sitting at the network's front door can be used to erase evidence, Cisco urges checking external logs. CISA set a three-day federal patch deadline.

Check
Patch Cisco ISE and its Passive Identity Connector to a fixed release immediately, since there is no workaround and exploitation is active, and restrict who can reach the appliance until patched.
Affected
Organizations running Cisco ISE or ISE Passive Identity Connector in any configuration (CVE-2026-76460); an unauthenticated attacker can bypass authentication through an API endpoint and gain root, exploitation confirmed in the wild.
Fix
Patch now, restrict access with infrastructure access lists, cross-check external network and firewall logs since a rooted device can hide its own indicators, and treat any exposed unpatched ISE as likely compromised.

Critical Check Point management flaw lets unauthenticated attackers gain root

Check Point patched a critical flaw in its management servers that lets an unauthenticated attacker run code as root. Tracked as CVE-2026-91843 and scored 9.8, it is a stack overflow in the login process, which handles requests before a user authenticates, and it can be triggered by a login request carrying an overly long username. It affects Quantum management, Log, and Multi-Domain servers, through the Trusted Clients path. Customers with automatic updates are already protected, and others should apply the vendor's live patch. Check Point reports no exploitation yet, but this is the third serious management-server flaw it has disclosed in weeks, and compromising it means control over the whole firewall estate.

Check
Apply Check Point's live patch for the management-server flaw now if automatic updates are not enabled, and restrict which clients can reach the management, Log, and Multi-Domain servers.
Affected
Organizations running affected Check Point Quantum management, Log, or Multi-Domain servers (CVE-2026-91843); an unauthenticated attacker can trigger a login overflow with a long username to run code as root.
Fix
Patch or confirm automatic updates applied, tightly restrict access to management-plane servers, monitor for anomalous pre-authentication login traffic, and treat the management plane as the highest-value target since it controls every firewall.

Critical Cisco Nexus switch flaw lets unauthenticated attackers run code as root

Cisco patched a critical flaw in its Nexus 9000 data-center switches that lets an unauthenticated, remote attacker execute code as root. Tracked as CVE-2026-20212 and scored 9.8, the bug affects Nexus 9000 models built on Cisco's Silicon One chips and stems from a service that binds to an unrestricted address, leaving TCP ports 43210 and 43211 reachable in the default routing configuration. An attacker who can reach either port sends crafted input that runs with root privileges, and can also crash and reload the device. Cisco reported no known exploitation at disclosure and shipped fixed software, with an access-list workaround for those who cannot patch immediately.

Check
Identify Nexus 9000 switches using Silicon One chips, upgrade to fixed NX-OS releases, and until then apply the access-control-list workaround that blocks TCP ports 43210 and 43211 to the device.
Affected
Organizations running affected Cisco Nexus 9000 switches with Silicon One chips (CVE-2026-20212); a remote, unauthenticated attacker reaching the exposed ports can execute code as root or crash the device, no credentials needed.
Fix
Patch to fixed NX-OS software, apply the access-list workaround and temporary shield until then, restrict management-plane reachability to the switches, and monitor for unexpected connections to the affected ports.