Daily briefing · September 16, 2026
Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISA
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention1 seen before CISA
September 16, 2026 demands immediate attention from network defenders: a wave of 853 new vulnerabilities includes 87 critical-severity entries, with the day dominated by multiple CVSS 10.0 flaws targeting Cisco Identity Services Engine and Cisco's broader security stack. CVE-2026-76460 stands out as the most urgent, with VulnCheck detecting active exploitation in the wild before any CISA confirmation — a clear signal that threat actors moved faster than official channels. Organizations running Cisco ISE, ASA, FMC, or Nexus Dashboard should treat today's advisories as an emergency patching event.
Today’s brief
- VulnCheck detected active exploitation of CVE-2026-76460 (Cisco ISE auth bypass, CVSS 10.0) before CISA could confirm — patch or isolate immediately
- Four separate CVSS 10.0 vulnerabilities hit Cisco Identity Services Engine alone, any one of which allows unauthenticated remote access
- Cisco ASA, FMC, and Nexus Dashboard also receive critical fixes today — the full Cisco security product line is in scope
- Brazil-focused ransomware group thegentlemen is on a rampage, with multiple fresh victims across professional services and retail sectors
Critical highlights
1
CVE-2026-76460◆ VulnCheckCVSS 10affects Cisco Identity Services Engine Software An unauthenticated remote attacker can bypass authentication entirely via a crafted API request to Cisco ISE — VulnCheck observed real-world exploitation before CISA acknowledgment, making this the single most urgent patch of the day. Any internet-exposed ISE instance should be considered actively targeted right now.
2
The Cisco ISE and ISE-PIC REST API is exposed without adequate authorization controls, granting an unauthenticated remote attacker full administrative access through a crafted HTTP request to the exposed port. This is a straight path to complete device takeover with zero credentials required.
3
Emerging from Cisco's own internal security review, this CVSS 10.0 flaw in ISE and ISE-PIC reflects a cluster of internally discovered vulnerabilities addressed in a hardening release — the breadth of the review suggests the attack surface was broader than previously understood. Organizations must apply the hardening release rather than wait for individual patch schedules.
4
A companion to CVE-2026-20130 and also stemming from Cisco's internal audit of ISE and ISE-PIC, this CVSS 10.0 entry signals that multiple critical weaknesses coexisted within the same platform simultaneously. The parallel disclosure reinforces the urgency of applying the full hardening release rather than treating these as isolated issues.
5
A server-side request forgery (SSRF) vulnerability in Altium Enterprise Server's UnifiedLogin service allows an unauthenticated network attacker to make the server issue outbound HTTP requests to arbitrary destinations, including internal services that expose credentials and configuration data. This effectively turns the server into a pivot point for lateral movement into protected network segments.
6
Dell ObjectScale versions prior to 4.4.0.0 are vulnerable to deserialization of untrusted data, enabling an unauthenticated remote attacker to achieve arbitrary code execution. Storage infrastructure platforms are high-value targets for ransomware actors seeking to encrypt or exfiltrate large data sets.
7
CVE-2026-20332CVSS 9.9affects Cisco Secure Firewall Adaptive Security Appliance (ASA) Software Part of Cisco's internal hardening review, this CVSS 9.9 flaw affects Cisco Secure ASA Software, Firewall Threat Defense, and Firewall Management Center — the breadth of affected products means a single unpatched deployment can expose an entire firewall management plane. The severity reflects the potential for attacker-controlled code execution within core perimeter defense infrastructure.
8
CVE-2026-20324CVSS 9.9affects Cisco Secure Firewall Management Center (FMC) An authenticated attacker with an established sftunnel peer relationship can abuse incorrect write permissions in Cisco FMC to place arbitrary files anywhere on the device and escalate to root command execution. In environments where FMC manages large firewall estates, a compromised peer credential translates directly to control of the entire managed firewall fleet.
9
Cisco Nexus Dashboard is affected by improper neutralization of special elements — a CVSS 9.9 injection-class vulnerability discovered during an internal review that could allow attackers to manipulate data center fabric management operations. Network fabric management planes are prime targets for persistent access and lateral movement in enterprise environments.
10
CVE-2026-20330CVSS 9.9affects Cisco Secure Firewall Adaptive Security Appliance (ASA) Software Another CVSS 9.9 entry from Cisco's internal ASA/FTD/FMC hardening release, this vulnerability rounds out a pattern where Cisco's own proactive audit uncovered severe flaws across its entire security product portfolio simultaneously. The coordinated disclosure is a credit to internal security practices, but it also means defenders must patch a wide range of interconnected products in parallel.
Ransomware today
The group thegentlemen has recently claimed victims in Brazil across multiple sectors, including Multipla Contabilidade Empresarial (professional services) and Humboldt, while qilin targeted Alicotrans in the transportation sector. Over the past 30 days, thegentlemen leads all groups in Brazil-focused activity with 9 confirmed victims, followed by krybit, Vexy Ransomware, dragonforce, emperador, and kazu — indicating a sustained and coordinated pressure campaign against Brazilian organizations of all sizes.
Multipla Contabilidade Empresarial BRthegentlemen · Professional Services
Humboldt BRthegentlemen · Other
Alicotrans BRqilin · Transportation
thegentlemen 9krybit 3Vexy Ransomware 2dragonforce 2emperador 2kazu 2
Active groups & APTs
Several threat actor groups are currently tracked as active or recently updated: mosesstaff (Iran), siegedsec (Russia), sinobi, spacebears, thegentlemen, and funksec. While no specific victim counts are attributed to these groups in the current tracking window, their operational status warrants monitoring, particularly mosesstaff given its Iranian nexus and history of destructive operations against infrastructure targets.
Brazil focus
Brazil is facing significant ransomware pressure across a diverse range of sectors in recent weeks, with confirmed victims including amorsaude.com.br (healthcare, lockbit5), Logar Network Solutions (technology, Vexy Ransomware), Tuboaços da Amazônia Ltda. (manufacturing, nightspire), Biotipo Jeans (retail, thegentlemen), Alurwalls (manufacturing, Dark Project), and Alicotrans (transportation, qilin). The concentration of attacks across healthcare, manufacturing, technology, and logistics underscores that no vertical is being spared, and the dominance of thegentlemen in this landscape signals a group with particular operational focus on the Brazilian market.
Humboldtthegentlemen · Other
Multipla Contabilidade Empresarialthegentlemen · Professional Services
Alicotransqilin · Transportation
Tuboaços da Amazônia Ltda.nightspire · Manufacturing
Logar Network SolutionsVexy Ransomware · Technology
amorsaude.com.brlockbit5 · Healthcare
AlurwallsDark Project · Manufacturing
Biotipo Jeansthegentlemen · Retail & E-Commerce
Today’s recommendation: All organizations running Cisco ISE, ASA, FTD, FMC, or Nexus Dashboard must apply today's hardening releases immediately, prioritizing CVE-2026-76460 and CVE-2026-76423 given confirmed active exploitation — if patching cannot be completed within hours, restrict API and management interface exposure at the network perimeter as a temporary control. Altium Enterprise Server and Dell ObjectScale administrators should also treat their respective critical fixes as same-day priorities given the unauthenticated remote exploitation vectors involved.
With unauthenticated remote code execution paths confirmed across core network and identity infrastructure today, now is the moment to validate which of these platforms are actually reachable from the internet or from adjacent trust zones in your own environment.Before an attacker finds it, find it first: run a free initial exposure assessment and see whether your infrastructure is vulnerable to flaws like these.Meet the Autonomous AI Pentest Agent →Previous briefings
September 20, 2026 — Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026 — Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026 — WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026 — Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026 — Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026 — Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026 — Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026 — WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026 — WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026 — GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026 — Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026 — Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →