securityonline.info 21 Sept 2026, 01:54 UTC

Cisco Warns of Actively Exploited Flaws Enabling Root Access

Cisco Warns of Actively Exploited Flaws Enabling Root Access
CyberSIXT Evidence Panel Source marked as original reporting

BETWEEN 14 and 20 September 2026, CVE Watchtower logged 4,378 new vulnerabilities, including 369 rated critical. Daily Cybersecurity identified 10 as exploited, three of which were also added to CISA’s Known Exploited Vulnerabilities (KEV) catalogue. CISA separately added four exploited flaws not included in Daily Cybersecurity’s set. The report cautions that the comparison is between different date fields and does not establish which source identified exploitation first.

The most serious issues include Cisco Identity Services Engine’s CVE-2026-76460, a CVSS 10.0 authentication bypass that Cisco said was being actively exploited. An unauthenticated attacker can send a crafted request to an ISE API endpoint to reach root-level access; Cisco found the issue while handling a customer case and says there is no workaround. Cisco Secure Email Gateway’s CVE-2026-76461, rated 9.8, is a SQL injection exploitable through a crafted email without authentication. Cisco recommends upgrading to AsyncOS 16.5.0-780 and has published indicators of compromise.

Other highlighted issues affect The Events Calendar WordPress plugin, where CVE-2026-78006 can enable unauthenticated PHP object injection and operating-system command execution; it was fixed in version 6.17.4.1, although exploitation has not been confirmed. CVE-2026-39364 affects Vite development servers and can expose files such as `.env` data; F5 recorded about 32,000 scanning events, not confirmed breaches. Fixed versions are 7.3.2 and 8.0.5. The report recommends prioritising exposed systems under confirmed attack, including applying Linux kernel, Pixel, Acronis and appliance updates.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline