Weekly briefing: September 14 to September 20, 2026

Cisco warns of actively exploited zero-day ISE authentication bypass (CVE-2026-76460, CVSS 10.0) that may yield root command execution. Google patches Pixel modem privilege escalation flaw CVE-2026-58704, which may be under limited targeted exploitation and was added to CISA KEV. Check Point patched a critical login stack overflow (CVE-2026-91843, CVSS 9.8) allowing unauthenticated attackers to run code as root on management servers.

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Cisco ISE CVE-2026-76460 is under active exploitation and may allow root command execution. The flaw received a maximum CVSS score of 10.0 and was added to CISA's KEV catalog on September 16, 2026.

Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

Google patches CVE-2026-58704, a Pixel modem privilege escalation flaw that may be under limited targeted exploitation. CISA added CVE-2026-58704 to its Known Exploited Vulnerabilities catalog on September 16, 2026 based on evidence of active exploitation.

China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America

FamousSparrow deploys the SparroWocky backdoor against government entities across Latin America.

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

Kaspersky reports three threat clusters targeting Russian enterprises with backdoors, ransomware, wipers and compromised VPN credentials. The NightEagle APT campaign uses GhostContainer backdoor, exploits Active Directory and RDP vulnerabilities.

Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks

Acronis says CVE-2026-87886, a local privilege escalation flaw in its Linux backup plugins, was exploited in limited targeted attacks. CISA added CVE-2026-87886 and CVE-2026-76460 to its KEV catalog on September 16, 2026 based on evidence of active exploitation.

SQL injection vulnerability in Cisco Secure Email Gateway (CVE-2026-76461)

JPCERT/CC issued an alert about CVE-2026-76461, a SQL injection flaw in Cisco Secure Email Gateway that could allow arbitrary command execution. CIS MS-ISAC notes multiple vulnerabilities in Cisco Secure Email products, the most severe allowing remote code execution as root.

Maximum Severity GitLab Flaw Puts Supply Chains at Risk

CIS MS-ISAC says the vulnerability could allow disclosure of sensitive data such as SSH keys and database credentials.

SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

SolarWinds patched an ARM hard-coded static key flaw that could enable unauthenticated remote code execution. Canadian Centre for Cyber Security advisory notes SolarWinds is affected by a vulnerability in Access Rights Manager.

Vulnerability in Moxa products

CERT-FR reports a vulnerability in Moxa products that allows a remote denial of service. Canadian Centre for Cyber Security advisory states Moxa is affected by a vulnerability in the TN-4500B Series.

Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

Check Point patched CVE-2026-91843, a critical login stack overflow that lets unauthenticated attackers run code as root on management servers. Canadian Centre for Cyber Security advisory notes Check Point is affected by a vulnerability in Security Management Server and related products.

Researchers used Claude to hack OpenAI

Ars Technica reports researchers used Claude to reach an OpenAI employee account and sensitive GitHub data. The Hacker News says Claude Opus 5 helped chain forum and login flaws to take over OpenAI staff accounts and access an internal repository.

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

CERT-FR notes multiple WordPress vulnerabilities allowing data confidentiality breach, remote cross-site scripting and security policy bypass.

Written by a language model from the linked articles only. Each sentence cites its sources and was checked against them, mechanically and by a model; sentences that failed either check were removed.