Daily cybersecurity briefing

The Top 10 Cybersecurity Stories, Prioritized Daily

Ten consequential developments selected for impact, urgency, scope, confidence, and practical defensive relevance.

/ Latest and recent editions Browse the complete archive
Latest edition

Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)

Cisco confirmed active exploitation of CVE-2026-76460, an authentication bypass in an ISE API endpoint that lets a remote unauthenticated attacker bypass the web management interface; the fix requires upgrading to 3.3 Patch 12, 3.4 Patch 7, or 3.5 Patch 4, and no workarounds exist. The Shadowserver Foundation separately observed active exploitation of CVE-2026-89026 in Issabel Framework, where a hard-coded HS256 JWT signing key in pbxapi/index.php lets an unauthenticated attacker forge bearer tokens and execute arbitrary OS commands as the Asterisk user; a patch shipped August 1, 2026, replaces the key with one stored in /etc/issabel.conf.

Read this edition

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

WatchTowr confirmed active in-the-wild exploitation of CVE-2026-5430 in WSO2 API Manager (CVSS 9.8), capturing forged admin-privilege JWT tokens on its honeypot network on September 13, 2026; vendor fixes ship as pull requests and update levels spanning API Manager 4.1.0 through 4.6.0, API Control Plane, Traffic Manager, and Universal Gateway. Acronis separately reported limited, targeted exploitation of CVE-2026-87886 in its cPanel/WHM backup plugin based on a single customer report, while CISA added CVE-2026-76461, a Cisco Secure Email Gateway SQL injection, to its Known Exploited Vulnerabilities catalog.

Read this edition

LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server

Cisco confirmed active exploitation of CVE-2026-76461, an unauthenticated SQL-injection flaw in Secure Email Gateway's AsyncOS email parsing that yields root command execution; CISA added it to the KEV catalog with a September 17 patch deadline, and Cisco published IoCs directing defenders to inspect cluster mail_logs for suspicious SQL statements. Volexity attributed the BlueMoon Chrome-Windows chain (CVE-2026-85046, -87491, -85880) to two China-linked actors, UTA0560 and APT31, who targeted NGOs on September 1 through a patch gap in which Chromium source carried the fixes before any stable Chrome release shipped them.

Read this edition

Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploited

Cisco confirmed that state-sponsored and ransomware actors are actively exploiting CVE-2026-20079, an authentication bypass in Secure Firewall Management Center, and N-able shipped an emergency hotfix for CVE-2026-86218, a pre-auth RCE in N-central already exploited in the wild. Sophos separately reported a Linux rootkit on compromised F5 BIG-IP APM appliances that keeps its web shell in memory to evade disk-based detection, while the Dutch NCSC issued an imminent-exploitation warning for two Check Point VPN flaws (CVE-2026-85102, CVE-2026-85103) for which no public proof-of-concept exists yet.

Read this edition

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

CISA added five actively exploited flaws to its KEV catalog—two JFrog Artifactory authorization bugs chained with CVE-2026-82329 to install Rust backdoors and malicious Groovy plugins on self-hosted servers, a ScreenConnect client flaw (CVE-2026-84869) used to push VBScript payloads to newly connected hosts, and two RouterOS flaws exploited in a chain CERT Polska calls MikroTrick—alongside N-able N-central's CVE-2026-86218, a pre-authentication static code injection (CVSS 10.0) fixed in 2026.3 Hotfix 4 with an FCEB patch deadline of September 11. The F5 BIG-IP APM in-memory web shell (c05d5254), which F5 linked to the reclassified CVE-2025-53521 RCE, is described by Sophos and ESET as designed to survive upgrade images because it hooks Apache's apr_dso_load to inject the shell into the libphp module in memory, evading disk-based integrity checks, and the UK NCSC advises investigating for compromise regardless of when the system was updated.

Read this edition

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

CISA added CVE-2026-85706 to its KEV catalog on September 11 after watchTowr observed in-the-wild probes against GitLab's unauthenticated repository-commits API path traversal (CVSS 10.0); self-managed instances should patch to 19.1.8, 19.2.6, or 19.3.2 and review HTTP POST requests to /api/v4/projects/{id}/repository/commits/ URIs containing file.Path parameters. Separately, Wiz confirmed that multiple actors chained CVE-2026-42018 and CVE-2026-42016 against self-hosted JFrog Artifactory between August 15 and September 8 to mint admin tokens, install malicious Groovy plugins, and deploy a Rust-based backdoor, with 49–62% of reachable instances vulnerable to at least one of the three flaws.

Read this edition

PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws

PaperCut released maintenance builds 26.0.5, 25.0.13, and 24.1.10 to replace emergency patches for CVE-2026-81578 and CVE-2026-82078, which GreyNoise and Blackpoint Cyber confirmed a suspected Russian-speaking actor used to breach at least 395 organizations via AI-agent-driven attacks. Cisco confirmed three threat clusters are exploiting CVE-2026-20079 and CVE-2026-20316 in Secure FMC to deploy Qilin ransomware and a Sandworm-linked Cyclops Blink variant, with hotfixes available and CISA mandating federal patching by September 12.

Read this edition