Cisco Zero-Day CVE-2026-76460 Actively Exploited in ISE. Cisco disclosed its second zero-day in as many days: CVE-2026-76460 in Identity Services Engine carries a perfect CVSS 10.0, enabling unauthenticated remote attackers to bypass authentication via API endpoints, modify network policies, and extract credentials. CISA added it to the KEV catalog immediately, and Cisco recommends emergency upgrades. Learn more
Check Point Critical RCE Flaw CVE-2026-91843 Enables Root Access. A stack-based buffer overflow in the login process of Check Point Security Management and Log Servers allows unauthenticated attackers to execute arbitrary code as root over the network with CVSS 9.8. A LivePatch fix is available and Check Point reports no active exploitation yet, though this follows two recent authentication bypass zero-days in the same product line.
Critical Pre-Auth RCE in Orkes Conductor Exploited in the Wild. CVE-2026-58138 allows attackers to submit malicious workflow definitions that execute arbitrary OS commands via unsandboxed GraalVM evaluators, with no authentication required. Fortinet observed a sharp rise in exploitation attempts originating primarily from Germany, Hong Kong, Indonesia, the UAE, and India. Organizations running Orkes Conductor should update to version 3.30.2 and restrict external API access immediately.
CISA Flags Three Linux Kernel Vulnerabilities Actively Exploited. CISA added CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 to its KEV catalog, covering memory disclosure, denial-of-service, and privilege escalation paths respectively. Federal agencies face a hard deadline of September 21, 2026 under BOD 26-04 to remediate these flaws, and public exploit code for four related Linux kernel root escalation paths was simultaneously released by a security researcher. Learn more
Key Takeaway
Patch Cisco ISE, Check Point management servers, and Orkes Conductor before any other item on your queue this week: all three carry unauthenticated RCE or full authentication bypass with confirmed or near-certain active exploitation.
