All posts

Cisco ISE zero-day CVE-2026-76460 added to CISA KEV

Senserva Watch

Join Senserva Watch and get Three Free Unlimited Audits with our full Claude MCP, a fresh audit credit every quarter, alerts when a CVE or KB you follow changes, critical security updates when they land, the Patch Tuesday wire on release day, and 20% off when you buy.

Join Senserva Watch

One email address. No tenant connection, no agent, no call.

The Senserva daily security read, September 18, 2026

Cisco ISE CVE-2026-76460 is exploited and now KEV-listed

The headline this week is Cisco Identity Services Engine. CVE-2026-76460, an incorrect use of privileged APIs flaw rated CVSS 10, was added to the CISA Known Exploited Vulnerabilities catalog on 2026-09-16. Cisco has confirmed it is a zero-day exploited in attacks, and Help Net Security reports that unauthenticated attackers are bypassing the ISE management interface.

This is the difference between patch eventually and patch now. ISE sits at the center of network access control, so an unauthenticated bypass of its management interface is about as bad as it gets. If you run ISE, treat this as your top priority and apply Cisco's fixed release, then review management interface exposure and logs for signs of prior access.

Other KEV additions and hot movers

Two more entries landed on the KEV list on 2026-09-16 alongside Cisco ISE: Google Pixel improper authorization (CVE-2026-58704, CVSS 8.8) and Acronis Backup incorrect default permissions (CVE-2026-87886).

On the wider exploitation board, several critical CVEs are moving with ransomware linkage. SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10, EPSS 0.85), Broadcom VMware vCenter path traversal (CVE-2026-59310, CVSS 9.8), WebPros cPanel and WHM missing authentication (CVE-2026-41940, EPSS 0.99), and Oracle PeopleSoft PeopleTools (CVE-2026-35273, EPSS 0.95) are all KEV-listed and ransomware-associated. GitLab path traversal (CVE-2026-85706, CVSS 10) and last week's Cisco Secure Email Gateway SQL injection (CVE-2026-76461) remain in the top movers as well.

Windows updates are breaking domain trust

If you already deployed this month's cumulative updates, watch for authentication problems. BleepingComputer reports that Windows 11 update KB5124008 is breaking domain trust for some users, and Microsoft has since released a workaround for Windows domain login authentication issues. Qualys flagged both KB5124008 and KB5124012 in its patch reliability writeup, and Dark Reading notes Microsoft issued emergency fixes after a heavy Patch Tuesday.

The recommended Windows Server 2022 and Windows 10 1809 cumulative updates (KB5046615, KB5046616, KB5046617, KB5046698) carry KEV-listed fixes across dozens of CVEs each, so you still need them. Stage and validate authentication before broad rollout so you do not trade a patched vulnerability for a domain login outage.

Also on the radar

Apple shipped its September 2026 security updates, covering a dozen CVEs reviewed by the Zero Day Initiative. CISA also published a batch of ICS advisories on 2026-09-17 covering Schneider Electric PowerChute, Modicon M340, and NetBotz, plus ABB Ability Edgenius, Hitachi Energy FCP, and Mitsubishi Electric GX Works3. On the Microsoft side, note that Windows 11 24H2 Home and Pro reach end of support in October.

Do this first

Work the confirmed exploitation first, then the reliability risk.

  • Patch Cisco ISE for CVE-2026-76460 now and hunt for management interface abuse; it is KEV-listed and exploited.
  • Check Google Pixel and Acronis Backup against the new KEV additions.
  • Prioritize ransomware-linked KEV entries: SonicWall SMA1000, VMware vCenter, cPanel and WHM, and Oracle PeopleSoft.
  • Stage the Windows KEV cumulative updates but validate domain trust and login, given the KB5124008 issue and Microsoft's workaround.
  • Use the free Senserva Microsoft Patch Tracker to rank your open Microsoft patches by KEV, EPSS, and ransomware linkage, and the non-Microsoft exploited-CVE tracker to follow KEV additions daily.

Sources

Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-09-18.

Senserva is a Microsoft security company and a member of the Microsoft Intelligent Security Association. Senserva audits your Microsoft 365, Intune, Defender, and Entra ID environment: complete patch state, 650+ security checks, and full reports, with clear guidance on what to fix first.

All posts

Patching across Intune, Windows Autopatch, Defender, Azure, and your endpoint managers: see Senserva patching in action.