Cisco ISE CVE-2026-76460 is exploited and now KEV-listed
The headline this week is Cisco Identity Services Engine. CVE-2026-76460, an incorrect use of privileged APIs flaw rated CVSS 10, was added to the CISA Known Exploited Vulnerabilities catalog on 2026-09-16. Cisco has confirmed it is a zero-day exploited in attacks, and Help Net Security reports that unauthenticated attackers are bypassing the ISE management interface.
This is the difference between patch eventually and patch now. ISE sits at the center of network access control, so an unauthenticated bypass of its management interface is about as bad as it gets. If you run ISE, treat this as your top priority and apply Cisco's fixed release, then review management interface exposure and logs for signs of prior access.
Other KEV additions and hot movers
Two more entries landed on the KEV list on 2026-09-16 alongside Cisco ISE: Google Pixel improper authorization (CVE-2026-58704, CVSS 8.8) and Acronis Backup incorrect default permissions (CVE-2026-87886).
On the wider exploitation board, several critical CVEs are moving with ransomware linkage. SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10, EPSS 0.85), Broadcom VMware vCenter path traversal (CVE-2026-59310, CVSS 9.8), WebPros cPanel and WHM missing authentication (CVE-2026-41940, EPSS 0.99), and Oracle PeopleSoft PeopleTools (CVE-2026-35273, EPSS 0.95) are all KEV-listed and ransomware-associated. GitLab path traversal (CVE-2026-85706, CVSS 10) and last week's Cisco Secure Email Gateway SQL injection (CVE-2026-76461) remain in the top movers as well.
Windows updates are breaking domain trust
If you already deployed this month's cumulative updates, watch for authentication problems. BleepingComputer reports that Windows 11 update KB5124008 is breaking domain trust for some users, and Microsoft has since released a workaround for Windows domain login authentication issues. Qualys flagged both KB5124008 and KB5124012 in its patch reliability writeup, and Dark Reading notes Microsoft issued emergency fixes after a heavy Patch Tuesday.
The recommended Windows Server 2022 and Windows 10 1809 cumulative updates (KB5046615, KB5046616, KB5046617, KB5046698) carry KEV-listed fixes across dozens of CVEs each, so you still need them. Stage and validate authentication before broad rollout so you do not trade a patched vulnerability for a domain login outage.
Also on the radar
Apple shipped its September 2026 security updates, covering a dozen CVEs reviewed by the Zero Day Initiative. CISA also published a batch of ICS advisories on 2026-09-17 covering Schneider Electric PowerChute, Modicon M340, and NetBotz, plus ABB Ability Edgenius, Hitachi Energy FCP, and Mitsubishi Electric GX Works3. On the Microsoft side, note that Windows 11 24H2 Home and Pro reach end of support in October.
Do this first
Work the confirmed exploitation first, then the reliability risk.
- Patch Cisco ISE for CVE-2026-76460 now and hunt for management interface abuse; it is KEV-listed and exploited.
- Check Google Pixel and Acronis Backup against the new KEV additions.
- Prioritize ransomware-linked KEV entries: SonicWall SMA1000, VMware vCenter, cPanel and WHM, and Oracle PeopleSoft.
- Stage the Windows KEV cumulative updates but validate domain trust and login, given the KB5124008 issue and Microsoft's workaround.
- Use the free Senserva Microsoft Patch Tracker to rank your open Microsoft patches by KEV, EPSS, and ransomware linkage, and the non-Microsoft exploited-CVE tracker to follow KEV additions daily.
Sources
- Help Net Security: Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) (2026-09-17)
- BleepingComputer: Cisco warns of max severity ISE zero-day exploited in attacks (2026-09-17)
- BleepingComputer: Microsoft shares workaround for Windows domain login issues (2026-09-17)
- BleepingComputer: Windows 11 KB5124008 update breaks domain trust for some users (2026-09-16)
- Dark Reading: Microsoft Issues Emergency Fixes After Massive Patch Tuesday (2026-09-15)
- Qualys: Before You Patch. Why Patch Reliability Matters for Confident Deployment (2026-09-15)
- Zero Day Initiative: The Apple Security Update Review for September 2026 (2026-09-16)
- CISA Cybersecurity Advisories: Schneider Electric PowerChute Serial Shutdown (2026-09-17)
Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-09-18.
Senserva is a Microsoft security company and a member of the Microsoft Intelligent Security Association. Senserva audits your Microsoft 365, Intune, Defender, and Entra ID environment: complete patch state, 650+ security checks, and full reports, with clear guidance on what to fix first.