Cisco ISE zero-day under active attack
The lead today is Cisco warning of a maximum severity zero-day in Identity Services Engine that is already being exploited in attacks. ISE sits at the center of network access control, so a flaw that attackers are actively using is a patch-now situation, not a patch-eventually one.
If you run ISE, treat this as an incident-priority action. Apply the fixed release Cisco has published as soon as your change process allows, and review authentication and admin access logs for anything abnormal while you get there.
KEV-listed exploitation still driving the week
No new CISA KEV additions landed on 2026-09-19, but several already-listed criticals remain the highest-risk items on the board, and most are ransomware-linked. That linkage is the dividing line between routine patching and drop-everything work.
The ones to prioritize by exploitation pressure:
- CVE-2026-41940 in WebPros cPanel and WHM, CVSS 9.8, KEV-listed and ransomware-linked, with EPSS at roughly 0.985 (missing authentication for a critical function).
- CVE-2026-35273 in Oracle PeopleSoft Enterprise PeopleTools, CVSS 9.8, KEV-listed and ransomware-linked, EPSS near 0.955 (missing authentication).
- CVE-2026-0257 authentication bypass in Palo Alto Networks PAN-OS, CVSS 9.1, KEV-listed and ransomware-linked, EPSS around 0.952.
- CVE-2026-15409 SSRF in SonicWall SMA1000 appliances, CVSS 10, KEV-listed and ransomware-linked.
- CVE-2026-85706 path traversal in GitLab Community and Enterprise Edition, CVSS 10, KEV-listed.
- CVE-2024-1708 and CVE-2026-84869 in ConnectWise ScreenConnect, both KEV-listed, the older path traversal flaw carrying EPSS around 0.955 and a ransomware link.
What the press added
SecurityWeek reported a critical Orkes Conductor vulnerability, CVE-2026-58138, being exploited in attacks, so add it to your review list if that workflow engine is anywhere in your stack.
Help Net Security detailed a zero-click remote code execution issue affecting four major AI coding agents, two of which remain unpatched. If your developers use these agents, restrict untrusted input paths until fixes ship.
On the Microsoft side, SecurityWeek noted Microsoft patched 18 vulnerabilities across its AI and cloud products. Two operational fixes also landed: Microsoft resolved the bug behind false 'Defender Antivirus is turned off' alerts, and fixed broken copy and paste for Excel 2016 users via KB5002914.
Windows update caveats worth knowing
Two Windows issues affect rollout planning. Microsoft published a workaround for domain login authentication problems, and BleepingComputer reported that KB5124008 broke domain trust for some Windows 11 users. Stage these in a test ring before broad deployment.
Also note that Windows 11 24H2 Home and Pro reach end of support in October, so factor that into your upgrade timeline now rather than during patch crunch.
Do this first
Work down from active exploitation, not just CVSS.
- Patch Cisco ISE immediately and hunt for signs of exploitation.
- Remediate the ransomware-linked KEV entries in this post: cPanel, PeopleSoft, PAN-OS, SonicWall SMA1000, and ScreenConnect.
- Confirm your Windows Server 2022 and Windows 10 1809 cumulative updates (KB5046616, KB5046698, KB5046615, KB5046617) are applied, but validate domain trust behavior before broad rollout.
- Check your own exposure against the KEV list. Senserva's free non-Microsoft exploited-CVE tracker follows CISA KEV additions daily, and the free Microsoft Patch Tracker ranks open patches by KEV, EPSS, and ransomware linkage so you can sort work by real risk.
Sources
- BleepingComputer: Cisco warns of max severity ISE zero-day exploited in attacks (2026-09-17)
- SecurityWeek: Critical Orkes Conductor Vulnerability Exploited in Attacks (2026-09-18)
- SecurityWeek: Microsoft Patches 18 Vulnerabilities in AI, Cloud Products (2026-09-18)
- Help Net Security: Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched (2026-09-18)
- BleepingComputer: Microsoft fixes bug behind ‘Defender Antivirus is turned off’ alerts (2026-09-18)
- BleepingComputer: Microsoft fixes broken copy and paste for Excel 2016 users (2026-09-18)
- BleepingComputer: Microsoft shares workaround for Windows domain login issues (2026-09-17)
- BleepingComputer: Windows 11 KB5124008 update breaks domain trust for some users (2026-09-16)
- BleepingComputer: Windows 11 24H2 Home and Pro reach end of support in October (2026-09-17)
Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-09-19.
Senserva is a Microsoft security company and a member of the Microsoft Intelligent Security Association. Senserva audits your Microsoft 365, Intune, Defender, and Entra ID environment: complete patch state, 650+ security checks, and full reports, with clear guidance on what to fix first.