All posts

Cisco ISE Zero-Day Exploited, Plus KEV Movers to Patch Now

Senserva Watch

Join Senserva Watch and get Three Free Unlimited Audits with our full Claude MCP, a fresh audit credit every quarter, alerts when a CVE or KB you follow changes, critical security updates when they land, the Patch Tuesday wire on release day, and 20% off when you buy.

Join Senserva Watch

One email address. No tenant connection, no agent, no call.

The Senserva daily security read, September 19, 2026

Cisco ISE zero-day under active attack

The lead today is Cisco warning of a maximum severity zero-day in Identity Services Engine that is already being exploited in attacks. ISE sits at the center of network access control, so a flaw that attackers are actively using is a patch-now situation, not a patch-eventually one.

If you run ISE, treat this as an incident-priority action. Apply the fixed release Cisco has published as soon as your change process allows, and review authentication and admin access logs for anything abnormal while you get there.

KEV-listed exploitation still driving the week

No new CISA KEV additions landed on 2026-09-19, but several already-listed criticals remain the highest-risk items on the board, and most are ransomware-linked. That linkage is the dividing line between routine patching and drop-everything work.

The ones to prioritize by exploitation pressure:

  • CVE-2026-41940 in WebPros cPanel and WHM, CVSS 9.8, KEV-listed and ransomware-linked, with EPSS at roughly 0.985 (missing authentication for a critical function).
  • CVE-2026-35273 in Oracle PeopleSoft Enterprise PeopleTools, CVSS 9.8, KEV-listed and ransomware-linked, EPSS near 0.955 (missing authentication).
  • CVE-2026-0257 authentication bypass in Palo Alto Networks PAN-OS, CVSS 9.1, KEV-listed and ransomware-linked, EPSS around 0.952.
  • CVE-2026-15409 SSRF in SonicWall SMA1000 appliances, CVSS 10, KEV-listed and ransomware-linked.
  • CVE-2026-85706 path traversal in GitLab Community and Enterprise Edition, CVSS 10, KEV-listed.
  • CVE-2024-1708 and CVE-2026-84869 in ConnectWise ScreenConnect, both KEV-listed, the older path traversal flaw carrying EPSS around 0.955 and a ransomware link.

What the press added

SecurityWeek reported a critical Orkes Conductor vulnerability, CVE-2026-58138, being exploited in attacks, so add it to your review list if that workflow engine is anywhere in your stack.

Help Net Security detailed a zero-click remote code execution issue affecting four major AI coding agents, two of which remain unpatched. If your developers use these agents, restrict untrusted input paths until fixes ship.

On the Microsoft side, SecurityWeek noted Microsoft patched 18 vulnerabilities across its AI and cloud products. Two operational fixes also landed: Microsoft resolved the bug behind false 'Defender Antivirus is turned off' alerts, and fixed broken copy and paste for Excel 2016 users via KB5002914.

Windows update caveats worth knowing

Two Windows issues affect rollout planning. Microsoft published a workaround for domain login authentication problems, and BleepingComputer reported that KB5124008 broke domain trust for some Windows 11 users. Stage these in a test ring before broad deployment.

Also note that Windows 11 24H2 Home and Pro reach end of support in October, so factor that into your upgrade timeline now rather than during patch crunch.

Do this first

Work down from active exploitation, not just CVSS.

  • Patch Cisco ISE immediately and hunt for signs of exploitation.
  • Remediate the ransomware-linked KEV entries in this post: cPanel, PeopleSoft, PAN-OS, SonicWall SMA1000, and ScreenConnect.
  • Confirm your Windows Server 2022 and Windows 10 1809 cumulative updates (KB5046616, KB5046698, KB5046615, KB5046617) are applied, but validate domain trust behavior before broad rollout.
  • Check your own exposure against the KEV list. Senserva's free non-Microsoft exploited-CVE tracker follows CISA KEV additions daily, and the free Microsoft Patch Tracker ranks open patches by KEV, EPSS, and ransomware linkage so you can sort work by real risk.

Sources

Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-09-19.

Senserva is a Microsoft security company and a member of the Microsoft Intelligent Security Association. Senserva audits your Microsoft 365, Intune, Defender, and Entra ID environment: complete patch state, 650+ security checks, and full reports, with clear guidance on what to fix first.

All posts

Patching across Intune, Windows Autopatch, Defender, Azure, and your endpoint managers: see Senserva patching in action.