The IT week was who gets on the network. Cisco TAC found ISE and the mail gateway; vCenter is ransomware Known.
14–21 September 2026. Seven new KEVs. ISE is a CVSS 10 API regardless of configuration. SEG is a crafted email to root. CISA flipped vCenter CVE-2026-59310 to Known ransomware use. The Linux kernel trio is due today.
Executive summary
FACT: Last week the highest-leverage enterprise problem was the box that administers other boxes — FMC, N-central, ScreenConnect, PaperCut, GitLab. This week the same class moved one hop closer to the human: the appliance that decides who is on the network, the appliance that must accept internet mail, and the appliance that runs the hypervisor estate.
CISA’s Known Exploited Vulnerabilities catalog, version 2026.09.18 released 18 September 19:00 UTC, now holds 1,716 rows. Seven of those were added between 14 and 18 September. All seven carry forensic triage Yes. Catalog ransomware-use on the new rows is Unknown. The material ransomware increment this week is not a new CVE. It is a field flip: CVE-2026-59310 on VMware vCenter, listed since 18 August, now reads knownRansomwareCampaignUse: Known. CISA has not named a family.
Cisco Product Security Incident Response Team found two of the week’s exploited bugs in TAC cases, 48 hours apart. CVE-2026-76461 (Secure Email Gateway, CVSS 9.8, crafted email → root) was disclosed 14 September and KEV’d the same day; federal clock 17 September. CVE-2026-76460 (Identity Services Engine, CVSS 10.0, unauthenticated API, regardless of configuration) was disclosed 16 September and KEV’d the same day; federal clock 19 September. Both clocks have expired. Forensic triage has not.
The Linux kernel trio — CVE-2025-39682 (kTLS), CVE-2026-53266 (ebtables SNAT ARP rewrite), CVE-2025-39964 (AF_ALG race) — was added 18 September. Federal due date is today, 21 September. They are not one bug and they are not a generic “patch Linux” ticket.
ASSESSMENT: If the patch queue this week was last week’s FMC/PaperCut/GitLab leftovers plus the 974 Microsoft CVEs, you sequenced it backwards again. ISE admits every other door. SEG’s exploit path is the mail the product exists to ingest. vCenter that already took reverse SSH in August is a ransomware precondition, not a closed KEV row.
The week in one assessment
Three threads, one pattern: attackers keep buying the box that admits the other boxes — ISE for who gets on, SEG for what mail gets in, vCenter for which VMs exist — while Check Point’s policy plane sits one LivePatch take away from the same class, unexploited, and the kernel floor under all of it went on KEV with a Monday clock.
1. Most important development
Cisco ISE. It is not a switch. It is the NAC. 802.1X, VPN posture, guest, profiling, pxGrid, SGT. Unauthenticated access that bypasses the web management interface is unauthenticated access to the policy that admits every other door.
Cisco first published cisco-sa-ISE-ABP-VNSW7Tn5 on 16 September 16:00 GMT. CVSS 3.1 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). CWE-648. Bug CSCww39530. ISE and ISE-PIC, regardless of device configuration. No workarounds. iACLs that restrict management and control-plane traffic are a mitigation, not a fix. Cisco’s exploitation sentence is one line and it is enough: PSIRT is aware of active exploitation. Source: a TAC support case. That is Cisco’s wording for “at least one customer environment was already in an incident before the advisory existed.” Successful exploit may yield root command execution. Cisco’s own recovery if the Kong hunt hits is re-image, not patch-in-place.
Do not collapse this with CVE-2026-76423. Same day, also CVSS 10, also an unauthenticated REST API failure, different advisory, different CWE (CWE-290), and PSIRT is not aware of malicious use. 76423 is not on KEV. Patch trains overlap. Hunting and KEV clocks do not.
Fixed trains: 3.1 Patch 12 / 3.2 Patch 11 / 3.3 Patch 12 / 3.4 Patch 7 / 3.5 Patch 4. Hunt access.log on every node in a distributed deployment. Cisco’s example string dummyuser is an illustration, not an actor handle. Evidence on the box may already be gone. Cross-check off-box.
There is no confirmed OT or physical-process impact. ISE sitting at an IT/OT boundary, authorizing engineering workstations onto a process VLAN, is still an IT compromise of the access-control plane at an industrial organization. Inventory that. Do not write it up as a PLC event.
2. Active exploitation
CONFIRMED in KEV this window, catalog 2026.09.18:
| Added | CVE | Product | Due | Forensic triage | Ransomware |
|---|---|---|---|---|---|
| 14 Sep | CVE-2026-76461 | Cisco Secure Email Gateway | 17 Sep | Yes | Unknown |
| 16 Sep | CVE-2026-76460 | Cisco ISE / ISE-PIC | 19 Sep | Yes | Unknown |
| 16 Sep | CVE-2026-87886 | Acronis Backup (cPanel/Plesk plugin) | 19 Sep | Yes | Unknown |
| 16 Sep | CVE-2026-58704 | Google Pixel cellular modem | 19 Sep | Yes | Unknown |
| 18 Sep | CVE-2025-39682 | Linux kTLS receive path | 21 Sep | Yes | Unknown |
| 18 Sep | CVE-2026-53266 | Linux ebtables SNAT ARP rewrite | 21 Sep | Yes | Unknown |
| 18 Sep | CVE-2025-39964 | Linux AF_ALG race | 21 Sep | Yes | Unknown |
The seventh row is not the seventh story. Pixel is adjacent-network, device-local, limited-targeted. Acronis is a hosting-panel LPE (PR:L in the vendor picture we published 17 September). Both are real KEV rows. Neither is an enterprise control plane.
SEG is. Advisory cisco-sa-esa-inj-2bLVGmhX, 14 September 16:00 GMT. CVSS 9.8. CWE-89. Bug CSCwu56234. Insufficient validation in AsyncOS email parsing. The payload is a crafted message. SQL, then root on the OS. Physical and virtual SEG, any configuration. No workarounds. SEWM and Secure Web Appliance are not affected. Cloud tenants are already on 16.5.0-780; Cisco contacted tenants where IoCs hit. On-prem floors: 15.5.5-014 / 16.0.4-302 / 16.5.0-780. Hunt COPY.*TO PROGRAM in mail_logs on every cluster member. Root can wipe the same logs. Closing the admin port does not close SMTP.
vCenter CVE-2026-59310 was already KEV. The increment is the ransomware field. Broadcom VMSA-2026-0006.2: unauthenticated directory traversal in the Syslog server, CVSS 9.8, no workarounds. Fixed: 9.1.0.0300 / 9.0.2.0100 / 8.0 U3k or U2f. QUIRSO previously reported reverse-SSH persistence from 3 August across 361 IPs / 47 countries — REPORTED DFIR telemetry, not a CISA attribution. Shadowserver “over 450” internet-visible vCenters is REPORTED via BleepingComputer, not a victim census. CISA has not named the ransomware family. UNKNOWN.
CONFIRMED exploited, not in KEV: CVE-2026-58138 in Orkes / conductor-oss Conductor. Unauthenticated GraalVM HostAccess.ALL RCE via INLINE / LAMBDA / DO_WHILE / SWITCH tasks. CNA range 3.21.21 before 3.30.2. The patch tagged 3 June without a CVE in the notes. Fortinet: 1,290 IPS blocks in 24 hours (9 September) and 6,696 over seven days. Named actor: UNKNOWN.
NOT exploited, on the record: Check Point CVE-2026-91843 (management / log-server login stack overflow, CVSS 9.8, unauthenticated root). Vendor and CISA-ADP: none. Not in catalog 2026.09.18. Last week’s VPN pair CVE-2026-85102 / CVE-2026-85103 is still not in KEV. Check Point’s SK for 85102 was last modified 18 September with a Take 26 note for some older Jumbo trains. NCSC-NL’s “imminent” language has not become a public exploit attempt we can cite.
3. Threat actor / campaign activity
No new Talos FMC cluster this window. Last week’s UAT-12197 / UAT-11823 (Sandworm-tooling overlap, not a named GRU attribution) / UAT-11988 (Qilin) remain the attributed exploitation on the firewall manager. This week’s Cisco TAC cases did not come with a cluster name.
Jade Sleet did. SentinelOne, 18 September: a second victim for macOS backdoors FLATROOF (Gaslight) and ROOFDECK. Apple Silicon DevOps MacBook at an India-based IT services firm with no crypto ties. First on disk 18 March; first execution 29 March via Cursor; last C2 1 June to grenight[.]com. Delivery on this host is UNKNOWN. The campaign lure elsewhere is a fake interview that ships a weaponized .terraform.lock.hcl and a HashiCorp-registry typosquat. That is CONFIRMED as LayerZero tradecraft and as recovered repos. It is not proven for the Indian MacBook. Cluster names (TraderTraitor / UNC4899 / PUKCHONG / Jade Sleet) are SentinelOne’s, with Google/Mandiant credited as partners. RWP is not independently attributing. No named customer follow-on. The intelligence point is the access class: a DevOps Mac with Terraform, Ansible, and cloud credentials is a nation-state target whether or not the firm trades tokens.
Huntress, 17 September: two Settra ransomware incidents (retail in July, manufacturing in September). MeshAgent RMM in both. September case added BYOVD via gdrv.sys and C2 193.5.65[.]114. Initial access in those two cases: UNKNOWN. SOCRadar’s 93-victim Settra figure is REPORTED, not Huntress’s census. Do not merge Settra with vCenter 59310. CISA did not name the family on 59310.
PaperCut’s GreyNoise campaign (440 instances / 395 orgs / 12 domain admin) did not publish a material second-wave increment in this window. The 14 September KEV clock expired. The hunt did not.
4. Vulnerabilities to prioritize
Order is reachability and post-exploit value, not CVSS.
- Cisco ISE CVE-2026-76460 — unauthenticated, configuration-independent, forensic triage Yes, clock expired 19 September. Patch the train. Hunt Kong
access.logon every node. Re-image on a hit. Take 76423 in the same change window even though it missed KEV. - Cisco SEG CVE-2026-76461 — mail-path root, clock expired 17 September, forensic triage Yes.
16.5.0-780is the recommended floor. Cloud “already upgraded” is not a clean bill for a tenant Cisco already called. - vCenter CVE-2026-59310 — ransomware-use Known, forensic triage still Yes, August clock long expired. Patching a box that already has outbound reverse SSH is how the affiliate inherits the cluster.
- Linux kernel trio, due today — inventory features, not
uname. 39682 is kTLS (tlsULP on a TCP socket); kernel.org 9.8 / Red Hat 7.0 Moderate. 53266 needs ebtables SNAT that rewrites ARP sender hardware addresses. 39964 is AF_ALG. Do not merge with Manizada’s 18 September LPE quartet (CVE-2026-80844 / 81000 / 68121 / 74469): public local-root PoCs, not KEV, no in-wild reports. - Check Point CVE-2026-91843 — unauthenticated root on Security Management / Log Server. LivePatch Take 28 (R81.20 / R82 / R82.10) and Take 29 (R82.20).
cplp listrowfwm:fwm armed. Take 24 closed last week’s VPN pair. It does not close this. R82.20 was out of 85102/85103 and in 91843. Restrict Trusted Clients; do not leave Client Type as Any. - Conductor CVE-2026-58138 — 3.30.2 or later. 3.30.1 is still in the CNA range. Default community API is unauthenticated. Not KEV. Do not wait.
- JFrog Artifactory CVE-2026-42016 / 42018 — KEV since 11 September, due 25 September, forensic triage No. Last week’s Wiz chain with CVE-2026-82329. No ransomware-use flag this window.
- Microsoft CVE-2026-81963 (Windows Update Stack EoP) — KEV since 8 September, due 22 September, forensic triage No. Local. Do not let it postpone ISE.
5. Identity / cloud / enterprise
ISE is the identity incident. A NAC that has already answered an unauthenticated API is an alternate path around every Conditional Access policy that assumes 802.1X and VPN posture are trustworthy. Rotate pxGrid certificates, admin identities, and anything the node used to join AD. iACLs after the fact do not unscrew a re-image you skipped.
SEG is an identity incident the second time: the box that decrypted TLS, ran DLP, held quarantines, and brokered LDAP. Cisco’s virtual-appliance recovery language is deploy a new VM on a fixed release, rebuild config, renew credentials and cryptographic materials. Physical: call TAC.
Jade Sleet is the identity of the builder. Cursor parenting the first execution, Terraform lock-file lures, AWS/OVH/OpenStack/VCS on the same Mac. Hunt FLATROOF at ~/Library/com.apple.iTunesCloud/SystemUpdate and ROOFDECK as iSync / stripped loginwindow. That is SentinelOne’s host picture, not a generic “watch macOS” ticket.
Artifactory tokens, GitLab deploy keys, and Conductor’s open API are the non-human-identity remainder of last week’s DevOps KEVs plus this week’s workflow RCE. Rotate them if the box was reachable.
Acronis 87886 and Pixel 58704 are KEV with 19 September clocks. They are not this section’s lead.
6. Ransomware / criminal activity
CONFIRMED by CISA: ransomware-campaign use of vCenter CVE-2026-59310. Family unnamed.
CONFIRMED last week, still in force: Talos UAT-11988 as a Qilin affiliate on FMC via CVE-2026-20316. Catalog ransomware-use on CVE-2026-20079 remains Unknown; on CVE-2026-20316 it is Known. Do not collapse the two FMC CVEs.
REPORTED Huntress Settra (two incidents, MeshAgent, one BYOVD). Not tied to a KEV CVE in this window.
PaperCut KEV ransomware-use remains Unknown. Domain admin on a school-district print server is still a ransomware precondition. No new GreyNoise increment past 440 this week.
Conductor 58138 ransomware-use is not a CISA field. UNKNOWN.
Do not convert an IT compromise at a manufacturer into confirmed OT impact. Huntress’s September Settra victim was a manufacturing firm. That is an IT encryption event at an industrial organization until someone produces process evidence. We do not have it.
7. Defensive priorities
- Internet-facing ISE, SEG, vCenter, Check Point Security Management / Log Server, Conductor, leftover FMC / N-central / ScreenConnect clients / PaperCut / GitLab / Magento / FortiOS / NetScaler. If it admits other boxes and it answers from WAN, it is this week’s ticket.
- Forensic triage is the instruction on ISE, SEG, vCenter, the kernel trio, Pixel, and Acronis. Patching without the hunt is how you leave a Kong username, a
COPY TO PROGRAMline, reverse SSH, or a kTLS implant class in place. - ISE: patch train and every-node
access.log. Re-image on a hit. - SEG: 16.5.0-780 and off-box network logs. The admin portal is not the vector.
- vCenter: fixed build and outbound SSH hunt. The August due date did not retire the row.
- Kernel: ask whether kTLS, ebtables ARP SNAT, or AF_ALG is actually in use. Due today.
- Check Point: Take 28/29 for 91843; confirm Take 24/26 still armed for 85102/85103. Two CVEs, two takes.
- Conductor 3.30.2+; Artifactory before 25 September.
- DevOps Macs: FLATROOF/ROOFDECK hashes, Cursor children,
.terraform.lock.hcltyposquats. - Windows September cumulatives for 81963 by tomorrow. Do not let a local EoP postpone the identity plane.
8. What changed from last week
Last week’s [weekly IT](/posts/2026-09-14-weekly-it-control-plane-fmc-papercut-gitlab/) was FMC (Talos three clusters), PaperCut’s 440, GitLab CVE-2026-85706 and ScreenConnect CVE-2026-84869 due 14 September, and Microsoft’s 974-CVE Patch Tuesday as capacity.
This week those open items closed or moved as follows:
- GitLab 85706 and ScreenConnect 84869 federal clocks expired 14 September. No documented secrets-to-supply-chain case on GitLab this window. ScreenConnect cloud “no action” vs host-client reinstall remains the operational split.
- Check Point 85102/85103 is still not KEV and still not exploited on the vendor record. The new Check Point row is 91843 on the management login, also not exploited, also not KEV, and it does include R82.20.
- PaperCut did not grow a published victim increment past 440.
- Artifactory 42016/42018 still due 25 September, ransomware Unknown, forensic triage No.
- The control-plane list widened: ISE (NAC), SEG (mail parser), vCenter (hypervisor, now ransomware Known), Check Point SMS (policy plane, unexploited).
- Cisco’s week was not an FMC hardening increment. It was two TAC-found zero-days in 48 hours.
- The kernel floor joined KEV with a Monday clock. That is a fleet problem, not an appliance SK.
- Identity kits (BigBear / Knight Office / stolen M365 sessions) were quieter in primary reporting than ISE. The identity incident this week is the NAC, not the browser.
- Jade Sleet showed the same macOS backdoors on an IT-services DevOps Mac. The crypto heist was optional.
- Conductor is exploited and still has no KEV row.
9. What we are watching next
Whether CISA lists Check Point 91843 or 85102/85103 after the first public exploit attempt. Whether Cisco publishes an ISE or SEG actor, IoC set, or victim increment beyond “TAC case.” Whether the vCenter ransomware-use flag gets a named family. Whether Conductor 58138 lands in KEV before Artifactory’s 25 September clock. Whether GreyNoise or PaperCut publish a second-wave increment. Whether GitLab 85706 produces a documented secrets-to-supply-chain case. Whether Jade Sleet’s Indian IT-services victim yields a named customer follow-on — SentinelOne currently assesses it did not. Whether Settra’s MeshAgent pattern ties to a KEV CVE. Chromium’s next in-the-wild after 85046 and 87491. Microsoft 81963 due 22 September.
10. RWP assessment
Confidence: High on the KEV listing set (catalog 2026.09.18, count 1716), on Cisco’s TAC-found exploitation of 76460 and 76461 as described, on the vCenter ransomware-use field as a catalog fact, and on the kernel trio as due today. Moderate on unifying ISE, SEG, and vCenter into a single “identity-plane campaign” — the pattern is target class, not actor. Moderate on SentinelOne’s Jade Sleet cluster for the Indian host (same implants; delivery UNKNOWN). Low on Check Point exploitation (vendor: none; 91843 and 85102/85103 both unlisted). None claimed on OT process impact.
The week does not require a new SIEM use-case. It requires the boxes that admit other boxes — ISE, SEG, vCenter — to be patched, hunted, and pulled off WAN, and the IdP to assume that a NAC node or a mail gateway can already mint a trusted path.
This assessment covers 14–21 September 2026 and was published 21 September 2026.
Sources
- CISA — KEV catalog JSON catalogVersion 2026.09.18
- CISA — Adds one KEV 14 September 2026
- CISA — Adds two KEVs 16 September 2026
- CISA — Adds one KEV 18 September 2026
- CISA — Adds two KEVs 18 September 2026
- CISA — Known Exploited Vulnerabilities Catalog
- CISA — BOD 26-04
- Cisco — ISE Authentication Bypass CVE-2026-76460
- Cisco — ISE CVE-2026-76423
- Cisco — Secure Email Gateway SQL Injection CVE-2026-76461
- Broadcom — VMSA-2026-0006.2
- BleepingComputer — CISA: Critical VMware RCE flaw now exploited by ransomware gangs
- Check Point — sk1000155 CVE-2026-91843
- Check Point — sk1000117 CVE-2026-85102
- CVE — CVE-2025-39682
- Red Hat — CVE-2025-39682
- FortiGuard Labs — Outbreak Alert — Orkes Conductor Evaluator RCE
- CVE — CVE-2026-58138
- SentinelOne — Don’t Call Us, We’ll Call Your APIs
- Huntress — Ready, Settra, Go
- Acronis — SEC-10986 CVE-2026-87886
- RWP — Daily Top Cisco SEG
- RWP — Daily Top vCenter ransomware
- RWP — Daily Top Cisco ISE
- RWP — Daily Top Check Point management
- RWP — Daily Top Linux kernel KEV
- RWP — Daily Top Conductor
- RWP — Daily Top Jade Sleet
- RWP — Weekly IT 14 September 2026