1H 2026 Examination of Cyber Hostility and Operations

Two Critical Cisco Vulnerabilities Put Network Access and Management Systems at Risk

Cisco disclosed two critical authentication bypass vulnerabilities in September 2026: CVE-2026-76460, affecting Identity Services Engine (ISE), and CVE-2026-76504, affecting Catalyst SD-WAN Manager. Cisco has confirmed active exploitation of both and released patches.

MSPs and security teams should identify affected deployments, urgently apply the appropriate updates, and investigate whether attackers already gained access.

CVE-2026-76460: Authentication Bypass in Cisco ISE

Disclosed on September 16 with a CVSS score of 10.0, this vulnerability affects vulnerable releases of Cisco ISE and ISE Passive Identity Connector (ISE-PIC), regardless of configuration. An unauthenticated remote attacker can exploit insufficient authentication controls on an API endpoint to gain unauthorized access. Cisco warns that successful exploitation may lead to command execution with root privileges.

That access also complicates investigation: attackers may remove or hide evidence. Cisco recommends reviewing logs from every ISE node alongside external network and firewall logs. If malicious activity is suspected, Cisco strongly recommends re-imaging affected nodes and restoring configuration backups as needed.

CVE-2026-76504: Admin Access to Cisco SD-WAN Manager

Disclosed on September 30 with a CVSS score of 9.8, this vulnerability affects vulnerable releases of Cisco Catalyst SD-WAN Manager, regardless of configuration. Improper handling of URI encoding allows an unauthenticated remote attacker to send a crafted HTTP request, bypass authentication, and access the API with admin privileges. Cisco became aware of active exploitation during September.

Cisco recommends reviewing serviceproxy-access.log and vmanage-server.log for suspicious requests associated with j_security_check, particularly from unknown or unauthorized IP addresses. Assess these indicators against normal activity to avoid false positives.

What MSPs and Security Teams Should Do

Cisco has released patches for both vulnerabilities. With active exploitation confirmed, defenders should urgently update affected systems to the appropriate fixed release and review available logs for signs of compromise. Cisco also provides temporary access restrictions to reduce exposure while updates are deployed. These mitigations do not replace patching.

Start by checking your infrastructure and customer environments against Cisco’s affected-version and fixed-release tables. Prioritize exposed management interfaces, restrict access to trusted systems, and preserve logs for investigation.

Patching closes the vulnerability but does not remove access or persistence an attacker may already have established. When authentication bypass affects network access and management infrastructure, patch deployment and compromise assessment should move together.

SUBSCRIBE

Briefings in your Inbox

Original CyOps research, monthly threat intel, and early access to webinars. No fluff. Unsubscribe anytime.

Related Posts

CISA Confirms Active Exploitation of Three On-Premises Microsoft SharePoint CVEs 
Copy Fail (CVE-2026-31431): A Linux Root Exploit Your Disk-Hash Monitoring Can't See
Mini Shai-Hulud: Supply Chain Compromise in the Age of AI-Driven Development 
Emerging Threat Advisory: Windows Shell Spoofing Vulnerability CVE-2026-32202 
Axios Interrupted: Navigating the Latest NPM Supply Chain Attack 

Reading is great. Seeing is better.

See Cynet's unified AI-powered platform in a 30-minute walkthrough tailored to your environment.

Search results for: