INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Cisco Warns of New Zero-Day ISE Auth Bypass Exploited
| 2026-10-01 12:00 CRITICAL MEDIUM EXPLOITED VULNERABILITY
Executive Summary
AI-generated
A critical vulnerability has been discovered in Monta [IOC HIDDEN • LOGIN REQUIRED], a widely used software solution, leaving it exposed to impersonation attacks. The identified vulnerabilities include CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, and CVE-2026-93474, with CVSS scores indicating a high level of severity. This lack of authentication mechanisms enables attackers to gain unauthorized access to the system, potentially leading to privilege escalation and compromising the entire security framework. Monta [IOC HIDDEN • LOGIN REQUIRED] versions 9.4 are affected by these vulnerabilities, which have been deployed in various sectors including energy and transportation systems worldwide.
Technical Mitigations AI-generated
• Implement rate limiting on WebSocket endpoints to prevent denial-of-service attacks and brute-force attempts.
• Use unique, unpredictable session identifiers for each charging station connection to prevent unauthorized authentication and denial-of-service conditions.
• Enforce proper authentication mechanisms, such as multi-factor authentication or secure password storage, to prevent impersonation of charging stations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
mo•••••.app
ac•••••.log
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-97363CVE-2026-97363
CVE-2026-20360CVE-2026-20360
CVE-2026-20334CVE-2026-20334
CVE-2026-95102CVE-2026-95102
CVE-2026-20282CVE-2026-20282
CVE-2026-20211CVE-2026-20211
CVE-2026-20306CVE-2026-20306
CVE-2026-20284CVE-2026-20284
CVE-2026-20353CVE-2026-20353
CVE-2026-20307CVE-2026-20307
CVE-2026-20340CVE-2026-20340
CVE-2026-20176CVE-2026-20176
CVE-2026-76420CVE-2026-76420
CVE-2026-76441CVE-2026-76441
CVE-2026-20283CVE-2026-20283
CVE-2026-97212CVE-2026-97212
CVE-2026-20326CVE-2026-20326
CVE-2026-76425CVE-2026-76425
CVE-2026-76443CVE-2026-76443
CVE-2026-76428CVE-2026-76428
CVE-2026-76424CVE-2026-76424
CVE-2026-76423CVE-2026-76423
CVE-2026-76409CVE-2026-76409
CVE-2026-20305CVE-2026-20305
CVE-2026-20361CVE-2026-20361
CVE-2026-20342CVE-2026-20342
CVE-2026-20325CVE-2026-20325
CVE-2026-20329CVE-2026-20329
CVE-2026-20336CVE-2026-20336
CVE-2026-76442CVE-2026-76442
CVE-2026-20242CVE-2026-20242
CVE-2026-20335CVE-2026-20335
CVE-2026-20192CVE-2026-20192
CVE-2026-76461CVE-2026-76461
CVE-2026-93474CVE-2026-93474
CVE-2026-20130CVE-2026-20130
CVE-2026-20344CVE-2026-20344
CVE-2026-76440CVE-2026-76440
CVE-2026-20330CVE-2026-20330
CVE-2026-20237CVE-2026-20237
CVE-2026-20234CVE-2026-20234
CVE-2026-20331CVE-2026-20331
CVE-2026-20332CVE-2026-20332
CVE-2026-20322CVE-2026-20322
CVE-2026-20333CVE-2026-20333
CVE-2026-20194CVE-2026-20194
CVE-2026-20343CVE-2026-20343
CVE-2026-76426CVE-2026-76426
CVE-2026-20324CVE-2026-20324
CVE-2026-20287CVE-2026-20287
CVE-2026-76413CVE-2026-76413
CVE-2026-76460CVE-2026-76460
CVE-2026-76427CVE-2026-76427
CVE-2026-20341CVE-2026-20341
CVE-2026-76412CVE-2026-76412
Target & Sectors
BENELUX
BENELUX
manufacturingmanufacturing
transportationtransportation
Incident Timeline
September 16, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76460 to its Known Exploited Vulnerabilities catalog on September 16, 2026.
Click on any entity below to view its context and source!
tactic
T1588.006 - Vulnerabilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 16, 2026,
added
CVE-2026-76460 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 19, 2026.
vulnerability
CVE-2026-76460
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 16, 2026,
added
CVE-2026-76460 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 19, 2026.
attribution
Known Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 16, 2026,
added
CVE-2026-76460 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 19, 2026.
attribution
KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 16, 2026,
added
CVE-2026-76460 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 19, 2026.
attribution
Federal Civilian Executive Branch
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 16, 2026,
added
CVE-2026-76460 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 19, 2026.
attribution
FCEB
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 16, 2026,
added
CVE-2026-76460 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 19, 2026.
Sep 17, 2026
Threat actors exploited a vulnerability in the Monta monta.app website to gain unauthorized access.
September 19, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76460 to its Known Exploited Vulnerabilities catalog, requiring Federal Civilian Executive Branch agencies to apply the patches by September 19, 2026.
Click on any entity below to view its context and source!
tactic
T1588.006 - Vulnerabilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 16, 2026,
added
CVE-2026-76460 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 19, 2026.
vulnerability
CVE-2026-76460
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 16, 2026,
added
CVE-2026-76460 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 19, 2026.
attribution
Known Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 16, 2026,
added
CVE-2026-76460 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 19, 2026.
attribution
KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 16, 2026,
added
CVE-2026-76460 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 19, 2026.
attribution
Federal Civilian Executive Branch
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 16, 2026,
added
CVE-2026-76460 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 19, 2026.
attribution
FCEB
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 16, 2026,
added
CVE-2026-76460 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 19, 2026.
2026/10/01
Threat actors used multiple vulnerabilities in Monta monta.app, including a WebSocket Application Programming Interface with insufficient authentication mechanisms and missing authentication for critical functions, to impersonate charging stations and execute arbitrary commands.
Click on any entity below to view its context and source!
organisation
WebSocket
Worldwide
Company Headquarters Location:
Netherlands
Vulnerabilities
Expand All +
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations.
infrastructure
9.4
The following versions of Monta monta.app are affected:
monta.app vers:all/* (CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.4
Monta
Monta monta.app
Missing Authentication for Critical Function, Improper Restriction of Excessive Authentication Attempts, Insufficient Session Expiration, Insufficiently Protected Credentials
Background
Critical Infrastructure Sectors:
Energy, Transportation Systems
Countries/Areas Deployed:
organisation
CVSS
The following versions of Monta monta.app are affected:
monta.app vers:all/* (CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.4
Monta
Monta monta.app
Missing Authentication for Critical Function, Improper Restriction of Excessive Authentication Attempts, Insufficient Session Expiration, Insufficiently Protected Credentials
Background
Critical Infrastructure Sectors:
Energy, Transportation Systems
Countries/Areas Deployed:
Software for Cisco Secure Email Gateway (
CVE-2026-76461
, CVSS score: 9.8) has come under active exploitation in the wild.
organisation
Vendor
Equipment
The following versions of Monta monta.app are affected:
monta.app vers:all/* (CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.4
Monta
Monta monta.app
Missing Authentication for Critical Function, Improper Restriction of Excessive Authentication Attempts, Insufficient Session Expiration, Insufficiently Protected Credentials
Background
Critical Infrastructure Sectors:
Energy, Transportation Systems
Countries/Areas Deployed:
organisation
Monta
Monta
The following versions of Monta monta.app are affected:
monta.app vers:all/* (CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.4
Monta
Monta monta.app
Missing Authentication for Critical Function, Improper Restriction of Excessive Authentication Attempts, Insufficient Session Expiration, Insufficiently Protected Credentials
Background
Critical Infrastructure Sectors:
Energy, Transportation Systems
Countries/Areas Deployed:
organisation
Missing Authentication for Critical Function
The following versions of Monta monta.app are affected:
monta.app vers:all/* (CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.4
Monta
Monta monta.app
Missing Authentication for Critical Function, Improper Restriction of Excessive Authentication Attempts, Insufficient Session Expiration, Insufficiently Protected Credentials
Background
Critical Infrastructure Sectors:
Energy, Transportation Systems
Countries/Areas Deployed:
organisation
Transportation Systems
Countries/Areas Deployed
The following versions of Monta monta.app are affected:
monta.app vers:all/* (CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.4
Monta
Monta monta.app
Missing Authentication for Critical Function, Improper Restriction of Excessive Authentication Attempts, Insufficient Session Expiration, Insufficiently Protected Credentials
Background
Critical Infrastructure Sectors:
Energy, Transportation Systems
Countries/Areas Deployed:
organisation
Monta
Monta monta.app.
organisation
Affected Products
Monta
View CVE Details
Affected Products
Monta monta.app
Vendor:
Monta
Product Version:
Monta monta.app: vers:all/*
Product Status:
known_affected
Relevant CWE:
CWE-306 Missing Authentication for Critical Function
Metrics
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests.
organisation
Monta
Product Version
View CVE Details
Affected Products
Monta monta.app
Vendor:
Monta
Product Version:
Monta monta.app: vers:all/*
Product Status:
known_affected
Relevant CWE:
CWE-306 Missing Authentication for Critical Function
Metrics
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests.
organisation
The WebSocket Application Programming Interface
View CVE Details
Affected Products
Monta monta.app
Vendor:
Monta
Product Version:
Monta monta.app: vers:all/*
Product Status:
known_affected
Relevant CWE:
CWE-306 Missing Authentication for Critical Function
Metrics
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests.
infrastructure
9.8
Software for Cisco Secure Email Gateway (
CVE-2026-76461
, CVSS score: 9.8) has come under active exploitation in the wild.
CVE-2026-20242 (CVSS score: 9.8)
- A vulnerability in the External Database Access feature of FMC Software that could allow an unauthenticated, remote attacker to execute arbitrary commands as root on an affected device.
organisation
Cisco Secure Email Gateway
Software for Cisco Secure Email Gateway (
CVE-2026-76461
, CVSS score: 9.8) has come under active exploitation in the wild.
organisation
this Privacy & Use
Legal Notice and Terms of Use
This product is provided subject to this Notification (
) and this Privacy & Use policy (
).
organisation
Initial Release Date
Revision History
Initial Release Date:
2026-10-01
Date
Revision
Summary
2026-10-01
1
Initial Publication
Legal Notice and Terms of Use
infrastructure
9.9
CVE-2026-20329 (CVSS score: 9.9), CVE-2026-20330 (CVSS score: 9.9), CVE-2026-20331 (CVSS score: 9.6), CVE-2026-20332 (CVSS score: 9.0), CVE-2026-20333, CVE-2026-20334, CVE-2026-20335, CVE-2026-20336
- Multiple vulnerabilities in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software and Cisco Secure Firewall Management Center (FMC) Software that are grouped by CWE category, covering areas like improper handling of exceptional conditions, improper access control, improper adherence to coding standards, and improper control of a resource through its lifetime.
CVE-2026-20324 (CVSS score: 9.9)
- A vulnerability in the sftunnel inter-device communication protocol of FMC Software that could allow an authenticated, remote attacker to execute arbitrary commands as root.
infrastructure
9.6
CVE-2026-20329 (CVSS score: 9.9), CVE-2026-20330 (CVSS score: 9.9), CVE-2026-20331 (CVSS score: 9.6), CVE-2026-20332 (CVSS score: 9.0), CVE-2026-20333, CVE-2026-20334, CVE-2026-20335, CVE-2026-20336
- Multiple vulnerabilities in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software and Cisco Secure Firewall Management Center (FMC) Software that are grouped by CWE category, covering areas like improper handling of exceptional conditions, improper access control, improper adherence to coding standards, and improper control of a resource through its lifetime.
infrastructure
9.0
CVE-2026-20329 (CVSS score: 9.9), CVE-2026-20330 (CVSS score: 9.9), CVE-2026-20331 (CVSS score: 9.6), CVE-2026-20332 (CVSS score: 9.0), CVE-2026-20333, CVE-2026-20334, CVE-2026-20335, CVE-2026-20336
- Multiple vulnerabilities in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software and Cisco Secure Firewall Management Center (FMC) Software that are grouped by CWE category, covering areas like improper handling of exceptional conditions, improper access control, improper adherence to coding standards, and improper control of a resource through its lifetime.
CVE-2026-76412, CVE-2026-76413, CVE-2026-76420 (CVSS score: 9.0)
- Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software that could allow a remote attacker to gain root access and perform session forgery or session impersonation.
organisation
Cisco Secure Firewall Adaptive Security Appliance
CVE-2026-20329 (CVSS score: 9.9), CVE-2026-20330 (CVSS score: 9.9), CVE-2026-20331 (CVSS score: 9.6), CVE-2026-20332 (CVSS score: 9.0), CVE-2026-20333, CVE-2026-20334, CVE-2026-20335, CVE-2026-20336
- Multiple vulnerabilities in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software and Cisco Secure Firewall Management Center (FMC) Software that are grouped by CWE category, covering areas like improper handling of exceptional conditions, improper access control, improper adherence to coding standards, and improper control of a resource through its lifetime.
organisation
Cisco Secure Firewall Threat Defense
CVE-2026-20329 (CVSS score: 9.9), CVE-2026-20330 (CVSS score: 9.9), CVE-2026-20331 (CVSS score: 9.6), CVE-2026-20332 (CVSS score: 9.0), CVE-2026-20333, CVE-2026-20334, CVE-2026-20335, CVE-2026-20336
- Multiple vulnerabilities in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software and Cisco Secure Firewall Management Center (FMC) Software that are grouped by CWE category, covering areas like improper handling of exceptional conditions, improper access control, improper adherence to coding standards, and improper control of a resource through its lifetime.
organisation
Cisco Secure Firewall Management Center
CVE-2026-20329 (CVSS score: 9.9), CVE-2026-20330 (CVSS score: 9.9), CVE-2026-20331 (CVSS score: 9.6), CVE-2026-20332 (CVSS score: 9.0), CVE-2026-20333, CVE-2026-20334, CVE-2026-20335, CVE-2026-20336
- Multiple vulnerabilities in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software and Cisco Secure Firewall Management Center (FMC) Software that are grouped by CWE category, covering areas like improper handling of exceptional conditions, improper access control, improper adherence to coding standards, and improper control of a resource through its lifetime.
organisation
CWE
CVE-2026-20329 (CVSS score: 9.9), CVE-2026-20330 (CVSS score: 9.9), CVE-2026-20331 (CVSS score: 9.6), CVE-2026-20332 (CVSS score: 9.0), CVE-2026-20333, CVE-2026-20334, CVE-2026-20335, CVE-2026-20336
- Multiple vulnerabilities in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software and Cisco Secure Firewall Management Center (FMC) Software that are grouped by CWE category, covering areas like improper handling of exceptional conditions, improper access control, improper adherence to coding standards, and improper control of a resource through its lifetime.
infrastructure
146 TIP-12
Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.
organisation
Virtual Private Networks
When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available.
organisation
CVE-2026-20324
CVE-2026-20324 (CVSS score: 9.9)
- A vulnerability in the sftunnel inter-device communication protocol of FMC Software that could allow an authenticated, remote attacker to execute arbitrary commands as root.
organisation
CVE-2026-76413
CVE-2026-76412, CVE-2026-76413, CVE-2026-76420 (CVSS score: 9.0)
- Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software that could allow a remote attacker to gain root access and perform session forgery or session impersonation.
infrastructure
9.0 Multiple vulnerabilities
CVE-2026-76412, CVE-2026-76413, CVE-2026-76420 (CVSS score: 9.0)
- Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software that could allow a remote attacker to gain root access and perform session forgery or session impersonation.
infrastructure
9.1
CVE-2026-20340, CVE-2026-20341 (CVSS score: 9.1), CVE-2026-20342, CVE-2026-20343, CVE-2026-20344
- Multiple vulnerabilities in FMC Software that could allow a remote attacker to gain root access, download sensitive files, perform a SQL injection attack, or cause a denial-of-service (DoS) condition.
organisation
DoS
CVE-2026-20340, CVE-2026-20341 (CVSS score: 9.1), CVE-2026-20342, CVE-2026-20343, CVE-2026-20344
- Multiple vulnerabilities in FMC Software that could allow a remote attacker to gain root access, download sensitive files, perform a SQL injection attack, or cause a denial-of-service (DoS) condition.
organisation
the External Database Access
CVE-2026-20242 (CVSS score: 9.8)
- A vulnerability in the External Database Access feature of FMC Software that could allow an unauthenticated, remote attacker to execute arbitrary commands as root on an affected device.
infrastructure
9.1 Multiple vulnerabilities
A brief description of the flaws is below -
CVE-2026-20176 (CVSS score: 9.9), CVE-2026-20211 (CVSS score: 9.1), CVE-2026-20307 (CVSS score: 9.1)
- Multiple vulnerabilities in ISE that could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device.
CVE-2026-20305 (CVSS score: 9.1), CVE-2026-20306 (CVSS score: 9.1)
- Multiple vulnerabilities in ISE and ISE-PIC that could allow an authenticated, remote attacker to perform command injection attacks on an affected device and execute arbitrary commands as the root user.
organisation
CVE-2026-20322
CVE-2026-20322 (CVSS score: 9.9), CVE-2026-20325 (CVSS score: 9.9), CVE-2026-20326 (CVSS score: 9.8), CVE-2026-20360, CVE-2026-20361, CVE-2026-76409
- Multiple vulnerabilities in Cisco Nexus Dashboard that could lead to command injection, authentication or authorization bypass, and information disclosure.
infrastructure
76409 Multiple vulnerabilities
CVE-2026-20322 (CVSS score: 9.9), CVE-2026-20325 (CVSS score: 9.9), CVE-2026-20326 (CVSS score: 9.8), CVE-2026-20360, CVE-2026-20361, CVE-2026-76409
- Multiple vulnerabilities in Cisco Nexus Dashboard that could lead to command injection, authentication or authorization bypass, and information disclosure.
organisation
CVE-2026-20130
CVE-2026-20130 (CVSS score: 10.0), CVE-2026-20192 (CVSS score: 10.0), CVE-2026-20194 (CVSS score: 9.1), CVE-2026-20234 (CVSS score: 9.9), CVE-2026-20237 (CVSS score: 9.9), CVE-2026-20287
- Multiple vulnerabilities in ISE and ISE-PIC that could lead to command injection, authentication or authorization bypass, and information disclosure.
infrastructure
20287 CVE-2026 Multiple
CVE-2026-20130 (CVSS score: 10.0), CVE-2026-20192 (CVSS score: 10.0), CVE-2026-20194 (CVSS score: 9.1), CVE-2026-20234 (CVSS score: 9.9), CVE-2026-20237 (CVSS score: 9.9), CVE-2026-20287
- Multiple vulnerabilities in ISE and ISE-PIC that could lead to command injection, authentication or authorization bypass, and information disclosure.
infrastructure
3.1
It has been addressed in the following versions -
3.1 - Fixed in 3.1 Patch 12
3.2 - Fixed in 3.2 Patch 11
3.3 - Fixed in 3.3 Patch 12
3.4 - Fixed in 3.4 Patch 7
3.51 - Fixed in 3.5 Patch 4
Cisco said it's "aware of active exploitation of this vulnerability," urging customers to upgrade to a fixed software release to counter the threat.
infrastructure
3.2
It has been addressed in the following versions -
3.1 - Fixed in 3.1 Patch 12
3.2 - Fixed in 3.2 Patch 11
3.3 - Fixed in 3.3 Patch 12
3.4 - Fixed in 3.4 Patch 7
3.51 - Fixed in 3.5 Patch 4
Cisco said it's "aware of active exploitation of this vulnerability," urging customers to upgrade to a fixed software release to counter the threat.
infrastructure
3.3
It has been addressed in the following versions -
3.1 - Fixed in 3.1 Patch 12
3.2 - Fixed in 3.2 Patch 11
3.3 - Fixed in 3.3 Patch 12
3.4 - Fixed in 3.4 Patch 7
3.51 - Fixed in 3.5 Patch 4
Cisco said it's "aware of active exploitation of this vulnerability," urging customers to upgrade to a fixed software release to counter the threat.
infrastructure
3.4
It has been addressed in the following versions -
3.1 - Fixed in 3.1 Patch 12
3.2 - Fixed in 3.2 Patch 11
3.3 - Fixed in 3.3 Patch 12
3.4 - Fixed in 3.4 Patch 7
3.51 - Fixed in 3.5 Patch 4
Cisco said it's "aware of active exploitation of this vulnerability," urging customers to upgrade to a fixed software release to counter the threat.
infrastructure
3.51
It has been addressed in the following versions -
3.1 - Fixed in 3.1 Patch 12
3.2 - Fixed in 3.2 Patch 11
3.3 - Fixed in 3.3 Patch 12
3.4 - Fixed in 3.4 Patch 7
3.51 - Fixed in 3.5 Patch 4
Cisco said it's "aware of active exploitation of this vulnerability," urging customers to upgrade to a fixed software release to counter the threat.
infrastructure
3.5
It has been addressed in the following versions -
3.1 - Fixed in 3.1 Patch 12
3.2 - Fixed in 3.2 Patch 11
3.3 - Fixed in 3.3 Patch 12
3.4 - Fixed in 3.4 Patch 7
3.51 - Fixed in 3.5 Patch 4
Cisco said it's "aware of active exploitation of this vulnerability," urging customers to upgrade to a fixed software release to counter the threat.
organisation
Cisco
It has been addressed in the following versions -
3.1 - Fixed in 3.1 Patch 12
3.2 - Fixed in 3.2 Patch 11
3.3 - Fixed in 3.3 Patch 12
3.4 - Fixed in 3.4 Patch 7
3.51 - Fixed in 3.5 Patch 4
Cisco said it's "aware of active exploitation of this vulnerability," urging customers to upgrade to a fixed software release to counter the threat.
organisation
CVE-2026-20306
CVE-2026-20305 (CVSS score: 9.1), CVE-2026-20306 (CVSS score: 9.1)
- Multiple vulnerabilities in ISE and ISE-PIC that could allow an authenticated, remote attacker to perform command injection attacks on an affected device and execute arbitrary commands as the root user.
organisation
ISE-PIC
CVE-2026-20305 (CVSS score: 9.1), CVE-2026-20306 (CVSS score: 9.1)
- Multiple vulnerabilities in ISE and ISE-PIC that could allow an authenticated, remote attacker to perform command injection attacks on an affected device and execute arbitrary commands as the root user.
organisation
CVE-2026-76423
CVE-2026-76423 (CVSS score: 10.0), CVE-2026-76424, CVE-2026-76425, CVE-2026-76426, CVE-2026-76427, CVE-2026-76428
- Multiple vulnerabilities in ISE and Cisco ISE Passive Identity Connector (ISE-PIC) that could allow a remote attacker to bypass authentication to the REST API, achieve remote code execution, perform SQL injection, and conduct XML External Entity injection attacks on an affected device.
organisation
CVE-2026-76425
CVE-2026-76423 (CVSS score: 10.0), CVE-2026-76424, CVE-2026-76425, CVE-2026-76426, CVE-2026-76427, CVE-2026-76428
- Multiple vulnerabilities in ISE and Cisco ISE Passive Identity Connector (ISE-PIC) that could allow a remote attacker to bypass authentication to the REST API, achieve remote code execution, perform SQL injection, and conduct XML External Entity injection attacks on an affected device.
organisation
CVE-2026
CVE-2026-76423 (CVSS score: 10.0), CVE-2026-76424, CVE-2026-76425, CVE-2026-76426, CVE-2026-76427, CVE-2026-76428
- Multiple vulnerabilities in ISE and Cisco ISE Passive Identity Connector (ISE-PIC) that could allow a remote attacker to bypass authentication to the REST API, achieve remote code execution, perform SQL injection, and conduct XML External Entity injection attacks on an affected device.
organisation
ISE
CVE-2026-76423 (CVSS score: 10.0), CVE-2026-76424, CVE-2026-76425, CVE-2026-76426, CVE-2026-76427, CVE-2026-76428
- Multiple vulnerabilities in ISE and Cisco ISE Passive Identity Connector (ISE-PIC) that could allow a remote attacker to bypass authentication to the REST API, achieve remote code execution, perform SQL injection, and conduct XML External Entity injection attacks on an affected device.
organisation
SQL
CVE-2026-76423 (CVSS score: 10.0), CVE-2026-76424, CVE-2026-76425, CVE-2026-76426, CVE-2026-76427, CVE-2026-76428
- Multiple vulnerabilities in ISE and Cisco ISE Passive Identity Connector (ISE-PIC) that could allow a remote attacker to bypass authentication to the REST API, achieve remote code execution, perform SQL injection, and conduct XML External Entity injection attacks on an affected device.
organisation
XML External
CVE-2026-76423 (CVSS score: 10.0), CVE-2026-76424, CVE-2026-76425, CVE-2026-76426, CVE-2026-76427, CVE-2026-76428
- Multiple vulnerabilities in ISE and Cisco ISE Passive Identity Connector (ISE-PIC) that could allow a remote attacker to bypass authentication to the REST API, achieve remote code execution, perform SQL injection, and conduct XML External Entity injection attacks on an affected device.
organisation
CVE-2026-20353
CVE-2026-20353 (CVSS score: 9.8), CVE-2026-76440 (CVSS score: 9.8), CVE-2026-76441 (CVSS score: 9.8), CVE-2026-76442 (CVSS score: 9.8), CVE-2026-76443
- Multiple vulnerabilities in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager that could lead to path traversal, authentication or authorization bypass, uncontrolled resource consumption, and command injection.
organisation
CVE-2026-76440
CVE-2026-20353 (CVSS score: 9.8), CVE-2026-76440 (CVSS score: 9.8), CVE-2026-76441 (CVSS score: 9.8), CVE-2026-76442 (CVSS score: 9.8), CVE-2026-76443
- Multiple vulnerabilities in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager that could lead to path traversal, authentication or authorization bypass, uncontrolled resource consumption, and command injection.
organisation
CVE-2026-76441
CVE-2026-20353 (CVSS score: 9.8), CVE-2026-76440 (CVSS score: 9.8), CVE-2026-76441 (CVSS score: 9.8), CVE-2026-76442 (CVSS score: 9.8), CVE-2026-76443
- Multiple vulnerabilities in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager that could lead to path traversal, authentication or authorization bypass, uncontrolled resource consumption, and command injection.
organisation
Vulnerability / Web Security
Ravie Lakshmanan
Sep 17, 2026
Vulnerability / Web Security
Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation.
organisation
Identity Services Engine
Ravie Lakshmanan
Sep 17, 2026
Vulnerability / Web Security
Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation.
organisation
API
"This vulnerability is due to insufficient authentication control on an API endpoint," Cisco said.
organisation
Cisco ISE
"
The issue affects Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC), regardless of device configuration.
organisation
Cisco ISE Passive Identity Connector
"
The issue affects Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC), regardless of device configuration.
organisation
Secure Firewall
Of the 77 new CVEs issued Wednesday, 41 affect ISE and 28 affect the Secure Firewall portfolio.
Tactical Metrics
Metrics
infrastructure
9.4
Software Version
Click for context!
The following versions of Monta monta.app are affected:
monta.app vers:all/* (CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.4
Monta
Monta monta.app
Missing Authentication for Critical Function, Improper Restriction of Excessive Authentication Attempts, Insufficient Session Expiration, Insufficiently Protected Credentials
Background
Critical Infrastructure Sectors:
Energy, Transportation Systems
Countries/Areas Deployed:
Metrics
infrastructure
146
Tip-12
Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.
Metrics
infrastructure
9.9
Software Version
CVE-2026-20329 (CVSS score: 9.9), CVE-2026-20330 (CVSS score: 9.9), CVE-2026-20331 (CVSS score: 9.6), CVE-2026-20332 (CVSS score: 9.0), CVE-2026-20333, CVE-2026-20334, CVE-2026-20335, CVE-2026-20336
- Multiple vulnerabilities in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software and Cisco Secure Firewall Management Center (FMC) Software that are grouped by CWE category, covering areas like improper handling of exceptional conditions, improper access control, improper adherence to coding standards, and improper control of a resource through its lifetime.
CVE-2026-20324 (CVSS score: 9.9)
- A vulnerability in the sftunnel inter-device communication protocol of FMC Software that could allow an authenticated, remote attacker to execute arbitrary commands as root.
Metrics
infrastructure
9.6
Software Version
CVE-2026-20329 (CVSS score: 9.9), CVE-2026-20330 (CVSS score: 9.9), CVE-2026-20331 (CVSS score: 9.6), CVE-2026-20332 (CVSS score: 9.0), CVE-2026-20333, CVE-2026-20334, CVE-2026-20335, CVE-2026-20336
- Multiple vulnerabilities in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software and Cisco Secure Firewall Management Center (FMC) Software that are grouped by CWE category, covering areas like improper handling of exceptional conditions, improper access control, improper adherence to coding standards, and improper control of a resource through its lifetime.
Metrics
infrastructure
9.0
Software Version
CVE-2026-20329 (CVSS score: 9.9), CVE-2026-20330 (CVSS score: 9.9), CVE-2026-20331 (CVSS score: 9.6), CVE-2026-20332 (CVSS score: 9.0), CVE-2026-20333, CVE-2026-20334, CVE-2026-20335, CVE-2026-20336
- Multiple vulnerabilities in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software and Cisco Secure Firewall Management Center (FMC) Software that are grouped by CWE category, covering areas like improper handling of exceptional conditions, improper access control, improper adherence to coding standards, and improper control of a resource through its lifetime.
CVE-2026-76412, CVE-2026-76413, CVE-2026-76420 (CVSS score: 9.0)
- Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software that could allow a remote attacker to gain root access and perform session forgery or session impersonation.
Metrics
infrastructure
9
Multiple Vulnerabilities
CVE-2026-76412, CVE-2026-76413, CVE-2026-76420 (CVSS score: 9.0)
- Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software that could allow a remote attacker to gain root access and perform session forgery or session impersonation.
Metrics
infrastructure
3.1
Software Version
It has been addressed in the following versions -
3.1 - Fixed in 3.1 Patch 12
3.2 - Fixed in 3.2 Patch 11
3.3 - Fixed in 3.3 Patch 12
3.4 - Fixed in 3.4 Patch 7
3.51 - Fixed in 3.5 Patch 4
Cisco said it's "aware of active exploitation of this vulnerability," urging customers to upgrade to a fixed software release to counter the threat.
Metrics
infrastructure
3.2
Software Version
It has been addressed in the following versions -
3.1 - Fixed in 3.1 Patch 12
3.2 - Fixed in 3.2 Patch 11
3.3 - Fixed in 3.3 Patch 12
3.4 - Fixed in 3.4 Patch 7
3.51 - Fixed in 3.5 Patch 4
Cisco said it's "aware of active exploitation of this vulnerability," urging customers to upgrade to a fixed software release to counter the threat.
Metrics
infrastructure
3.3
Software Version
It has been addressed in the following versions -
3.1 - Fixed in 3.1 Patch 12
3.2 - Fixed in 3.2 Patch 11
3.3 - Fixed in 3.3 Patch 12
3.4 - Fixed in 3.4 Patch 7
3.51 - Fixed in 3.5 Patch 4
Cisco said it's "aware of active exploitation of this vulnerability," urging customers to upgrade to a fixed software release to counter the threat.
Metrics
infrastructure
3.4
Software Version
It has been addressed in the following versions -
3.1 - Fixed in 3.1 Patch 12
3.2 - Fixed in 3.2 Patch 11
3.3 - Fixed in 3.3 Patch 12
3.4 - Fixed in 3.4 Patch 7
3.51 - Fixed in 3.5 Patch 4
Cisco said it's "aware of active exploitation of this vulnerability," urging customers to upgrade to a fixed software release to counter the threat.
Metrics
infrastructure
3.51
Software Version
It has been addressed in the following versions -
3.1 - Fixed in 3.1 Patch 12
3.2 - Fixed in 3.2 Patch 11
3.3 - Fixed in 3.3 Patch 12
3.4 - Fixed in 3.4 Patch 7
3.51 - Fixed in 3.5 Patch 4
Cisco said it's "aware of active exploitation of this vulnerability," urging customers to upgrade to a fixed software release to counter the threat.
Metrics
infrastructure
3.5
Software Version
It has been addressed in the following versions -
3.1 - Fixed in 3.1 Patch 12
3.2 - Fixed in 3.2 Patch 11
3.3 - Fixed in 3.3 Patch 12
3.4 - Fixed in 3.4 Patch 7
3.51 - Fixed in 3.5 Patch 4
Cisco said it's "aware of active exploitation of this vulnerability," urging customers to upgrade to a fixed software release to counter the threat.
Metrics
infrastructure
9.8
Software Version
Software for Cisco Secure Email Gateway (
CVE-2026-76461
, CVSS score: 9.8) has come under active exploitation in the wild.
CVE-2026-20242 (CVSS score: 9.8)
- A vulnerability in the External Database Access feature of FMC Software that could allow an unauthenticated, remote attacker to execute arbitrary commands as root on an affected device.
Metrics
infrastructure
9
Multiple Vulnerabilities
A brief description of the flaws is below -
CVE-2026-20176 (CVSS score: 9.9), CVE-2026-20211 (CVSS score: 9.1), CVE-2026-20307 (CVSS score: 9.1)
- Multiple vulnerabilities in ISE that could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device.
CVE-2026-20305 (CVSS score: 9.1), CVE-2026-20306 (CVSS score: 9.1)
- Multiple vulnerabilities in ISE and ISE-PIC that could allow an authenticated, remote attacker to perform command injection attacks on an affected device and execute arbitrary commands as the root user.
Metrics
infrastructure
76,409
Multiple Vulnerabilities
CVE-2026-20322 (CVSS score: 9.9), CVE-2026-20325 (CVSS score: 9.9), CVE-2026-20326 (CVSS score: 9.8), CVE-2026-20360, CVE-2026-20361, CVE-2026-76409
- Multiple vulnerabilities in Cisco Nexus Dashboard that could lead to command injection, authentication or authorization bypass, and information disclosure.
Metrics
infrastructure
20,287
Cve-2026 Multiple
CVE-2026-20130 (CVSS score: 10.0), CVE-2026-20192 (CVSS score: 10.0), CVE-2026-20194 (CVSS score: 9.1), CVE-2026-20234 (CVSS score: 9.9), CVE-2026-20237 (CVSS score: 9.9), CVE-2026-20287
- Multiple vulnerabilities in ISE and ISE-PIC that could lead to command injection, authentication or authorization bypass, and information disclosure.
Metrics
infrastructure
9.1
Software Version
CVE-2026-20340, CVE-2026-20341 (CVSS score: 9.1), CVE-2026-20342, CVE-2026-20343, CVE-2026-20344
- Multiple vulnerabilities in FMC Software that could allow a remote attacker to gain root access, download sensitive files, perform a SQL injection attack, or cause a denial-of-service (DoS) condition.
Intelligence Sources
The Hacker News
2026-09-17
CISA Advisories
2026-10-01
Monta monta.app
CISA Advisories
CISA
2026-10-01
Monta monta.app
CISA
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-03T15:34
Comprehensive Tactical Telemetry
Highly Correlated Entities
55x
vulnerability
Exploited CVE
CVE-2026-95102
cve
43x
organisation
Identified Entity
WebSocket
entity
12x
infrastructure
Software Version
9.4
version
8x
attribution
Attributing Entity
Improving Industrial Control Systems Cybersecurity
authority
8x
general metric
Patch
3
patch
5x
timeline
Temporal Reference
2026/10/01
Date
Revision
Summary
2026
date
4x
tactic
Cyber Operation Type
Impersonate
tactic
4x
industry
Targeted Sector
Energy
sector
4x
general metric
Cvss Score
10
cvss score
3x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
3x
infrastructure
Multiple Vulnerabilities
9
multiple vulnerabilities
Contextual Telemetry
Context Block
13 METRICS
target region
Target Country
Netherlands
country
general metric
Monta
9
monta
general metric
Summary Publication Legal Notice
10
summary publication legal notice
general metric
Initial Publication
1
initial publication
infrastructure
Tip-12
146
tip-12
vulnerability
CVSS Score
10
score
general metric
Versions
3
versions
general metric
Cisco
4
cisco
general metric
Score
9
score
infrastructure
Cve-2026 Multiple
20,287
cve-2026 multiple
general metric
Sep
17
sep
general metric
Wednesday
41
wednesday
general metric
Ise
28
ise
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.