INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Cisco Warns of New Zero-Day ISE Auth Bypass Exploited

| 2026-10-01 12:00 CRITICAL MEDIUM EXPLOITED VULNERABILITY
Executive Summary
AI-generated
A critical vulnerability has been discovered in Monta [IOC HIDDEN • LOGIN REQUIRED], a widely used software solution, leaving it exposed to impersonation attacks. The identified vulnerabilities include CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, and CVE-2026-93474, with CVSS scores indicating a high level of severity. This lack of authentication mechanisms enables attackers to gain unauthorized access to the system, potentially leading to privilege escalation and compromising the entire security framework. Monta [IOC HIDDEN • LOGIN REQUIRED] versions 9.4 are affected by these vulnerabilities, which have been deployed in various sectors including energy and transportation systems worldwide.
Technical Mitigations AI-generated
• Implement rate limiting on WebSocket endpoints to prevent denial-of-service attacks and brute-force attempts. • Use unique, unpredictable session identifiers for each charging station connection to prevent unauthorized authentication and denial-of-service conditions. • Enforce proper authentication mechanisms, such as multi-factor authentication or secure password storage, to prevent impersonation of charging stations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

mo•••••.app
ac•••••.log
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-97363CVE-2026-97363 CVE-2026-20360CVE-2026-20360 CVE-2026-20334CVE-2026-20334 CVE-2026-95102CVE-2026-95102 CVE-2026-20282CVE-2026-20282 CVE-2026-20211CVE-2026-20211 CVE-2026-20306CVE-2026-20306 CVE-2026-20284CVE-2026-20284 CVE-2026-20353CVE-2026-20353 CVE-2026-20307CVE-2026-20307 CVE-2026-20340CVE-2026-20340 CVE-2026-20176CVE-2026-20176 CVE-2026-76420CVE-2026-76420 CVE-2026-76441CVE-2026-76441 CVE-2026-20283CVE-2026-20283 CVE-2026-97212CVE-2026-97212 CVE-2026-20326CVE-2026-20326 CVE-2026-76425CVE-2026-76425 CVE-2026-76443CVE-2026-76443 CVE-2026-76428CVE-2026-76428 CVE-2026-76424CVE-2026-76424 CVE-2026-76423CVE-2026-76423 CVE-2026-76409CVE-2026-76409 CVE-2026-20305CVE-2026-20305 CVE-2026-20361CVE-2026-20361 CVE-2026-20342CVE-2026-20342 CVE-2026-20325CVE-2026-20325 CVE-2026-20329CVE-2026-20329 CVE-2026-20336CVE-2026-20336 CVE-2026-76442CVE-2026-76442 CVE-2026-20242CVE-2026-20242 CVE-2026-20335CVE-2026-20335 CVE-2026-20192CVE-2026-20192 CVE-2026-76461CVE-2026-76461 CVE-2026-93474CVE-2026-93474 CVE-2026-20130CVE-2026-20130 CVE-2026-20344CVE-2026-20344 CVE-2026-76440CVE-2026-76440 CVE-2026-20330CVE-2026-20330 CVE-2026-20237CVE-2026-20237 CVE-2026-20234CVE-2026-20234 CVE-2026-20331CVE-2026-20331 CVE-2026-20332CVE-2026-20332 CVE-2026-20322CVE-2026-20322 CVE-2026-20333CVE-2026-20333 CVE-2026-20194CVE-2026-20194 CVE-2026-20343CVE-2026-20343 CVE-2026-76426CVE-2026-76426 CVE-2026-20324CVE-2026-20324 CVE-2026-20287CVE-2026-20287 CVE-2026-76413CVE-2026-76413 CVE-2026-76460CVE-2026-76460 CVE-2026-76427CVE-2026-76427 CVE-2026-20341CVE-2026-20341 CVE-2026-76412CVE-2026-76412
Target & Sectors
BENELUX BENELUX manufacturingmanufacturing transportationtransportation
Incident Timeline
‎September 16, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76460 to its Known Exploited Vulnerabilities catalog on September 16, 2026.
tactic T1588.006 - Vulnerabilities
vulnerability CVE-2026-76460
attribution Known Exploited
attribution KEV
attribution Federal Civilian Executive Branch
attribution FCEB
‎Sep 17, 2026
Threat actors exploited a vulnerability in the Monta monta.app website to gain unauthorized access.
‎September 19, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76460 to its Known Exploited Vulnerabilities catalog, requiring Federal Civilian Executive Branch agencies to apply the patches by September 19, 2026.
tactic T1588.006 - Vulnerabilities
vulnerability CVE-2026-76460
attribution Known Exploited
attribution KEV
attribution Federal Civilian Executive Branch
attribution FCEB
‎2026/10/01
Threat actors used multiple vulnerabilities in Monta monta.app, including a WebSocket Application Programming Interface with insufficient authentication mechanisms and missing authentication for critical functions, to impersonate charging stations and execute arbitrary commands.
organisation WebSocket
infrastructure 9.4
organisation CVSS
organisation Vendor Equipment
organisation Monta Monta
organisation Missing Authentication for Critical Function
organisation Transportation Systems Countries/Areas Deployed
organisation Monta
organisation Affected Products Monta
organisation Monta Product Version
organisation The WebSocket Application Programming Interface
infrastructure 9.8
organisation Cisco Secure Email Gateway
organisation this Privacy & Use
organisation Initial Release Date
infrastructure 9.9
infrastructure 9.6
infrastructure 9.0
organisation Cisco Secure Firewall Adaptive Security Appliance
organisation Cisco Secure Firewall Threat Defense
organisation Cisco Secure Firewall Management Center
organisation CWE
infrastructure 146 TIP-12
organisation Virtual Private Networks
organisation CVE-2026-20324
organisation CVE-2026-76413
infrastructure 9.0 Multiple vulnerabilities
infrastructure 9.1
organisation DoS
organisation the External Database Access
infrastructure 9.1 Multiple vulnerabilities
organisation CVE-2026-20322
infrastructure 76409 Multiple vulnerabilities
organisation CVE-2026-20130
infrastructure 20287 CVE-2026 Multiple
infrastructure 3.1
infrastructure 3.2
infrastructure 3.3
infrastructure 3.4
infrastructure 3.51
infrastructure 3.5
organisation Cisco
organisation CVE-2026-20306
organisation ISE-PIC
organisation CVE-2026-76423
organisation CVE-2026-76425
organisation CVE-2026
organisation ISE
organisation SQL
organisation XML External
organisation CVE-2026-20353
organisation CVE-2026-76440
organisation CVE-2026-76441
organisation Vulnerability / Web Security
organisation Identity Services Engine
organisation API
organisation Cisco ISE
organisation Cisco ISE Passive Identity Connector
organisation Secure Firewall
Tactical Metrics
Metrics
infrastructure
‎9.4
Software Version
Metrics
infrastructure
146
Tip-12
Metrics
infrastructure
‎9.9
Software Version
Metrics
infrastructure
‎9.6
Software Version
Metrics
infrastructure
‎9.0
Software Version
Metrics
infrastructure
9
Multiple Vulnerabilities
Metrics
infrastructure
‎3.1
Software Version
Metrics
infrastructure
‎3.2
Software Version
Metrics
infrastructure
‎3.3
Software Version
Metrics
infrastructure
‎3.4
Software Version
Metrics
infrastructure
‎3.51
Software Version
Metrics
infrastructure
‎3.5
Software Version
Metrics
infrastructure
‎9.8
Software Version
Metrics
infrastructure
9
Multiple Vulnerabilities
Metrics
infrastructure
76,409
Multiple Vulnerabilities
Metrics
infrastructure
20,287
Cve-2026 Multiple
Metrics
infrastructure
‎9.1
Software Version
Intelligence Sources
CISA Advisories 2026-10-01
Monta monta.app CISA Advisories
CISA 2026-10-01