INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Cisco Warns of Active Exploitation of Critical ISE Flaw

| 2026-10-01 12:00 HIGH MEDIUM EXPLOITED VULNERABILITY
Executive Summary
AI-generated
A critical authorization flaw has been discovered in the Meari IoT Cloud Platform OpenAPI Service, allowing authenticated users to manipulate device configurations they do not own. The vulnerability affects all versions of the service, with a CVSS score of 7.7 and identified by CVE-2026-101104 and CVE-2026-96613. This issue impacts commercial facilities, information technology, and industrial control systems sectors worldwide, particularly in China. CISA has reported these vulnerabilities to Gabriel Adams and provides resources for improving cybersecurity strategies. Organizations are encouraged to implement recommended defense-in-depth strategies to protect ICS assets.
Technical Mitigations AI-generated
• Implement role-based access control to restrict device configuration manipulation and unauthorized behavior. • Use secure authentication mechanisms, such as multi-factor authentication (MFA), to verify the identity of users requesting access to sensitive information. • Isolate Meari IoT Cloud Platform OpenAPI Service behind firewalls and ensure it is not accessible from the internet.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

ac•••••.log
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-20176CVE-2026-20176 CVE-2026-20211CVE-2026-20211 CVE-2026-20284CVE-2026-20284 CVE-2025-20337CVE-2025-20337 CVE-2026-101104CVE-2026-101104 CVE-2026-20307CVE-2026-20307 CVE-2026-76460CVE-2026-76460 CVE-2026-76423CVE-2026-76423 CVE-2026-96613CVE-2026-96613
Target & Sectors
CN
manufacturingmanufacturing
Incident Timeline
‎July 2025
Threat actors exploited the Cisco ISE zero-day vulnerability CVE-2025-20337 to deploy a custom web shell disguised as an IdentityAuditAction component on the Meari IoT Cloud Platform OpenAPI Service.
vulnerability CVE-2025-20337
tactic Remote Code Execution
‎September 16
Threat actors successfully exploited a vulnerability in the Meari IoT Cloud Platform OpenAPI service, allowing unauthorized access to affected devices via the web-based management interface.
‎2026/09/16
Threat actors used unpatched authentication bypass flaws in Cisco ISE-PIC to target the Meari IoT Cloud Platform OpenAPI Service.
vulnerability CVE-2026-76460
vulnerability CVE-2026-76423
vulnerability CVE-2026-20176
vulnerability CVE-2026-20211
vulnerability CVE-2026-20307
vulnerability CVE-2026-20284
organisation Cisco ISE-PIC
‎2026/10/01
Threat actors exploited a vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), tracked as CVE-2026-76460, to bypass authentication.
organisation Platform OpenAPI Service
infrastructure 7.7
organisation CVSS
organisation Vendor Equipment
organisation Initial Release Date
infrastructure 146 TIP-12
organisation Meari IoT Cloud Platform OpenAPI Service
organisation Affected Products
organisation Virtual Private Networks
organisation API
organisation Cisco ISE Passive Identity Connector
organisation API of Cisco Identity Services Engine
organisation CVE-2026-76460
organisation Product Security Incident Response Team
infrastructure 3.1
infrastructure 3.2
infrastructure 3.3
infrastructure 3.4
infrastructure 3.5
organisation ISE-PIC Release
organisation Cisco Identity Services Engine
organisation Cisco ISE
organisation Zero Trust
organisation Cisco Customers Told
organisation IP
organisation Admins
organisation Identity Services Engine
organisation NFL
organisation CHANEL
Tactical Metrics
Metrics
infrastructure
‎7.7
Software Version
Metrics
infrastructure
146
Tip-12
Metrics
infrastructure
‎3.1
Software Version
Metrics
infrastructure
‎3.2
Software Version
Metrics
infrastructure
‎3.3
Software Version
Metrics
infrastructure
‎3.4
Software Version
Metrics
infrastructure
‎3.5
Software Version
Intelligence Sources
BleepingComputer 2026-09-17
Infosecurity-Magazine 2026-09-17
CISA Advisories 2026-10-01