Thursday, September 17, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Cisco accounts for the largest share of yesterday's critical disclosures, with Identity Services Engine, Secure Firewall Management Center, and Adaptive Security Appliance software all affected. The day brought 19 critical CVEs (down 70 percent from the prior day's 64) and 87 high-priority CVEs (up 47 percent from 59), for 106 total. CVE-2026-20130 and CVE-2026-20192 both score CVSS 10 in Cisco Identity Services Engine Software, CVE-2026-70416 scores CVSS 10 in Dell ObjectScale, and CVE-2026-20242 scores CVSS 9.8 in Cisco Secure Firewall Management Center. The pattern favors pre-authentication flaws in network access control, firewall management, and storage platforms, alongside web application issues in uvdesk community-skeleton and a WordPress file upload plugin, and eight CVEs carry confirmed active exploitation including CVE-2026-76460 in Cisco ISE. Inventory Cisco ISE, FMC, and ASA deployments first, restrict management interface access to trusted administrative networks, and verify fix status for each affected product in the vendor's own advisory.

  • Cisco Identity Services Engine Software carries multiple CVSS 10 flaws (CVE-2026-20130, CVE-2026-20192, CVE-2026-76423), making it the highest-priority platform to review
  • 19 critical CVEs (CVSS 9.0+), down 70 percent from 64 the prior day
  • 87 high-priority CVEs (CVSS 7.0 to 8.9), up 47 percent from 59 the prior day
  • Remote code execution and authentication bypass patterns concentrate in security infrastructure: Cisco Secure Firewall Management Center (CVE-2026-20242, CVSS 9.8) and ASA Software (CVE-2026-20332, CVSS 9.9)
  • Check first: Cisco ISE, FMC and ASA, Dell ObjectScale (CVE-2026-70416, CVSS 10), uvdesk community-skeleton (CVE-2026-92805, CVSS 9.8), and the sh1zen Multi Uploader for Gravity Forms plugin (CVE-2026-87796, CVSS 9.8)
  • Eight CVEs have confirmed active exploitation, spanning ConnectWise ScreenConnect, GitLab, Cisco Secure Email Gateway and ISE, Google Pixel, Acronis Backup, and JFrog Artifactory

Immediate action: Prioritize Cisco Identity Services Engine, Secure Firewall Management Center, and ASA Software, then Dell ObjectScale, JFrog Artifactory, and ConnectWise ScreenConnect where active exploitation is confirmed. Limit exposure of administrative and management interfaces to trusted networks while you work through the list. Confirm the fixed release and any interim mitigations in each vendor's own advisory before scheduling maintenance.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation