Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Cisco has disclosed a critical vulnerability (CVE-2026-76460) in its Identity Services Engine (ISE) that allows unauthenticated remote attackers to bypass authentication via a flaw in an API endpoint. This vulnerability has a CVSS score of 10.0 and is actively being exploited in the wild, prompting...
On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic....
On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like Wha...
Acronis has released urgent patches for a high-severity vulnerability (CVE-2026-87886) in its Backup plugin for cPanel & WHM and Plesk, which has been actively exploited in targeted attacks. The flaw, stemming from insecure file permissions, allows low-privileged attackers to escalate their privileg...