PDF briefing studio

Prepare a decision-ready brief.

Select a reporting window. Top cyber news, vulnerabilities and CISA ICS advisories are ranked automatically.

OT Daily BriefIndustrial cyber intelligence
Source-groundedweek decision brief
OT / ICS / BAS intelligenceDecision brief / 2026.09.18
Intelligence for industrial defenders

Weekly
cyber risk brief.

September 12, 2026 — September 18, 2026

This edition / priority focus

Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

Threat posture66 active signals
Scope15 selected signals
Source-grounded intelligence / selected reporting windowEvidence / exposure / operational context
Analyzed390Feed items
Selected15Relevant signals
Critical11Priority items
Active66Exploitation signals
Sources1Referenced
Vendor concentrationWithin vendors
Cisco3
MikroTik2
JFrog2
Citrix1
Technology concentrationWithin technologies
RouterOS2
Artifactory2
Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management1
Identity Services Engine1
Period pulseLatest reporting movement
12131415161718
High / Critical / Active exploitation
Editorial movementLatest 4 selected editions
Active threat: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

4 confirmed active-exploitation signals, 7 critical items, and 5 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.

85 analyzed
Active threat: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

8 confirmed active-exploitation signals, 1 critical item, and 11 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.

78 analyzed
Active threat: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

7 confirmed active-exploitation signals, 3 critical items, and 9 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.

47 analyzed
Active threat: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

11 confirmed active-exploitation signals, 0 critical items, and 12 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.

51 analyzed

Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

15 items have authoritative exploitation evidence and should move first through exposure validation. Current concentration is around Cisco, Citrix, Fortinet; use the product context in the queue to compare it with the asset inventory.

15 active exploitation signals0 critical items7 editions reviewed
Now
Validate active exposure

Confirm asset, version, reachability and compensating controls for Cisco.

Active threat: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

4 confirmed active-exploitation signals, 7 critical items, and 5 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.

Active threat: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

8 confirmed active-exploitation signals, 1 critical item, and 11 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.

Active threat: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

7 confirmed active-exploitation signals, 3 critical items, and 9 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.

01
ACTIVECVEOT relevance 40%EPSS 75.8%

CVE-2026-20079: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementCISA KEV
02
ACTIVECVEOT relevance 58%

CVE-2026-76460: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Cisco / Identity Services EngineCISA KEV
03
ACTIVECVEOT relevance 40%EPSS 5.6%

CVE-2026-19490: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Citrix / NetScalerCISA KEV
04
ACTIVECVEOT relevance 40%EPSS 2.4%

CVE-2025-25249: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability

Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Fortinet / Multiple ProductsCISA KEV
05
ACTIVECVEOT relevance 40%EPSS 1.1%

CVE-2026-86060: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacker to change the trusted RouterOS policy mask, leading to privilege escalation. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

MikroTik / RouterOSCISA KEV
06
ACTIVECVEOT relevance 40%EPSS 0.9%

CVE-2026-67277: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability

MikroTik RouterOS contains a missing authentication for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

MikroTik / RouterOSCISA KEV
07
ACTIVECVEOT relevance 40%EPSS 0.9%

CVE-2026-87491: Google Chromium V8 Out of Bounds Write Vulnerability

Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Google / Chromium V8CISA KEV
08
ACTIVECVEOT relevance 40%EPSS 0.7%

CVE-2026-86218: N-able N-central Static Code Injection Vulnerability

N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

N-able / N-centralCISA KEV
09
ACTIVECVEOT relevance 33%EPSS 2.0%

CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability

Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Cisco / Secure Email GatewayCISA KEV
10
ACTIVECVEOT relevance 33%EPSS 0.9%

CVE-2026-42018: JFrog Artifactory Improper Authentication Vulnerability

JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

JFrog / ArtifactoryCISA KEV
11
ACTIVECVEOT relevance 33%EPSS 0.9%

CVE-2026-42016: JFrog Artifactory Incorrect Authorization Vulnerability

JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

JFrog / ArtifactoryCISA KEV
12
ACTIVECVEOT relevance 33%EPSS 0.7%

CVE-2026-84869: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote session without authorization or host confirmation. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

ConnectWise / ScreenConnectCISA KEV
CVECISA KEVActive signal

CVE-2026-20079: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CISA KEV
CVECISA KEVActive signal

CVE-2026-76460: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CISA KEV
CVECISA KEVActive signal

CVE-2026-19490: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CISA KEV
Active threat: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability4 confirmed active-exploitation signals, 7 critical items, and 5 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.85 analyzed
Active threat: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability8 confirmed active-exploitation signals, 1 critical item, and 11 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.78 analyzed
Active threat: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability7 confirmed active-exploitation signals, 3 critical items, and 9 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.47 analyzed
Active threat: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability11 confirmed active-exploitation signals, 0 critical items, and 12 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.51 analyzed
Active threat: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability12 confirmed active-exploitation signals, 0 critical items, and 12 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.40 analyzed
Active threat: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability12 confirmed active-exploitation signals, 0 critical items, and 12 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.36 analyzed
Active threat: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability12 confirmed active-exploitation signals, 0 critical items, and 12 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.53 analyzed
Methodology / transparent by design

Evidence first.
Context always.

A triage aid for exposure validation and operational review.

Exploit evidence
OT relevance
Severity
Source confidence
+10EPSS acceleratorMaximum additional points
100-point base model + up to 10 predictive points. The score is not a percentage of plant risk.
Evidence standard

Active exploitation is reserved for authoritative confirmation. CVSS alone is never treated as operational risk; exposure, process context and safe remediation remain essential.