PDF briefing studio

Prepare a decision-ready brief.

Select a reporting window. Top cyber news, vulnerabilities and CISA ICS advisories are ranked automatically.

OT Daily BriefIndustrial cyber intelligence
Source-groundedweek decision brief
OT / ICS / BAS intelligenceDecision brief / 2026.09.25
Intelligence for industrial defenders

Weekly
cyber risk brief.

September 19, 2026 — September 25, 2026

This edition / priority focus

Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

Threat posture50 active signals
Scope15 selected signals
Source-grounded intelligence / selected reporting windowEvidence / exposure / operational context
Analyzed251Feed items
Selected15Relevant signals
Critical29Priority items
Active50Exploitation signals
Sources2Referenced
Vendor concentrationWithin vendors
Linux3
Cisco2
Check Point2
Adobe1
Technology concentrationWithin technologies
Multiple Products3
Kernel3
Identity Services Engine1
Secure Email Gateway1
Period pulseLatest reporting movement
19202122232425
High / Critical / Active exploitation
Editorial movementLatest 4 selected editions
Active threat: Check Point Multiple Products Improper Certificate Validation Vulnerability

7 confirmed active-exploitation signals, 4 critical items, and 7 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.

22 analyzed
Active threat: Check Point Multiple Products Improper Certificate Validation Vulnerability

8 confirmed active-exploitation signals, 4 critical items, and 8 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.

31 analyzed
Active threat: Check Point Multiple Products Improper Certificate Validation Vulnerability

8 confirmed active-exploitation signals, 4 critical items, and 8 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.

37 analyzed
Active threat: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

7 confirmed active-exploitation signals, 3 critical items, and 9 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.

40 analyzed

Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

14 items have authoritative exploitation evidence and should move first through exposure validation. Current concentration is around Cisco, Check Point, Adobe; use the product context in the queue to compare it with the asset inventory.

14 active exploitation signals1 critical item7 editions reviewed
Now
Validate active exposure

Confirm asset, version, reachability and compensating controls for Cisco.

Next window
Plan safe remediation

Review maintenance constraints and vendor guidance for CVE-2026-85751: Mailu is a mail server distributed as a set of Docker images.

Active threat: Check Point Multiple Products Improper Certificate Validation Vulnerability

7 confirmed active-exploitation signals, 4 critical items, and 7 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.

Active threat: Check Point Multiple Products Improper Certificate Validation Vulnerability

8 confirmed active-exploitation signals, 4 critical items, and 8 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.

Active threat: Check Point Multiple Products Improper Certificate Validation Vulnerability

8 confirmed active-exploitation signals, 4 critical items, and 8 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.

01
ACTIVECVEOT relevance 58%EPSS 0.8%

CVE-2026-76460: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Cisco / Identity Services EngineCISA KEV
02
ACTIVECVEOT relevance 36%EPSS 1.0%

CVE-2026-85102: Check Point Multiple Products Improper Certificate Validation Vulnerability

Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Check Point / Multiple ProductsCISA KEV
03
ACTIVECVEOT relevance 33%EPSS 2.0%

CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability

Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Cisco / Secure Email GatewayCISA KEV
04
ACTIVECVEOT relevance 15%EPSS 2.4%

CVE-2026-93616: Check Point Multiple Products Path Traversal Vulnerability

Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Check Point / Multiple ProductsCISA KEV
05
ACTIVECVEOT relevance 15%EPSS 2.3%

CVE-2026-71362: Adobe Commerce and Magento Incorrect Authorization Vulnerability

Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Adobe / Commerce and Magento CISA KEV
06
ACTIVECVEOT relevance 15%EPSS 2.0%

CVE-2025-39682: Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Linux / KernelCISA KEV
07
ACTIVECVEOT relevance 15%EPSS 1.3%

CVE-2026-94127: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

F5 / BIG-IP APMCISA KEV
08
ACTIVECVEOT relevance 15%EPSS 1.3%

CVE-2026-7273: Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability

Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Zyxel / GS1900 Series SwitchesCISA KEV
09
ACTIVECVEOT relevance 15%EPSS 0.9%

CVE-2026-93952: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability

Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Arista / VeloCloud OrchestratorCISA KEV
10
ACTIVECVEOT relevance 15%EPSS 0.8%

CVE-2025-39964: Linux Kernel Race Condition Vulnerability

Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Linux / KernelCISA KEV
11
ACTIVECVEOT relevance 15%EPSS 0.4%

CVE-2026-5430: WSO2 Multiple Products Path Traversal Vulnerability

WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

WSO2 / Multiple ProductsCISA KEV
12
ACTIVECVEOT relevance 15%EPSS 0.3%

CVE-2026-53266: Linux Kernel Out-of-Bounds Write Vulnerability

Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Linux / KernelCISA KEV
CVECISA KEVActive signal

CVE-2026-76460: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CISA KEV
CVECISA KEVActive signal

CVE-2026-85102: Check Point Multiple Products Improper Certificate Validation Vulnerability

Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CISA KEV
CVECISA KEVActive signal

CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability

Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CISA KEV
Active threat: Check Point Multiple Products Improper Certificate Validation Vulnerability7 confirmed active-exploitation signals, 4 critical items, and 7 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.22 analyzed
Active threat: Check Point Multiple Products Improper Certificate Validation Vulnerability8 confirmed active-exploitation signals, 4 critical items, and 8 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.31 analyzed
Active threat: Check Point Multiple Products Improper Certificate Validation Vulnerability8 confirmed active-exploitation signals, 4 critical items, and 8 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.37 analyzed
Active threat: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability7 confirmed active-exploitation signals, 3 critical items, and 9 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.40 analyzed
Active threat: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability6 confirmed active-exploitation signals, 6 critical items, and 6 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.37 analyzed
Active threat: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability7 confirmed active-exploitation signals, 4 critical items, and 8 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.35 analyzed
Active threat: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability7 confirmed active-exploitation signals, 4 critical items, and 8 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.49 analyzed
Methodology / transparent by design

Evidence first.
Context always.

A triage aid for exposure validation and operational review.

Exploit evidence
OT relevance
Severity
Source confidence
+10EPSS acceleratorMaximum additional points
100-point base model + up to 10 predictive points. The score is not a percentage of plant risk.
Evidence standard

Active exploitation is reserved for authoritative confirmation. CVSS alone is never treated as operational risk; exposure, process context and safe remediation remain essential.