CRITICAL 13 min read 17 Sep 2026

Multiple vulnerabilities in Cisco Identity Services Engine Leads Today's Security Review

Threat Level: Critical Tags: cve-2026-20176, cve-2026-20211, cve-2026-20307, cve-2026-20282, cve-2026-20283, cve-2026-20284, cve-2026-76423, cve-2026-76424, cve-2026-76425, cve-2026-76426

Key findings
01
Multiple vulnerabilities in Cisco Identity Services Engine
CRITICAL
CVE coverage: CVE-2026-20176, CVE-2026-20211, CVE-2026-20307, CVE-2026-20282, CVE-2026-20283, CVE-2026-20284, CVE-2026-76423, CVE-2026-76424, CVE-2026-76425, CVE-2026-76426, CVE-2026-76427, CVE-2026-76428, CVE-2026-20305, CVE-2026-20306, CVE-2026-76460, CVE-2026-20352, CVE-2026-20071, CVE-2026-20072, CVE-2026-76431, CVE-2026-76432, CVE-2026-76433, CVE-2026-76434, CVE-2026-20309, CVE-2026-20285, CVE-2026-20286, CVE-2026-76439, CVE-2026-76444, CVE-2026-76446, CVE-2026-76447, CVE-2026-76448, CVE-2026-76449, CVE-2026-76450, CVE-2026-76451, CVE-2026-20247, CVE-2026-20300, CVE-2026-20235.
02
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
CRITICAL
A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation.
03
Enterprises Warned of Attacks Exploiting WSO2 Vulnerability
CRITICAL
A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic signature that could result in account takeover.
04
Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026
CRITICAL
CVE coverage: CVE-2026-20329, CVE-2026-20330, CVE-2026-20331, CVE-2026-20332, CVE-2026-20333, CVE-2026-20334, CVE-2026-20335, CVE-2026-20336, CVE-2026-20242, CVE-2026-20130, CVE-2026-20192, CVE-2026-20194, CVE-2026-20234, CVE-2026-20237, CVE-2026-20287, CVE-2026-20322, CVE-2026-20325,
05
@zereight/mcp-gitlab: Unauthenticated arbitrary file read via 'upload_markdown' enables PAT exfiltration and full account takeover
CRITICAL
@zereight/mcp-gitlab: Unauthenticated arbitrary file read via upload_markdown enables PAT exfiltration and full account takeover The cited source identifies the affected product and the available advisory or remediation status. CVE coverage: CVE-2026-61560.
06
LMdeploy: Deserialization of Untrusted Data
CRITICAL
LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy The cited source identifies the affected product and the available advisory or remediation status. CVE coverage: CVE-2025-59953.
07
Multiple vulnerabilities in djust
CRITICAL
djust carries 10 CVEs across 5 advisories: Cross-Site Request Forgery on the Server-Sent-Events transport; Multi-tenant isolation fails open on the WebSocket/SSE path; Broken object-level access control (IDOR); Vulnerable to stored/reflected XSS via javascript: URLs in built-in com; mount path; view-mount path.
08
Google Pixel Improper Authorization Vulnerability
HIGH
Google Pixel Improper Authorization Vulnerability. The cited source identifies the affected product and the available advisory or remediation status. The assigned identifier is CVE-2026-58704.
09
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
HIGH
Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. The cited source identifies the affected product and the available advisory or remediation status. The assigned identifier is CVE-2026-85921.
10
Multiple vulnerabilities in Chromium
HIGH
Chromium fixes 5 CVEs in one release: Buffer overflow in WebRTC; Missing authorization in Extensions; Incomplete cleanup in Browser; Incorrect authorization in Navigation; Confused deputy in Prerender. CVE coverage: CVE-2026-87430, CVE-2026-87431, CVE-2026-87436, CVE-2026-87432, CVE-2026-87442.
11
OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS
HIGH
OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS The cited source identifies the affected product and the available advisory or remediation status. CVE coverage: CVE-2026-81192.
12
Multiple vulnerabilities in Xpand IT Write-Back Manager
HIGH
CVE coverage: CVE-2026-92205, CVE-2023-27170. The cited advisories disclose: Arbitrary File Creation Vulnerability; via modification of the siteName parameter.
13
GitPython: Improper Neutralization of Special Elements in Output
HIGH
GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names.
14
Cisco ThousandEyes Virtual Appliance Authenticated Web Interface Command Injection Vulnerability
MEDIUM
A vulnerability in the web-based management interface of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to inject arbitrary operating system commands. This vulnerability is due to improper validation of user-supplied input to the web-based management interface.
15
Cisco BroadWorks CommPilot Application Software Authorization Bypass Vulnerability
MEDIUM
A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker with low privileges to alter configurations on an affected device. This vulnerability is due to missing authorization checks.

Executive assessment

Today's brief leads with Multiple vulnerabilities in Cisco Identity Services Engine. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.

Panel synthesis: Finding 01 leads because it is critical, exploitation is listed as in the wild, and fixed patch levels are provided across the affected Cisco ISE branches. Themes: Actively exploited critical flaws; Management-interface exposure controls; Vendor fixes available. Patch order: Finding 01 (Critical Cisco ISE vulnerabilities are being exploited in the wild, with fixed patch levels listed); Finding 02 (Critical unauthenticated OS command execution is being exploited in the wild, with patch commit b97dbaf listed); Finding 03 (Critical WSO2 vulnerability is being exploited in the wild, with fixed support update levels listed); Finding 08 (High-severity Pixel improper authorization vulnerability is being exploited in the wild, with security patch level 2026-09-05 or later listed as fixed).

Finding 01 — Multiple vulnerabilities in Cisco Identity Services Engine

What changed: CVE coverage: CVE-2026-20176, CVE-2026-20211, CVE-2026-20307, CVE-2026-20282, CVE-2026-20283, CVE-2026-20284, CVE-2026-76423, CVE-2026-76424, CVE-2026-76425, CVE-2026-76426, CVE-2026-76427, CVE-2026-76428, CVE-2026-20305, CVE-2026-20306, CVE-2026-76460, CVE-2026-20352, CVE-2026-20071, CVE-2026-20072, CVE-2026-76431, CVE-2026-76432, CVE-2026-76433, CVE-2026-76434, CVE-2026-20309, CVE-2026-20285, CVE-2026-20286, CVE-2026-76439, CVE-2026-76444, CVE-2026-76446, CVE-2026-76447, CVE-2026-76448, CVE-2026-76449, CVE-2026-76450, CVE-2026-76451, CVE-2026-20247, CVE-2026-20300, CVE-2026-20235. The cited advisories disclose: Remote Code Execution Vulnerabilities; Authenticated Remote Code Execution and API Vulnerabilities; Vulnerabilities; Command Injection Vulnerabilities; Authentication Bypass Vulnerability; RADIUS Denial of Service Vulnerability; 802.1X Session Hijack and Information Disclosure Vulnerabilities; Multiple Path Traversal Vulnerabilities; Cross-Site Scripting Vulnerability; Authorization Bypass Vulnerabilities; Authentication Bypass Vulnerabilities; SQL and HQL Injection Vulnerabilities; SQL Injection Vulnerabilities; Information Disclosure Vulnerability.

Technical evidence: CVE-2026-20176; CVSS v3.1 9.1; weakness CWE-77; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: For CVE-2026-76460, use iACLs to allow only required management and control-plane traffic to affected devices; review each node's ise-kong/access.log for suspicious usernames and cross-check external network and firewall logs. For CVE-2026-20283, remove vulnerable API-created IPsec VTI tunnels and recreate them through the web interface. Cisco PSIRT reports active exploitation of CVE-2026-76460. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5), [sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-mult-vul-ymSsTLCc))

Fix: For CVE-2026-76460: 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5))

Panel assessment: Patch now: Cisco reports active exploitation of CVE-2026-76460, it affects ISE and ISE-PIC regardless of configuration, and RCE on an identity and network-access control platform carries a high blast radius even before estate-specific exposure is known. The practical attack path is remote code execution through command injection or unsafe deserialisation against the appliance, giving an attacker a route into the service that brokers identity and access-control decisions. (priority: patch now)

Action: Map CVE-2026-20176 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-se7bYU57?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Remote%20Code%20Execution%20Vulnerabilities%26vs_k=1)

Finding 02 — Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

What changed: A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded The cited source identifies the affected product and the available advisory or remediation status.

Technical evidence: CVE-2026-89026; CVSS v4.0 9.3; weakness CWE-321; technical confidence Medium.

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: The cited source reports active in-the-wild exploitation; independent corroboration (CISA KEV or grounded vendor data) is not yet available.

Analyst note: Restrict network access to the Asterisk manager originate endpoint (pbxapi/manager/originate) so unauthenticated remote attackers cannot reach it. VulnCheck reports that the Shadowserver Foundation first observed exploitation evidence on 9 September 2026. ([vulncheck.com](https://www.vulncheck.com/advisories/issabel-pbx-hard-coded-jwt-key-rce-via-pbxapi-manager-originate), [secalerts.co](https://secalerts.co/vulnerability/CVE-2026-89026))

Affected: Issabel Framework builds before commit b97dbaf0b71c1c36f841e672b664afbeb02773bd. ([vulncheck.com](https://www.vulncheck.com/advisories/issabel-pbx-hard-coded-jwt-key-rce-via-pbxapi-manager-originate))

Fix: Patch commit b97dbaf. ([secalerts.co](https://secalerts.co/vulnerability/CVE-2026-89026))

Panel assessment: Patch now where Issabel Framework is in use and network-reachable: exploitation is already observed in the wild, the attack is unauthenticated, and success gives arbitrary OS command execution on the PBX host. The likely path is abuse of the hard-coded key to reach pbxapi/manager/originate, turning a telephony management endpoint into host-level command execution with whatever credentials, configuration, logs, call-related data, or adjacent access that host can reach. (priority: patch now)

Action: Map CVE-2026-89026 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation reported by the source, not independently corroborated

[Evidence source: thehackernews.com](https://thehackernews.com/2026/09/attackers-exploit-issabel-framework.html)

Finding 03 — Enterprises Warned of Attacks Exploiting WSO2 Vulnerability

What changed: A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic signature that could result in account takeover.

Technical evidence: CVE-2026-5430; CVSS v3.1 10; weakness CWE-347; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Restrict network access to affected management and gateway interfaces. ([ionix.io](https://www.ionix.io/threat-center/cve-2026-5430/), [securityweek.com](https://www.securityweek.com/enterprises-warned-of-attacks-exploiting-wso2-vulnerability/), [security.docs.wso2.com](https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5328/))

Affected: WSO2 lists these affected product streams: API Control Plane 4.5.0 and 4.6.0; API Manager 4.1.0 through 4.6.0; Traffic Manager 4.5.0 and 4.6.0; Universal Gateway 4.5.0 and 4.6.0. ([security.docs.wso2.com](https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5328/))

Fix: WSO2 support update levels, shown as version/update level: API Control Plane 4.6.0/22 and 4.5.0/58; API Manager 4.6.0/21, 4.5.0/57, 4.4.0/72, 4.3.0/108, 4.2.0/197 and 4.1.0/257; Traffic Manager 4.6.0/ ([security.docs.wso2.com](https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5328/))

Action: Map CVE-2026-5430 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: securityweek.com](https://www.securityweek.com/enterprises-warned-of-attacks-exploiting-wso2-vulnerability/)

Finding 04 — Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026

What changed: CVE coverage: CVE-2026-20329, CVE-2026-20330, CVE-2026-20331, CVE-2026-20332, CVE-2026-20333, CVE-2026-20334, CVE-2026-20335, CVE-2026-20336, CVE-2026-20242, CVE-2026-20130, CVE-2026-20192, CVE-2026-20194, CVE-2026-20234, CVE-2026-20237, CVE-2026-20287, CVE-2026-20322, CVE-2026-20325, CVE-2026-20326, CVE-2026-20360, CVE-2026-20361, CVE-2026-76409, CVE-2026-20340, CVE-2026-20341, CVE-2026-20342, CVE-2026-20343, CVE-2026-20344, CVE-2026-76412, CVE-2026-76413, CVE-2026-76420, CVE-2024-20260, CVE-2026-20250, CVE-2026-20248, CVE-2026-20120, CVE-2026-20121, CVE-2026-20222, CVE-2026-20154, CVE-2026-20249, CVE-2026-20295, CVE-2026-20323, CVE-2026-20135, CVE-2026-20290. As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software and Cisco Secure Firewall Management Center (FMC) Software engineering team has conducted a comprehensive internal security review.

Technical evidence: CVE-2026-20329; CVSS v3.1 9.9; weakness CWE-703; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Analyst note: For the two actively exploited FMC issues linked by this hardening advisory, restrict public internet access to the FMC management interface; Cisco says this reduces the attack surface. In expert mode, run zgrep "package_info.license" /var/log/messages; output containing /var/tmp/license.tmp may indicate exploitation, and Cisco directs suspected cases to TAC. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-asaftdfmc-uvpPROhN), [sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh), [sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2))

Affected: Cisco Secure Firewall ASA releases 9.16 and earlier, 9.18, 9.20, 9.22, 9.23 and 9.24; Secure FTD and FMC releases 7.0 and earlier, 7.2, 7.4, 7.6, 7.7, 10.0 and 10.1. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-asaftdfmc-uvpPROhN))

Fix: ASA: 9.16.4.103, 9.18.4.94, 9.20.4.49, 9.22.3.26, 9.23.1.47 and 9.24.1.26. FTD/FMC: 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2 and 10.1.0. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-asaftdfmc-uvpPROhN))

Action: Map CVE-2026-20329 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-asaftdfmc-uvpPROhN?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Adaptive%20Security%20Appliance)

Finding 05 — @zereight/mcp-gitlab: Unauthenticated arbitrary file read via 'upload_markdown' enables PAT exfiltration and full account takeover

What changed: @zereight/mcp-gitlab: Unauthenticated arbitrary file read via upload_markdown enables PAT exfiltration and full account takeover The cited source identifies the affected product and the available advisory or remediation status. CVE coverage: CVE-2026-61560.

Technical evidence: CVE-2026-61560; CVSS v3.1 9.8; weakness CWE-22; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Bind the service to 127.0.0.1 or place it behind an authenticating reverse proxy; do not expose port 3002 on a routable interface. Monitor for unexpected tool calls, sensitive-path uploads and unrecognised outbound hosts. ([github.com](https://github.com/zereight/gitlab-mcp/security/advisories/GHSA-cv3r-c5h8-f4g5), [pluto.security](https://pluto.security/blog/two-critical-vulnerabilities-gitlab-mcp-account-takeover/))

Affected: @zereight/mcp-gitlab versions earlier than 2.1.27 when deployed with SSE transport enabled. ([github.com](https://github.com/zereight/gitlab-mcp/security/advisories/GHSA-cv3r-c5h8-f4g5))

Fix: 2.1.27 ([github.com](https://github.com/zereight/gitlab-mcp/security/advisories/GHSA-cv3r-c5h8-f4g5))

Action: Map CVE-2026-61560 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: github.com](https://github.com/advisories/GHSA-cv3r-c5h8-f4g5)

Finding 06 — LMdeploy: Deserialization of Untrusted Data

What changed: LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy The cited source identifies the affected product and the available advisory or remediation status. CVE coverage: CVE-2025-59953.

Technical evidence: CVE-2025-59953; CVSS v3.1 9.8; weakness CWE-502; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Block untrusted network access to LMDeploy's randomly selected ZMQ RPC port and segment the service from untrusted peers. Enable RPC authentication so only authenticated, trusted users can join the cluster. ([github.com](https://github.com/advisories/GHSA-5h8j-6crg-7rmw))

Affected: >= 0.9.1, < 0.10.2 ([github.com](https://github.com/advisories/GHSA-5h8j-6crg-7rmw))

Fix: 0.10.2 ([github.com](https://github.com/advisories/GHSA-5h8j-6crg-7rmw))

Action: Map CVE-2025-59953 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: github.com](https://github.com/advisories/GHSA-5h8j-6crg-7rmw)

Finding 07 — Multiple vulnerabilities in djust

What changed: djust carries 10 CVEs across 5 advisories: Cross-Site Request Forgery on the Server-Sent-Events transport; Multi-tenant isolation fails open on the WebSocket/SSE path; Broken object-level access control (IDOR); Vulnerable to stored/reflected XSS via javascript: URLs in built-in com; mount path; view-mount path. CVE coverage: CVE-2026-61594, CVE-2026-61599, CVE-2026-61593, CVE-2026-61595, CVE-2026-61598, CVE-2026-61591, CVE-2026-61592, CVE-2026-61589, CVE-2026-61596, CVE-2026-61597.

Technical evidence: CVE-2026-61594; CVSS v3.1 9.1; weakness CWE-306, CWE-862; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Analyst note: Gate views with djust's login_required, permission_required or check_permissions attributes rather than HTTP-only mixins or decorators. Set LIVEVIEW_ALLOWED_MODULES to the narrow list of modules containing mountable LiveView classes. ([github.com](https://github.com/advisories/GHSA-xhhm-f6hp-2qwj), [github.com](https://github.com/advisories/GHSA-7prp-2623-8g45))

Affected: djust versions earlier than 1.0.7 ([github.com](https://github.com/advisories/GHSA-xhhm-f6hp-2qwj), [github.com](https://github.com/advisories/GHSA-7prp-2623-8g45))

Fix: djust 1.0.7 ([github.com](https://github.com/advisories/GHSA-xhhm-f6hp-2qwj), [github.com](https://github.com/advisories/GHSA-7prp-2623-8g45))

Action: Map CVE-2026-61594 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: github.com](https://github.com/advisories/GHSA-xhhm-f6hp-2qwj)

Finding 08 — Google Pixel Improper Authorization Vulnerability

What changed: Google Pixel Improper Authorization Vulnerability. The cited source identifies the affected product and the available advisory or remediation status.

Technical evidence: CVE-2026-58704; CVSS v3.1 8.8; weakness CWE-693, CWE-285; technical confidence High.

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: Observed in-the-wild exploitation is confirmed.

Analyst note: Until patched, use airplane mode as a short-term measure; disable unused Bluetooth and Wi-Fi Direct interfaces in high-sensitivity environments. Google reports indications that CVE-2026-58704 may be under limited, targeted exploitation. ([source.android.com](https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01), [threataft.com](https://threataft.com/articles/google-pixel-cve-2026-58704-cellular-modem-privilege-escalation))

Affected: All supported Pixel devices from the Pixel 6 series through the Pixel 11 family, plus Pixel Tablet and Pixel Fold, with security patch levels before 2026-09-05. ([threataft.com](https://threataft.com/articles/google-pixel-cve-2026-58704-cellular-modem-privilege-escalation))

Fix: Security patch level 2026-09-05 or later. ([source.android.com](https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01))

Action: Map CVE-2026-58704 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: cisa.gov](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?vulnId=CVE-2026-58704)

Finding 09 — Windows Secure Kernel Mode Elevation of Privilege Vulnerability

What changed: Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. The cited source identifies the affected product and the available advisory or remediation status.

Technical evidence: CVE-2026-85921; CVSS v3.1 8.2; weakness CWE-415; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Microsoft reports that it was neither publicly disclosed nor exploited at original publication. ([msrc.microsoft.com](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85921), [cve.org](https://www.cve.org/CVERecord?id=CVE-2026-85921), [support.microsoft.com](https://support.microsoft.com/en-us/servicing/os/windows-11/2026/09/kb5129194-windows-11-26h1-security-update))

Affected: Windows 11 version 26H1 for x64- and ARM64-based systems, from build 10.0.28000.0 up to but excluding 10.0.28000.2956. ([cve.org](https://www.cve.org/CVERecord?id=CVE-2026-85921), [msrc.microsoft.com](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85921))

Panel assessment: Patch this week: exploitation requires authorised local access and Microsoft reports no public disclosure or exploitation, but a Secure Kernel Mode privilege escalation has high host-level blast radius once an attacker already has a foothold. The likely path is local code execution by an authorised user triggering the double free to gain higher privileges, putting host credentials, security controls and local data at risk. (priority: this week)

Action: Map CVE-2026-85921 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: msrc.microsoft.com](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85921)

Finding 10 — Multiple vulnerabilities in Chromium

What changed: Chromium fixes 5 CVEs in one release: Buffer overflow in WebRTC; Missing authorization in Extensions; Incomplete cleanup in Browser; Incorrect authorization in Navigation; Confused deputy in Prerender. CVE coverage: CVE-2026-87430, CVE-2026-87431, CVE-2026-87436, CVE-2026-87432, CVE-2026-87442.

Technical evidence: CVE-2026-87430; CVSS v3.1 8.8; weakness CWE-122; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-87430 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: chromereleases.googleblog.com](https://chromereleases.googleblog.com/2026)

Finding 11 — OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS

What changed: OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS The cited source identifies the affected product and the available advisory or remediation status. CVE coverage: CVE-2026-81192.

Technical evidence: CVE-2026-81192; CVSS v3.1 7; weakness CWE-426; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Analyst note: On macOS, prevent less-privileged users from modifying the application’s PATH and remove user-writable directories that precede system directories. ([github.com](https://github.com/open-telemetry/opentelemetry-dotnet-contrib/security/advisories/GHSA-v8pv-4842-x354))

Affected: OpenTelemetry.Resources.Host versions earlier than 1.16.0-beta.2. ([github.com](https://github.com/open-telemetry/opentelemetry-dotnet-contrib/security/advisories/GHSA-v8pv-4842-x354))

Fix: OpenTelemetry.Resources.Host 1.16.0-beta.2. ([github.com](https://github.com/open-telemetry/opentelemetry-dotnet-contrib/security/advisories/GHSA-v8pv-4842-x354))

Action: Map CVE-2026-81192 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: github.com](https://github.com/advisories/GHSA-v8pv-4842-x354)

Finding 12 — Multiple vulnerabilities in Xpand IT Write-Back Manager

What changed: CVE coverage: CVE-2026-92205, CVE-2023-27170. The cited advisories disclose: Arbitrary File Creation Vulnerability; via modification of the siteName parameter.

Technical evidence: CVE-2023-27170; CVSS v3.1 7.5; weakness CWE-22; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: For BusyBox, restrict interaction with the product and prevent users from opening untrusted files. For Write-Back Manager, restrict access to its file-upload features to trusted users. CISA's ADP Vulnrichment assesses CVE-2023-27170 exploitation as PoC. ([zerodayinitiative.com](https://www.zerodayinitiative.com/advisories/ZDI-26-705/), [balwurk.com](https://balwurk.com/cve-2023-27170-improper-limitation-of-a-pathname-to-a-restricted-directory/), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2023-27170))

Affected: CVE-2023-27170: Xpand IT Write-Back Manager v2.3.1. ([balwurk.com](https://balwurk.com/cve-2023-27170-improper-limitation-of-a-pathname-to-a-restricted-directory/))

Fix: CVE-2023-27170: Write-Back 4.1 or later. ([balwurk.com](https://balwurk.com/cve-2023-27170-improper-limitation-of-a-pathname-to-a-restricted-directory/))

Action: Map CVE-2023-27170 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: zerodayinitiative.com](http://www.zerodayinitiative.com/advisories/ZDI-26-705/)

Finding 13 — GitPython: Improper Neutralization of Special Elements in Output

What changed: GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config via create_submodule or clone_from operations, achieving remote code execution when git performs ssh operations.

Technical evidence: CVE-2026-69097; CVSS v4.0 7.3; weakness CWE-74; technical confidence Medium.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Analyst note: Until patched, avoid cloning or creating submodules from untrusted Git repositories. ([access.redhat.com](https://access.redhat.com/security/cve/cve-2026-69097), [vulnerability.circl.lu](https://vulnerability.circl.lu/vuln/cve-2026-69097), [github.com](https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3rp5-jjmw-4wv2))

Affected: GitPython versions up to and including 3.1.52. ([github.com](https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3rp5-jjmw-4wv2))

Fix: GitPython 3.1.53 and later. ([github.com](https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3rp5-jjmw-4wv2))

Action: Map CVE-2026-69097 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-69097)

Finding 14 — Cisco ThousandEyes Virtual Appliance Authenticated Web Interface Command Injection Vulnerability

What changed: A vulnerability in the web-based management interface of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to inject arbitrary operating system commands. This vulnerability is due to improper validation of user-supplied input to the web-based management interface.

Technical evidence: CVE-2026-20350; CVSS v3.1 4.7; weakness CWE-78; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Analyst note: Disable the Virtual Appliance web interface and manage it through SSH; Cisco documents running sudo te-va-disable-webserver from the appliance CLI. Cisco PSIRT reports that it is not aware of any public announcements or malicious use of this vulnerability. ([docs.thousandeyes.com](https://docs.thousandeyes.com/product-documentation/global-vantage-points/enterprise-agents/configuring/disabling-the-web-server-of-a-virtual-appliance), [sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-teva-os-command-W4GAO6jp))

Affected: Cisco ThousandEyes Virtual Appliance releases earlier than 0.265. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-teva-os-command-W4GAO6jp))

Fix: 0.265.0. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-teva-os-command-W4GAO6jp))

Action: Map CVE-2026-20350 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-teva-os-command-W4GAO6jp?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20ThousandEyes%20Virtual%20Appliance%20Authenticated%20Web%20Interface%20Command%20Injection%20Vulnerability%26vs_k=1)

Finding 15 — Cisco BroadWorks CommPilot Application Software Authorization Bypass Vulnerability

What changed: A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker with low privileges to alter configurations on an affected device. This vulnerability is due to missing authorization checks.

Technical evidence: CVE-2026-76438; CVSS v3.1 6.5; weakness CWE-863; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Analyst note: Cisco PSIRT reports no known public announcements or malicious use. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-auth-bypass-broadwor-57m9dmm5/csaf/cisco-sa-auth-bypass-broadwor-57m9dmm5.json))

Affected: CommPilot Application Software: 23.0, 24.0 before 24.0.2026.07, 25.0, 26.0, and 27.0 before 27.0.2026.08. BroadWorks Application Server: 24.0 before patch AP.as.24.0.944.ap385770, and releases earlier ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-auth-bypass-broadwor-57m9dmm5/csaf/cisco-sa-auth-bypass-broadwor-57m9dmm5.json))

Fix: CommPilot Application Software: 24.0.2026.07 for release 24.0 and 27.0.2026.08 for release 27.0; releases 23.0, 25.0 and 26.0 must migrate. BroadWorks Application Server: patch AP.as.24.0.944.ap385770 ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-auth-bypass-broadwor-57m9dmm5/csaf/cisco-sa-auth-bypass-broadwor-57m9dmm5.json))

Action: Map CVE-2026-76438 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-auth-bypass-broadwor-57m9dmm5?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20BroadWorks%20CommPilot%20Application%20Software%20Authorization%20Bypass%20Vulnerability%26vs_k=1)

cve-2025-59953cve-2026-20176cve-2026-20211cve-2026-20282cve-2026-20283cve-2026-20284cve-2026-20307cve-2026-20329cve-2026-20350cve-2026-5430

Act on this brief

Map detection coverage gaps for the techniques above, or generate Sigma rules from the named CVEs.