“Inventory all Cisco ISE instances in your environment and apply available patches or isolate them behind additional authentication layers—do this today, not this week.”
CVE-2026-81963: Windows Update Stack Zero-Day Exploited in the Wild — SYSTEM Privileges via Link-Following
CVE-2026-81963 is an actively exploited elevation-of-privilege zero-day in the Windows Update Stack (CVSS 7.8) affecting every supported Windows client and server. A local low-privileged attacker can exploit improper link resolution to reach SYSTEM privileges with no user interaction required, making it a prime post-compromise escalation primitive. Workaround: No known workaround; patch immediately via September 2026 Patch Tuesday.
Read more →Cisco Identity Services Engine Auth Bypass Actively Exploited (CVE-2026-76460) — CISA KEV Listed
Cisco disclosed and CISA catalogued CVE-2026-76460, a critical authentication bypass in Cisco Identity Services Engine (ISE) allowing unauthenticated remote attackers to bypass authentication. Cisco confirmed active exploitation. Patch immediately via Cisco's security updates; as an interim measure, restrict ISE management access to dedicated admin networks only.
Read more →Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.