VYPR
AI Brief2026-09-19· generated Sep 18, 2026

What you need to know today.

Critical vulnerabilities in Microsoft Azure, Cisco ISE, and Apple products allow privilege escalation and authentication bypass, with several actively exploited.

Multiple critical vulnerabilities in Microsoft products, including Azure AI Foundry, Azure Logic Apps, and Microsoft Fabric, allow for privilege escalation and authentication bypass. CVE-2026-85889, a critical flaw in Azure AI Foundry, enables unauthorized attackers to elevate privileges over a network due to missing authentication for a critical function. Similarly, CVE-2026-70200 in Azure Logic Apps involves a path traversal vulnerability, while CVE-2026-69843 in Microsoft Fabric allows authentication bypass by spoofing. These issues, all rated CVSS 10.0, pose a significant risk to organizations utilizing these Microsoft services. As reported by The Hacker News, Microsoft has released patches to address these critical vulnerabilities.

Cisco is addressing two critical vulnerabilities in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). CVE-2026-20192 and CVE-2026-20130 are described as authentication bypass vulnerabilities that could allow an attacker to gain unauthorized access. The severity of these flaws is underscored by The Hacker News reporting that they are being exploited in active attacks, with Cisco warning of a new zero-day ISE auth bypass. Organizations using Cisco ISE should prioritize applying the available security updates to mitigate the risk of exploitation.

Apple has released security updates for its operating systems, including macOS Golden Gate, Sequoia, and Tahoe, to address a validation issue in entitlement verification. CVE-2026-65381, a critical vulnerability, could allow a malicious app to gain elevated privileges. While the specific impact is not fully detailed, Apple has addressed this with improved validation. As noted by Vypr Intelligence and the SANS Internet Storm Center, these updates are part of a broader patch release for Apple products.

Several WordPress plugins and themes are affected by critical vulnerabilities. CVE-2026-62104, an unauthenticated Remote Code Execution (RCE) vulnerability in Migratico Lite versions up to 2.6.8, allows attackers to execute arbitrary code. Additionally, unauthenticated broken authentication vulnerabilities were found in Headless Single Sign On (CVE-2026-62108) and EduAdmin Booking (CVE-2026-62101). The Multi Uploader for Gravity Forms plugin is also vulnerable to Arbitrary File Upload via CVE-2026-87796 due to insufficient file type validation. Users of these plugins should update immediately to secure their WordPress sites.

A critical Server-Side Request Forgery (SSRF) vulnerability, CVE-2025-56563, has been identified in Zenith Satellite Tracker 1.0. The vulnerability in the sat_proxy.php script allows unauthenticated attackers to make the application forward requests to arbitrary external resources by manipulating the url parameter without proper validation. This could lead to various attacks, including accessing internal network resources or interacting with external services on behalf of the server. Users of Zenith Satellite Tracker should seek updated versions or apply mitigations to prevent exploitation.

Apache Artemis and ActiveMQ Artemis are affected by CVE-2026-27446, a critical vulnerability allowing unauthenticated remote attackers to establish outbound federation connections. This missing authentication for a critical function could be exploited to compromise broker security. As highlighted by CISA ICS Advisories, this impacts industrial control systems, emphasizing the need for prompt patching.

GitHub's SiYuan product has a critical missing authorization vulnerability in its POST /mcp kernel endpoint, identified as CVE-2026-66012. Versions prior to v3.7.2 lack proper admin-role or read-only enforcement, allowing general authentication checks to be bypassed. This exposes 31 MCP tools to unauthorized access and potential misuse by attackers. Users should update to SiYuan v3.7.2 or later to remediate this risk.

Flowiseai versions up to 2.2.7 contain a critical path traversal vulnerability, CVE-2025-71338, in its document-store loader endpoint. Attackers can exploit this by using parent-directory sequences to write files outside the intended storage directory, bypassing the security controls. This could lead to unauthorized file modifications or system compromise. Applying updates to Flowiseai is crucial to prevent exploitation.

Synthesized by Vypr AI