VYPR
AI Brief2026-09-26· generated Sep 26, 2026

What you need to know today.

CISA flags actively exploited Cisco ISE and WSO2 flaws, while numerous critical RCE and privilege escalation vulnerabilities impact IBM, GitLab, Lantronix, and Microsoft Azure.

Cisco Identity Services Engine (ISE) is facing a critical authentication bypass vulnerability, CVE-2026-76460, which allows unauthenticated remote attackers to gain access. This flaw, due to insufficient authentication controls on an API endpoint, has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. Cisco has released patches to address this issue, urging customers to update their systems promptly. As CyberScoop reported, this is the second zero-day in as many days for Cisco, highlighting ongoing API security concerns.

A critical vulnerability in WSO2's JWT authentication mechanism, CVE-2026-5430, allows attackers to forge tokens using unsupported algorithms, leading to authentication bypass and potential system compromise. This flaw has also been added to the CISA KEV catalog due to active exploitation, as noted by The Hacker News. Enterprises using WSO2 products are advised to apply the available security updates immediately to mitigate the risk of unauthorized access.

Multiple critical vulnerabilities have been disclosed in IBM Concert versions 1.0.0 through 3.0.0, including memory corruption, buffer overflows, and unauthenticated command execution. CVE-2026-6928, CVE-2026-6730, and CVE-2026-6721 are among the flaws that could allow attackers to crash applications or execute arbitrary code. Vypr Intelligence reported on these 15 disclosed vulnerabilities, emphasizing the severe risk to systems running unpatched versions.

GitLab has released critical patches for versions 19.2, 19.3, and 19.4 to address multiple vulnerabilities, including two critical remote code execution (RCE) flaws. CVE-2026-89078 and CVE-2026-93577 allow authenticated users to execute arbitrary code under certain conditions, as detailed in Cyber Security News. Users are urged to update to the latest versions, 19.2.7, 19.3.3, or 19.4.1, to protect against these threats.

Lantronix devices, including SLC8000, SLC9000, EMG8500/EMG7500, and others, are affected by several critical vulnerabilities. CVE-2026-80155 presents an authentication bypass in the web management interface, while CVE-2026-80144 and CVE-2026-80143 allow authenticated attackers to execute arbitrary commands. Firmware updates are available for most affected models, and users should apply them to secure their devices.

Critical vulnerabilities have been identified in Microsoft Azure AI Foundry, with CVE-2026-85889 allowing unauthorized privilege escalation over a network. The Hacker News highlighted this CVSS 10.0 flaw, noting its potential for significant impact. Microsoft has released patches, and users of Azure AI Foundry are strongly advised to update their systems.

Wgetnz HFS2 versions prior to 2.4.0 contain critical vulnerabilities, including CVE-2026-97360 for arbitrary file access and CVE-2026-97359 for remote code execution via template injection in the multipart upload handler. These flaws allow unauthenticated attackers to read, write, or delete files, and potentially execute arbitrary code, posing a severe risk to affected systems.

Cisco ISE and Cisco ISE-PIC are also impacted by CVE-2026-20147, a vulnerability that allows authenticated remote attackers to execute arbitrary commands on the underlying operating system. This requires the attacker to have valid user credentials, making it a significant threat for systems with compromised accounts. The Zero Day Initiative provides further details on this command injection vulnerability.

Critical vulnerabilities have been disclosed in MindsDB Minds Platform version 26.1.0 and earlier, specifically CVE-2026-73678, which allows unauthenticated remote code execution by submitting crafted prompts to the unprotected POST / endpoint. This RCE vulnerability poses a significant risk, and users should update to a patched version.

WordPress plugin "Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code" versions up to 4.8.6 are affected by CVE-2026-14281, a privilege escalation vulnerability due to missing permission enforcement. This allows lower-privileged users to gain elevated access, potentially leading to system compromise.

Honeywell PD45 Industrial Printer, firmware version F10.19.010040, contains CVE-2026-13249, an unauthenticated arbitrary file upload vulnerability in its web management interface. This allows attackers to upload malicious files without authentication, potentially leading to remote code execution.

Delta Electronics DIAEnergie versions before 1.11.00.022 suffer from CVE-2026-78308, an improper authentication vulnerability that allows authentication bypass, enabling unauthorized access to the system.

Gigatech PDV5701 1.0.31_240305_112640 has a vulnerability, CVE-2026-94493, in its WebSocket Service component that results in missing authentication for the /index.html file, allowing unauthenticated access.

Moodle Socialwall plugin versions v.3.0 through v.3.3 are vulnerable to CVE-2025-63564, a SQL injection flaw that allows attackers to execute arbitrary code via crafted HTTP requests.

Synthesized by Vypr AI
Cisco, WSO2 Flaws Exploited; Critical RCEs Hit IBM, GitLab, Azure · VYPR