Friday, September 18, 2026
Daily digest
Two critical, actively-exploited vulnerabilities dominate today: a maximum-severity (CVSS 10) Cisco ISE authentication bypass and an unauthenticated root RCE in Check Point management servers. Both warrant emergency patching if these products are in your environment.
Cisco drops another exploited zero-day, this time a perfect 10
Cisco disclosed an actively exploited authentication bypass vulnerability in Identity Services Engine (ISE) rated CVSS 10.0. This is the second Cisco zero-day disclosed in recent days that has sent administrators scrambling to patch.
Why it matters: ISE is widely deployed for network access control in defense and government networks; an unauthenticated bypass under active exploitation demands emergency patching and falls squarely under CMMC L2 vulnerability remediation timelines.
Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
Check Point patched a critical vulnerability in its Security Management and Log Servers that allows an unauthenticated attacker to execute code as root over the network. The fix is delivered through Check Point's LivePatch update channel, and the company says it has no evidence of active exploitation yet.
Why it matters: The Security Management Server controls firewall policy and admin access — if Check Point is in your stack, apply the LivePatch immediately given the severity and network-reachable attack surface.
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
NLnet Labs disclosed a critical heap overflow (CVE-2026-81642) in the Unbound DNS resolver's DNSSEC validator, affecting every release prior to 1.26.1. An attacker controlling a malicious DNS zone can trigger remote code execution against a vulnerable resolver simply by having it queried.
Why it matters: If Unbound is used anywhere in your DNS infrastructure (common in Linux-based, Ansible-managed environments), upgrade to 1.26.1 immediately — this is remotely triggerable via normal DNS resolution.
Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files
Docker disclosed CVE-2026-77179, a critical flaw in Docker Sandboxes on macOS that lets malicious code inside a sandboxed VM escape its project directory and read or modify arbitrary files on the host, running with the host account's privileges. Docker published a fix in a September 15 security announcement.
Why it matters: If developers run Docker Sandboxes on macOS endpoints, this breaks the container isolation boundary and could expose data on Intune-managed devices — patch and verify no macOS dev machines are exposed.
Brevo supply-chain attack injected ClickFix scripts on customer sites
Brevo (formerly Sendinblue) confirmed attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into Brevo's websites and JavaScript files embedded on customer sites, distributing malware to site visitors. The company has since revoked the compromised key.
Why it matters: Any org embedding Brevo's JavaScript on public-facing sites should audit for injected scripts — a good reminder to inventory third-party JS dependencies as part of supply-chain risk assessment under NIST 800-171.
China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America
ESET researchers attributed a new modular C++ backdoor called SparroWocky to the China-aligned FamousSparrow threat actor, targeting government and political organizations across Latin America since at least August 2025. The backdoor supports remote command execution and data exfiltration.
Microsoft patch gives domain-joined Windows PCs trust issues
A recent Microsoft security update introduced Machine Identity Isolation policies that can reject valid credentials on domain-joined Windows PCs unless domain controllers meet the Windows Server 2025 functional level. Affected organizations are reporting authentication failures following the patch.
Why it matters: Verify domain controller functional levels before this update rolls out to your Intune-managed Windows 11 fleet — organizations without Server 2025 DCs risk widespread authentication breakage.
Run open weight models on Amazon Bedrock in AWS European Sovereign Cloud
AWS announced general availability of open-weight generative AI models on Amazon Bedrock within the AWS European Sovereign Cloud, allowing organizations to run AI workloads while keeping data within the EU and meeting regional regulatory requirements.
AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom
Researchers disclosed "Plugin4Shell," a zero-click remote code execution flaw affecting the plugin architecture of all major AI coding agents. The vulnerability could allow attackers to gain full control over systems running these agents without any user interaction.
Why it matters: If any self-hosted AI stack uses coding agent plugins for automation or development workflows, audit plugin sources and update immediately — a zero-click RCE here could compromise your entire automation pipeline.
Microsoft fixes bug behind 'Defender Antivirus is turned off' alerts
Microsoft resolved a known issue causing Defender Antivirus to incorrectly show "turned off" alerts after installing recent Windows updates. The fix is now rolling out to affected systems.
Why it matters: If your Intune-managed fleet has been generating false Defender-disabled alerts, this confirms it's a known bug rather than a real compliance gap — update and stand down unnecessary incident response.
DHS sets fast-track schedule for network, cloud and cyber consolidation vehicle
The Department of Homeland Security is working on a compressed timeline to make awards for a new contract vehicle intended to centralize network, cloud, and cyber operations across headquarters and component agencies.
CISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus
CISA is discontinuing its weekly vulnerability summary bulletins in favor of a more targeted, risk-based approach to advisories, aligning with its broader guidance urging organizations to prioritize vulnerabilities that pose actual exploitation risk.
Why it matters: If your vulnerability management process (a required NIST 800-171 control) relies on CISA's weekly bulletin as an input, you'll need to adjust your patch-prioritization workflow to the new advisory cadence.