~/greenteam/nerd

Saturday, September 19, 2026

Daily digest

Two maximum-severity (CVSS 10.0) vulnerabilities dropped today — an authentication bypass in Cisco ISE and a privilege escalation flaw in Microsoft Azure AI Foundry — both warrant immediate patch verification given their prevalence in enterprise and government networks.

cybersec Dark Reading

Cisco ISE Zero-Day Scores Maximum 10.0 CVSS

Cisco disclosed CVE-2026-76460, an authentication bypass in Identity Services Engine (ISE) API endpoints, rated a perfect 10.0 on the CVSS scale. The flaw allows attackers to bypass authentication entirely and interact with protected API functions.

Why it matters: ISE is a common network access control backbone in federal and CMMC environments; an unauthenticated bypass at this severity should trigger emergency patching and a review of ISE-gated network segments.

cybersec The Hacker News

Microsoft Patches CVSS 10.0 Privilege Escalation in Azure AI Foundry

Microsoft fixed a maximum-severity flaw (CVE-2026-85889) in Azure AI Foundry caused by missing authentication on a critical function, allowing unauthorized network-based privilege escalation. Microsoft stated no customer action is required since the fix was applied service-side.

Why it matters: If any Azure AI Foundry workloads are integrated with your GCC High tenant or self-hosted AI pipeline, confirm the service-side fix applied and review Foundry access logs for anomalous privilege changes prior to the patch.

cybersec The Hacker News

SolarWinds Patches Hard-Coded Key RCE in Access Rights Manager

SolarWinds released updates fixing CVE-2026-28326, an 8.8 CVSS unauthenticated remote code execution flaw in Access Rights Manager caused by a hard-coded cryptographic key. The issue affects all ARM versions 2026.2 and earlier.

Why it matters: If ARM is used for AD/identity governance in your environment, this is an unauthenticated RCE path — patch immediately rather than waiting for the standard maintenance window.

cybersec The Hacker News

CISA Adds Three Actively Exploited Linux Kernel Flaws to KEV Catalog

CISA added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog, including CVE-2025-39682 (CVSS 9.8) in the TLS receive path, citing confirmed active exploitation. Federal agencies are required to remediate per binding operational directive timelines.

Why it matters: KEV entries carry mandatory remediation timelines for federal systems and are a direct input to CMMC/800-171 vulnerability management evidence — check kernel versions across any Linux-based Nutanix AHV components and container hosts.

cybersec The Hacker News

Working Exploits Public for Four Linux Kernel Local-Root Flaws

A researcher published functional exploit code for four Linux kernel vulnerabilities that allow local privilege escalation to root. All four have been patched by kernel maintainers over recent weeks, but unpatched systems are now exposed to public exploit code.

Why it matters: Verify kernel patch levels across all Linux VMs and container hosts on AHV — public exploit availability significantly raises the likelihood of opportunistic exploitation on any lagging systems.

cybersec BleepingComputer

Critical Check Point Flaw Allows Root Code Execution

Check Point Software released security updates for a critical vulnerability in its management systems that lets attackers execute code with root privileges. No exploitation in the wild has been reported yet, but a patch is available.

Why it matters: If Check Point manages perimeter security for your GovCloud connectivity or CUI boundary, prioritize this patch given the root-level impact on management infrastructure.

cybersec Dark Reading

MFA Alone Doesn't Stop OAuth Consent Abuse

A Dark Reading analysis details how attackers increasingly bypass MFA protections by abusing OAuth consent grants to gain persistent access to cloud accounts and data, without ever needing the victim's password or MFA token.

Why it matters: In M365 GCC High, review app consent policies and enable admin consent workflows — OAuth token abuse can persist even after password resets and MFA re-enrollment, undermining standard incident response assumptions.

cybersec The Hacker News

CrowdSec Confirms 170 Private GitHub Repos Copied After TanStack npm Supply-Chain Attack

CrowdSec disclosed that an attacker copied roughly 170 of its private GitHub repositories in May, using credentials stolen from a departed employee's laptop that had been compromised in the earlier TanStack npm supply-chain attack. The employee's GitHub access had not been revoked after departure.

Why it matters: A reminder to audit offboarding processes for immediate revocation of source-control and CI/CD access — a gap here directly maps to 800-171 access control requirements (AC.L2-3.1.2) and is a common CMMC assessment finding.

infrastructure BleepingComputer

Microsoft Teams Adding Admin Controls to Block Custom File Extensions

Microsoft is rolling out a Teams feature letting administrators customize the list of file extensions blocked from being shared, expanding beyond the default set associated with security threats.

Why it matters: Useful for tightening data loss prevention controls in M365 GCC High Teams tenants; consider adding this to file-type restriction policies alongside existing DLP rules.

cmmc FedScoop

TIGTA: IRS Cybersecurity Program Still Rated 'Not Effective'

A Treasury Inspector General for Tax Administration report found the IRS's cybersecurity program remains rated 'not effective' under FISMA metrics despite recent improvements in several control areas. The watchdog said gaps could leave taxpayer data exposed.

Why it matters: Illustrates that even mature federal agencies struggle to reach FISMA/NIST 'effective' ratings, useful context for benchmarking your own CMMC L2 assessment readiness against a real-world large-agency example.

cmmc Federal News Network

Commentary: New CI Fortify Network Isolation Guidance Creates Risks and Opportunities for Contractors

A Federal News Network commentary examines new guidance from CI Fortify on network isolation for critical infrastructure operators, arguing that the ability to meaningfully segment and isolate systems during an incident can be decisive for containment.

Why it matters: Network segmentation and isolation capability is a recurring theme in NIST 800-171/CMMC assessments (SC.L2-3.13.1); this guidance may inform how assessors evaluate isolation readiness for defense contractors.