CERT-FR flags actively exploited Cisco ISE, Apple flaws
CERT-FR's weekly bulletin lists critical, actively-exploited vulnerabilities in Cisco ISE, Apple macOS, Cisco Secure Email Gateway and others requiring urgent patching.
CERT-FR's weekly vulnerability digest (week 38, 14-20 Sept 2026) highlights the most significant flaws disclosed across major vendors including Cisco, Apple, Oracle, HPE Aruba, IBM, Check Point, Google, Microsoft, SUSE, Ubuntu, Debian, Acronis and Proxmox. Several are confirmed as actively exploited in the wild: a maximum-severity (CVSS 10) security policy bypass in Cisco Identity Services Engine (CVE-2026-76460), a critical Apple macOS security bypass (CVE-2026-65400), a critical SQL injection in Cisco Secure Email Gateway (CVE-2026-76461), an Ubuntu kernel-related flaw (CVE-2026-53266), a Microsoft Edge RCE (CVE-2026-87491), a Google Pixel privilege escalation (CVE-2026-58704), a SUSE security bypass (CVE-2025-39964), a Debian Linux flaw (CVE-2025-39682) and an Acronis Backup privilege escalation (CVE-2026-87886) both listed in CISA's KEV catalog, and a Proxmox VE security bypass (CVE-2023-54391).
Beyond the confirmed-exploited set, the bulletin catalogs a large number of additional critical (CVSS 9.1-10) vulnerabilities without confirmed in-the-wild exploitation, notably a dense cluster of flaws in Cisco Identity Services Engine, Nexus Dashboard, Secure Firewall/FMC/ASA, HPE Aruba EdgeConnect SD-WAN gateways, Oracle WebLogic, IBM WebSphere/Sterling, Check Point log/management servers, Apple's OS family (macOS, iOS, watchOS, tvOS, iPadOS, visionOS), and Google Chrome/Microsoft Edge. Many of these affect network perimeter and identity infrastructure (ISE, firewalls, SD-WAN gateways) that are high-value targets for lateral movement and persistent access if left unpatched.
Defenders should prioritize patching internet-facing and identity/network management products first — particularly Cisco ISE, Secure Firewall/FMC, and HPE Aruba EdgeConnect gateways given the volume and severity of flaws — and apply the confirmed-exploited fixes (Cisco ISE, Apple macOS, Cisco ESA, Ubuntu, Edge, Pixel, SUSE, Debian, Acronis, Proxmox) immediately per vendor advisories. This is a routine aggregation bulletin rather than a single incident report; full advisory numbers (CERTFR-2026-AVI-xxxx) and vendor links are provided for remediation guidance.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/actualite/CERTFR-2026-ACT-040
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free