Daily Security Intel

Archives
Log in
Subscribe
September 18, 2026

[SecurityIntel] 18 Sep | Active Zero-Day Exploit in Cisco ISE (CVE-2026-76460)

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Friday, September 18, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Active Zero-Day Exploit in Cisco ISE (CVE-2026-76460)

CRITICAL

5

C2 IPs

80

OTX IOCs

40

ARTICLES

■ ANALYST TLDR

Today's threat landscape is dominated by a critical, actively exploited zero-day vulnerability (CVE-2026-76460) in Cisco Identity Services Engine (ISE) and a critical heap overflow in NLnet Labs Unbound DNS resolvers. Additionally, supply-chain attacks are escalating, as seen in the Brevo compromise where stolen Cloudflare API keys were used to inject malicious ClickFix scripts. On the espionage front, China-aligned threat actor FamousSparrow is actively targeting Latin American governments using a new backdoor called SparroWocky.

■ CRITICAL STORIES

CRITICAL#1

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Cisco has warned of a maximum-severity auth bypass vulnerability (CVE-2026-76460) in its Identity Services Engine (ISE) that is being actively exploited in the wild, allowing unauthenticated remote attackers to gain root-level access.

CRITICAL#2

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

Every release of NLnet Labs Unbound before 1.26.1 contains a critical heap overflow in its DNSSEC validator, allowing remote attackers controlling a malicious zone to achieve remote code execution (RCE).

HIGH#3

Brevo supply-chain attack injected ClickFix scripts on customer sites

Attackers stole a Cloudflare API key from Brevo to inject malicious ClickFix scripts into customer-facing JavaScript files, distributing malware via a trusted email marketing platform.

HIGH#4

China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America

The state-sponsored group FamousSparrow has been targeting Latin American government entities since at least August 2025 using a newly discovered backdoor named SparroWocky to conduct espionage.

■ CVEs IDENTIFIED

CVE-2026-76460

Cisco Identity Services Engine (ISE) — Authentication bypass exploited in active attacks, allowing unauthenticated remote attackers to gain unauthorized access.

Critical (10.0)

[CVE-TBD] (NLnet Labs Unbound)

NLnet Labs Unbound — Heap overflow in DNSSEC validator prior to version 1.26.1, allowing remote code execution (RCE) via a malicious DNS zone.

Critical

[CVE-TBD] (ISC BIND 9)

ISC BIND 9 — 14 vulnerabilities, including an unauthenticated crash over DNS-over-HTTPS (DoH) and resource exhaustion.

High/Critical

[CVE-TBD] (Cisco FMC/Nexus)

Cisco Firepower Management Center & Nexus Dashboard — Flaws leading to root access, command execution, bypasses, SQL injection, and remote code execution.

High/Critical

■ THREAT ACTORS

FamousSparrow

APT

China-aligned state-sponsored threat actor deploying the "SparroWocky" backdoor to target government organizations in Latin America.

BlackCore

Private Contractor

Israeli influence-for-hire company training Angolan officials in online influence operations and fake persona creation.

NightmareStresser Operators

Cybercriminals

Operators of the NightmareStresser DDoS-for-hire platform seized by the FBI.

■ ATT&CK TTPs

T1195.002
Supply Chain Compromise: Compromise of Software Dependencies and Environments | Injected ClickFix scripts on Brevo customer sites.
T1566.001
Phishing: Spearphishing Attachment | LausivLoader distributed via malspam message.
T1566.002
Phishing: Spearphishing Link | Phishing texts targeting Revolut and T-Mobile customers.
T1219
Remote Access Software | RatHat Android malware utilizing AI to automate device control.
T1110.002
Password Cracking | Gyazo breach exposing password hashes.
T1078
Valid Accounts | Abuse of stolen Cloudflare API key in Brevo supply-chain attack.

■ PATCH PRIORITY

[P3 PATCH NOW]≤1 week

CRITICAL — Cisco Identity Services Engine (ISE) — Actively exploited CVSS 10.0 auth bypass (CVE-2026-76460) — THN

[P3 PATCH NOW]≤1 week

CRITICAL — NLnet Labs Unbound — Heap overflow in DNSSEC validator allowing RCE — THN

[P3 PATCH NOW]≤1 week

HIGH — ISC BIND 9 — 14 vulnerabilities including unauthenticated crash over DoH — THN

[P3 PATCH NOW]≤1 week

HIGH — Cisco Firepower Management Center (FMC) & Nexus Dashboard — Multiple flaws leading to root access/RCE — SW

■ RECOMMENDED ACTIONS TODAY

1[P1] Immediately patch Cisco Identity Services Engine (ISE) to address the actively exploited CVE-2026-76460 authentication bypass vulnerability.
2[P1] Upgrade NLnet Labs Unbound DNS resolvers to version 1.26.1 or later to mitigate the critical DNSSEC validator heap overflow RCE flaw.
3[P1] Apply BIND 9 security updates (9.20.29 / 9.21.26) to remediate 14 vulnerabilities, including the unauthenticated DoH crash.
4[P2] Audit and rotate all Cloudflare API keys and third-party integrations for Brevo to ensure malicious ClickFix scripts are completely purged.
5[P2] Deploy the Microsoft-provided temporary workaround for Windows 11 domain login issues resulting from the September 2026 security updates.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 19 Sep | Critical Orkes Conductor RCE Vulnerability Actively Exploited Older → [SecurityIntel] 17 Sep | First Agentic AI Data Breach Reported in Spain
Powered by Buttondown, the easiest way to start and grow your newsletter.