The Exploit Bulletin — Friday, September 18, 2026: 4 issues require action
Friday, September 18, 2026 — 4 issues require action. If you run none of the software below, you are done.
Affects: Cisco Identity Services Engine · Cisco ISE Passive Identity Connector per the hardening · Cisco Secure Firewall · Brevo · Brevo forms script · Brevo Conversations widget script · Brevo SDK loader script · brevo.com pages · sendinblue.com pages · login.brevo.com / account.brevo.com / my.brevo.com · Claude Code, OpenAI Codex CLI, Google Gemini CLI, Microsoft · Claude Code
1. Unauthenticated improper access control in Cisco ISE and ISE-PIC (CVE-2026-20192)
AUTHENTICATION BYPASS · CRITICAL · CVSS 10.0
Cisco's 2026-09-16 hardening advisory states one of the grouped flaws is being exploited and the Canadian Centre for Cyber Security issued alert AL26-021 on 2026-09-17 confirming exploitation, so ISE 3.1 and 3.2 deployments left on affected patch levels remain exposed to an unauthenticated network attack.
CVE-2026-20192 groups improper access control (CWE-284) flaws in Cisco Identity Services Engine and ISE Passive Identity Connector fixed in Cisco's September 2026 hardening release. It is rated CVSS 10.0 with no authentication or user interaction required, allowing a remote attacker to bypass access controls on the appliance that governs network access for the whole organization.
Affected: Cisco Identity Services Engine 3.1.0 through 3.1.0 p6; Cisco Identity Services Engine 3.2.0 through 3.2.0 p2; Cisco ISE Passive Identity Connector (ISE-PIC) per the hardening advisory
How to Test: Check the ISE/ISE-PIC release and patch level in the admin portal or CLI: 3.1.0 with patches 1–6 and 3.2.0 with patches 1–2 are listed as affected. Review admin portal and API access logs and the ISE audit/operations reports for unexpected administrative sessions, new admin accounts, or configuration changes originating from unfamiliar source addresses; the Canadian Cyber Centre alert AL26-021 provides additional detection advice.
How to Patch: Apply Cisco's September 2026 ISE hardening release (advisory cisco-sa-hardening-ise-XU5EwX5T) to the 3.1 and 3.2 trains; Cisco states no workarounds are available, so if patching must wait, restrict network access to the ISE administrative interfaces to trusted management networks.
Evidence: Canadian Centre for Cyber Security AL26-021: Cisco has confirmed active exploitation · The Hacker News: Cisco warns of ISE auth bypass (CVSS 10.0) exploited in attacks
2. Crafted HTTP request to Remote Access SSL VPN reloads Cisco ASA/FTD firewalls (CVE-2026-20349)
CISA KEV (due 2026-08-14) · DENIAL OF SERVICE · HIGH · CVSS 8.6
Cisco revised the advisory on 2026-09-16 as part of its September 16 advisory bundle after Eclypsium reported attackers crashing Cisco firewalls with this flaw in August, so teams still running unpatched ASA/FTD with SSL VPN exposed can have their edge firewall rebooted at will by anyone on the internet.
Insufficient error checking when the Remote Access SSL VPN service on Cisco Secure Firewall ASA and FTD processes HTTP requests lets an unauthenticated remote attacker send a crafted request that forces the device to reload. Each trigger drops all traffic and VPN sessions through the firewall until it comes back up, and Cisco states there are no workarounds.
Affected: Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.1, 9.16.1.28, 9.16.2, 9.16.2.3, 9.16.2.7, 9.16.2.11, 9.16.2.13, 9.16.2.14, 9.16.3, 9.16.3.3 (and other releases listed in cisco-sa-asaftd-vpn-dos-dzv4mQFF); Cisco Secure Firewall Threat Defense (FTD) Software with the Remote Access SSL VPN service enabled
How to Test: Check the running ASA/FTD software version against the affected release list in advisory cisco-sa-asaftd-vpn-dos-dzv4mQFF; the flaw is reachable only where the Remote Access SSL VPN service is enabled on an interface, so confirm whether that service is exposed on any internet-facing interface. For signs of attack, review the device for unexpected reloads and crash files since 2026-08-11 and correlate with inbound HTTP requests to the SSL VPN service in the same window.
How to Patch: Upgrade ASA/FTD to a fixed release for your train per Cisco advisory cisco-sa-asaftd-vpn-dos-dzv4mQFF (Bug ID CSCwv96220, version 1.1 of 2026-09-16). Cisco states no workarounds address this vulnerability; until the upgrade is applied, the only risk reduction is restricting who can reach the Remote Access SSL VPN service.
Evidence: CISA KEV · VulnCheck KEV · CISA SSVC: active · Eclypsium: someone is crashing Cisco firewalls with CVE-2026-20349 · HKCERT bulletin cited by VulnCheck KEV as exploitation source
3. Brevo CDN compromise injected ClickFix malware into customer-embedded scripts
SUPPLY-CHAIN COMPROMISE · HIGH
The vendor published its post-mortem on 17 September and reporting puts the blast radius above 100,000 customer websites, so any organisation embedding Brevo scripts must find and remediate visitors and staff who executed ClickFix commands before those footholds are sold on this week.
Brevo's post-mortem confirms attackers stole a Cloudflare API key and used it to deploy a malicious Cloudflare Worker that rewrote content at the CDN edge for roughly five and a half hours on 14 September 2026. The Worker altered pages on brevo.com, sendinblue.com, onboarding/login/account/my subdomains and sibforms.com, and — critically — the Brevo forms script, Brevo Conversations widget and Brevo SDK loader that customers embed on their own websites, serving ClickFix social-engineering prompts that lead visitors to run malware-installing commands.
Affected: Brevo forms script (sibforms.com embed) — 14 September 2026, ~5.5-hour window; Brevo Conversations widget script; Brevo SDK loader script; brevo.com pages; sendinblue.com pages; login.brevo.com / account.brevo.com / my.brevo.com / onboarding.brevo.com
How to Test: Grep your site templates, tag manager and CMS plugins for Brevo/Sendinblue script tags (sibforms.com, sibautomation.com, brevo.com SDK loader, Conversations widget) to confirm exposure; then search proxy, CDN and browser-error logs for requests to those hosts during 14 September 2026 and hunt endpoints for ClickFix execution artefacts — Windows RunMRU registry entries, clipboard-launched powershell.exe/mshta.exe/curl spawned from explorer.exe, and unexpected scheduled tasks or Run-key persistence created that day on machines whose users visited an affected site.
How to Mitigate: Nothing in your own code needs patching — the injection happened at Brevo's CDN edge and has been reverted — so remediation is to verify the currently served Brevo scripts match known-good hashes, pin them with Subresource Integrity or self-host where the vendor supports it, tighten script-src in your Content Security Policy, and reimage plus rotate credentials, browser sessions and MFA for every endpoint that ran a ClickFix command.
Evidence: BleepingComputer: Brevo post-mortem confirms stolen Cloudflare API key and malicious Worker · Cybernews: 100,000+ websites served malware for hours
4. Plugin4Shell: plugin SHA-pinning bypass gives zero-click code execution via auto-updating plugins (Claude Code, Codex, Gemini CLI, Copilot)
UNVERIFIED PUBLIC REPORT · NO CVE · REMOTE CODE EXECUTION · HIGH
Air published the technical write-up on 17 September and The Register covered it the same day; fixes for Claude Code and Codex exist now, while Gemini CLI has no fix and Copilot is unpatched, so developer machines and CI runners with plugins installed are exposed until upgraded or plugins are removed.
Researchers at Air Security report that major AI coding agents check out a marketplace plugin at its pinned commit SHA but never verify the checkout actually resolved to that commit. An attacker who controls a plugin's repository can make the checkout resolve to malicious code while the pin appears honored; because Claude Code and Codex auto-update installed plugins by default, the malicious version is pulled and executed with no user action, giving the attacker everything the agent can reach (source, credentials, tokens, cloud access). Anthropic and OpenAI have patched; Google says the deprecated Gemini CLI will not be fixed; Microsoft has not responded and Air says Copilot remains vulnerable. GitHub says it blocks branch/tag names that resemble SHAs, but Air notes marketplaces hosted elsewhere (e.g., Bitbucket) are not covered. No CVE has been assigned and there is no report of exploitation.
Affected: Claude Code before 2.1.179; Codex CLI before 0.146.0; all Gemini CLI installs (deprecated, no fix); Microsoft Copilot (unpatched, per Air) — exact Copilot builds not stated
How to Test: Check versions: claude --version (need 2.1.179+), codex --version (need 0.146.0+); any Gemini CLI install is affected; Copilot users with marketplace plugins from non-GitHub hosts should assume exposure. List installed plugins and their marketplace source; for each, compare the locally checked-out commit hash against the marketplace's pinned SHA and confirm the repo's branch/tag names do not resemble commit SHAs. Review agent logs for unexpected plugin updates since June.
How to Patch: Upgrade Claude Code to 2.1.179 or later and Codex to 0.146.0 or later. Uninstall Gemini CLI and move to a supported tool (Google recommends Antigravity). For Copilot and any agent without a fix, turn off plugin auto-update, remove plugins sourced from non-GitHub marketplaces, and restrict agents to plugins from repositories you control.
Evidence: The Register coverage of Plugin4Shell
Read on the web · Every past edition
The Exploit Bulletin is free and daily. It publishes only what security teams must act on today — nothing else. Forward it freely.
Spot an error, or an exploit we missed? Reply here or email [email protected].