Rapid responses

The runZero Rapid Response program detects emerging threats and notifies you immediately. Older entries move to standalone queries or templates.

8
Rapid Responses
6
software
1
services
1
assets
8 of 8 rapid responses
Multiple Vulnerabilities In Cisco Identity Services Engine (2026-09)
Type:softwarePublished:Sep 17, 2026

Cisco Identity Services Engine (ISE) is a network access control and policy enforcement platform, and Cisco ISE Passive Identity Connector (ISE-PIC) provides passive identity mapping for third-party enforcement devices.

On September 16, 2026, Cisco published four advisories covering multiple vulnerabilities in ISE and ISE-PIC. All four advisories affect the same 3.1-3.5 release lines and share an identical set of first-fixed releases, so they are combined here into a single rapid response with one remediation path. The vulnerabilities are independent of one another; a release affected by one is not necessarily affected by the others.

  • CVE-2026-76460 (CVSS 10.0, cisco-sa-ISE-ABP-VNSW7Tn5): An unauthenticated, remote attacker can bypass authentication on an API endpoint due to insufficient authentication control, gaining unauthorized access to the web-based management interface.

  • CVE-2026-76423 (CVSS 10.0, cisco-sa-ise-multi-hrP9jQSQ): An unauthenticated, remote attacker can gain administrative access via the REST API due to insufficient authorization checks on the exposed REST API port.

  • CVE-2026-76424 (CVSS 7.2, cisco-sa-ise-multi-hrP9jQSQ): An authenticated attacker can upload or copy arbitrary files via the REST API due to insufficient path validation, leading to root command execution.

  • CVE-2026-76425 (CVSS 7.6, cisco-sa-ise-multi-hrP9jQSQ): An authenticated attacker can conduct SQL injection against the backend database and perform SSRF.

  • CVE-2026-76426 (CVSS 4.9, cisco-sa-ise-multi-hrP9jQSQ): An authenticated attacker can conduct SQL injection against the monitoring database via the REST API.

  • CVE-2026-76427 (CVSS 4.9, cisco-sa-ise-multi-hrP9jQSQ): An authenticated attacker can read arbitrary files via XML external entity injection in the offline profiler feed service.

  • CVE-2026-76428 (CVSS 4.9, cisco-sa-ise-multi-hrP9jQSQ): An authenticated attacker can conduct SQL injection against the session database via the REST API.

  • CVE-2026-20307 (CVSS 9.9, cisco-sa-ise-rce-se7bYU57): A low-privileged, authenticated attacker can execute arbitrary root-level commands via insecure deserialization of a Java object in the web-based management interface.

  • CVE-2026-20176 (CVSS 9.1, cisco-sa-ise-rce-se7bYU57): A high-privileged, authenticated attacker can execute arbitrary root-level commands due to insufficient input validation.

  • CVE-2026-20211 (CVSS 9.1, cisco-sa-ise-rce-se7bYU57): A high-privileged, authenticated attacker can execute arbitrary root-level commands via insecure deserialization of Java objects.

Cisco also disclosed a hardening release (cisco-sa-hardening-ise-XU5EwX5T) covering multiple vulnerabilities found during internal security testing. Cisco grouped these by underlying CWE class and assigned one CVE ID per class, so each CVE below represents several related internal findings rather than a single flaw:

  • CVE-2026-20130 (CVSS 10.0, cisco-sa-hardening-ise-XU5EwX5T): Improper neutralization of special elements in output (CWE-74), covering command injection, cross-site scripting, XML injection, code injection, and resource injection findings.

  • CVE-2026-20192 (CVSS 10.0, cisco-sa-hardening-ise-XU5EwX5T): Improper access control (CWE-284), covering authorization, authentication, privilege, and bypass findings.

  • CVE-2026-20194 (CVSS 9.1, cisco-sa-hardening-ise-XU5EwX5T): Incorrect resource transfer between spheres (CWE-669), covering exposure of sensitive information in transit, improper removal of sensitive information before storage, and unrestricted file upload findings.

  • CVE-2026-20234 (CVSS 9.9, cisco-sa-hardening-ise-XU5EwX5T): Insufficiently protected credentials (CWE-522), covering information disclosure and passwords stored or encoded in a recoverable format.

  • CVE-2026-20237 (CVSS 9.9, cisco-sa-hardening-ise-XU5EwX5T): Improper input validation (CWE-20), covering path traversal and external control of file paths.

  • CVE-2026-20287 (CVSS 6.5, cisco-sa-hardening-ise-XU5EwX5T): Improper privilege management (CWE-269), covering incorrect privilege assignment, privilege chaining, and misuse of privilege-checking APIs.

These vulnerabilities affect Cisco ISE and ISE-PIC regardless of device configuration.

There is evidence that CVE-2026-76460 is being actively exploited in the wild, and it was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on September 16, 2026.

The following releases are affected by one or more of these vulnerabilities:

  • Cisco ISE and ISE-PIC 3.1: Versions through 3.1 Patch 11
  • Cisco ISE and ISE-PIC 3.2: Versions through 3.2 Patch 10
  • Cisco ISE and ISE-PIC 3.3: Versions through 3.3 Patch 11
  • Cisco ISE and ISE-PIC 3.4: Versions through 3.4 Patch 6
  • Cisco ISE and ISE-PIC 3.5: Versions through 3.5 Patch 3

Cisco ISE Software Release 3.0 has reached End of Software Maintenance; customers are advised to migrate to a supported release that includes the fixes.

vendor:="Cisco" AND product:="Identity Services Engine"
Cisco Secure Email Gateway SQL Injection (CVE-2026-76461)
Type:servicesPublished:Sep 14, 2026

Cisco Secure Email Gateway is a secure email security appliance that allows organizations to handle email securely and potentially quarantine malicious or unwanted emails for analysis.

Certain versions of the Secure Email Gateway are affected by an unauthenticated SQL injection vulnerability, that could allow an unauthenticated actor to execute commands with administrative privileges on the underlying operating system.

There is evidence that these vulnerabilities are being actively exploited in the wild and the vulnerability has been added to the CISA KEV list September 14, 2026.

The following versions are affected

  • 15.5.4-012 and earlier
  • 16.0.3-044 and earlier
  • 16.5.0 before 16.5.0-780
_asset.protocol:=http AND protocol:=http AND last.html.title:"Cisco%Gateway%C" AND NOT last.html.title:"Cloud"
GitLab Unauthenticated Path Traversal (CVE-2026-85706)
Type:softwarePublished:Sep 11, 2026

GitLab Community Edition (CE) provides core Git repository management and CI/CD pipelines, while Enterprise Edition (EE) includes all CE capabilities alongside advanced security, compliance, and enterprise scalability features.

Self-managed installations of GitLab Community Edition (CE) and Enterprise Edition (EE) contain a critical path traversal vulnerability in the repository commits API. Due to improper path confinement and missing authentication enforcement, a remote, unauthenticated attacker can read arbitrary server files. Successful exploitation may lead to the exposure of sensitive configuration data, system credentials, or source code.

There is evidence that this vulnerability is being actively exploited in the wild, and it was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on September 11, 2026.

The following versions are affected:

  • GitLab CE & EE 18.x - 19.1.x: Versions 18.7.0 through 19.1.7
  • GitLab CE & EE 19.2.x: Versions 19.2.0 through 19.2.5
  • GitLab CE & EE 19.3.x: Versions 19.3.0 through 19.3.1
vendor:="GitLab" AND product:="GitLab"
N-Able N-Central Multiple Vulnerabilities (2026-09)
Type:softwarePublished:Sep 9, 2026

N-able N-central is an enterprise remote monitoring and management (RMM) software platform used by managed service providers (MSPs) and internal IT teams to discover, automate, patch, and secure network infrastructure and endpoints across Windows, macOS, Linux, and cloud environments.

Certain versions of N-Central are affected by multiple vulnerabilities:

  • CVE-2026-86206: An access control bypass vulnerability in the internal API access control filter allows a remote, unauthenticated attacker to obtain unauthorized access to internal APIs.

  • CVE-2026-86207: An authentication bypass vulnerability in the internal API allows a remote, low-privileged attacker to obtain unauthorized privileges.

  • CVE-2026-86218: A pre-authentication remote code execution (RCE) vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the target server.

There is evidence that CVE-2026-86218 is being actively exploited in the wild, prompting its addition to the CISA KEV catalog on September 8, 2026.

The following versions are affected:

  • N-Central: Versions prior to 2026.3 Hotfix 4 (Build 2026.3.1.14)

Note: CVE-2026-86218 is resolved in 2026.3 Hotfix 4 (Build 2026.3.1.14), which supersedes 2026.3 Hotfix 3 (Build 2026.3.1.13) (the patch for CVE-2026-86206 and CVE-2026-86207).

vendor:="N-able" AND product:="N-central" AND source:runzero
Multiple Vulnerabilities In Mikrotik RouterOS
Type:softwarePublished:Sep 7, 2026

Mikrotik RouterOS versions prior to 6.49.21, 7.23.4, 7.24.2, or 7.25 beta 3 are affected by multiple vulnerabilities:

  • CVE-2026-67276: RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.

  • CVE-2026-67277: RouterOS accepts a “related” btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With “random-data=false”, the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel.

  • CVE-2026-67278: MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during X.509 validation. Because its trust store includes an e=3 root CA, an attacker controlling or redirecting an outbound RouterOS TLS connection can use the root’s public certificate - without its private key - to forge a trusted intermediate and issue certificates for arbitrary hostnames, enabling TLS server impersonation.

  • CVE-2026-67279: RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support files containing configuration and diagnostic data.

  • CVE-2026-67281: RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving path dereferences this pointer with sufficient rights, then supply parent-directory components in an encrypted URI to escape the WebFig file namespace and disclose root-owned files, including configuration stores containing credentials.

  • CVE-2026-86060: RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.

There is evidence that these vulnerabilities are being actively exploited in the wild as of September 6th, 2026.

The following versions are affected

  • From 6.0.0 below 6.49.21
  • From 7.0.0 below 7.23.4
  • From 7.24 below 7.24.2
os:="MikroTik RouterOS" AND ((os_version:>="6.0.0" AND os_version:<="6.49.21") OR (os_version:>"7.0.0" AND os_version:<="7.23.4") OR (os_version:>"7.24" AND os_version:<="7.24.2"))
Multiple Vulnerabilities In SonicWall SMA 1000 Series Products
Type:softwarePublished:Sep 3, 2026

SonicWall Secure Mobile Access (SMA) 1000 series appliances are hardware security devices that provide zero-trust and secure access gateway support for businesses.

Certain versions of the SonicWall SMA1000 appliances are affected by multiple vulnerabilities:

  • CVE-2026-83548: An Server-Side Request Forgery (SSRF) vulnerability allows a remote unauthenticated attacker to access internal server resources and unintented locations.

  • CVE-2026-83549: An authenticated remote code execution (RCE) vulnerability in the SMA1000 Appliance Management Console (AMC) could allow an attacker with valid permissions to execute OS commands.

There is evidence that these vulnerabilities are being actively exploited in the wild and the vulnerability has been added to the CISA KEV list September 3rd, 2026.

The following versions are affected

  • SMA1000 Models - 6210, 7210, 8200v
    • 12.4.3-03453
    • 12.5.0-02835
hw:="SonicWall SMA1000" AND os_version:>0 AND (os_version:=12.4.3 OR os_version:=12.5.0)
Plex Media Server & Desktop Undisclosed Vulnerabilities (2026-09)
Type:softwarePublished:Sep 2, 2026

Plex Media Server and Plex Desktop form a client-server media system where the server organizes and streams personal media files from a central storage device, and the desktop application serves as a frontend interface for browsing and playing that content on a computer.

Plex has issued a security update addressing multiple undisclosed vulnerabilities across Plex Media Server and Plex Desktop. While formal CVE identifiers have been requested, specific technical details and CVSS ratings remain undisclosed. Unpatched installations may expose systems to unauthorized access or remote security risks depending on the specific attack vector.

The following versions are affected:

  • Plex Media Server: Versions prior to 1.43.3
  • Plex Desktop: Versions prior to 1.115.0
vendor:=Plex AND product:"Media Server"
BMC Vulnerabilities - runZero Research
Type:assetsPublished:Aug 4, 2026

runZero has identified multiple vulnerabilities in a large subset of major baseboard management controllers (BMCs) that can lead to device compromise or segmentation breakdowns. Details of individual vulnerabilities will be published as the disclosure process completes.

BMCs are embedded into every modern enterprise server. These devices run their own OS, have their own network interfaces, and are network-reachable even when the server is powered off. The devices speak a protocol called IPMI that was thoroughly trashed by Dan Farmer’s ground-breaking research in 2013. Since Farmer’s original research into Cipher Zero authentication bypass and RAKP password hash disclosure, dozens of new vulnerabilities have been identified in these devices, but none of this research revisits the IPMI protocol itself.

High level details of our findings will be presented at Black Hat 2026 & DEF CON 34.

(protocol:ipmi OR type:=BMC) AND ( hw:=OpenBMC OR  hw:="Super Micro IPMI" OR  hw:="HP% iLO%" OR  hw:="Dell iDRAC%" OR  hw:="AMI MegaRAC" OR  (hw:="Raritan%" AND type:="Power Device") OR  hw:="H3C HDM" OR  hw:="Fujitsu%")

Each Rapid Response includes a query that finds matching assets, a trigger that analyzes all inventories for exposure, and a blog post with the details of the issue, so you can mitigate exposures before compromise.

As mitigations become available, runZero replaces a Rapid Response entry with more specific coverage.
Updated