MEFILES · Edition No. 68Today's edition · Archive · RSS
Ten files · One region · Zero illusions
All Digital Front Monitor stories → The full edition of September 21, 2026 →
Control Planes

A maximum-severity Cisco flaw and a root-level Check Point bug surface in the same week

Both sit in the administrative layer of enterprise and government networks. Neither has an attributed actor, and this desk was unable to open the originating advisories.

The 20 September edition of the This Week in Security newsletter, attributing the reporting to CyberScoop, says Cisco customers face two actively exploited zero-days, one of them CVE-2026-76460 in Cisco Identity Services Engine carrying a maximum severity score of 10 out of 10. A second critical bug is referenced without an identifier in the summary this desk saw. ISE is the identity and access-control layer: it decides which device and which user reaches which part of a network, which makes an unauthenticated maximum-severity flaw in it a question of who controls the network rather than a routine patch note. Two cautions apply. The CyberScoop original was not read for this edition, and the Cisco advisory and CISA’s Known Exploited Vulnerabilities entry were not checked directly. There is exploitation reported and no attribution attached to it.

SecurityWeek’s front page carried four further items dated 18 September, headline-level only, with article URLs not captured. A critical vulnerability in Check Point Security Management and Log Servers permits remote code execution with root privileges — Check Point is an Israeli vendor whose management plane sits inside a large number of Middle East government and enterprise networks, which makes a root-level flaw there a sovereignty-adjacent problem rather than an IT one. CVE-2026-58138 is described as an unauthenticated remote code execution flaw exploitable through inline workflow definitions; the affected product was not captured. Microsoft patched a set of Azure and AI-branded product flaws in which privilege escalation was the majority. And NightmareStresser, described as one of the longest-running DDoS-for-hire services and active since at least 2022, was taken down — booter services being the actual delivery mechanism behind most claimed hacktivist DDoS in the Iran–Israel exchange.

The same newsletter carries two other items in the control-infrastructure category, both with originals this desk could not open. A physical Flock automated licence-plate-reader camera was taken apart, its software extracted and the code passed to DDoSecrets, which supplied copies to Wired and 404 Media; the teardowns are characterised as showing the cameras are essentially Android phones on mounts, with hardcoded keys among the flaws, while cities including Boston continue to adopt the technology. No Middle East angle is confirmed in that reporting. Separately, the email platform Brevo — breached the previous week to send phishing to Trezor wallet customers — was breached a second time, resulting in ClickFix-style malware served through more than 100,000 websites that embed Brevo code. A linked Reddit malvertising campaign pushing a spoofed HBO site involved more than a hundred malicious ads, according to Hudson Rock; neither Reddit nor HBO disclosed click numbers.

Assessment: The temptation with a 10-out-of-10 flaw in an identity-control plane is to reach for the actor who has used that access before, and in 2026 that reflex points at Iranian and Israeli operators. Resist it until a vendor names a cluster or CISA lists the CVE as exploited. Note also how much of this week’s material reaches readers through a single weekly newsletter summarising paywalled and uncaptured originals: the 100,000-website figure is order-of-magnitude at best, and the Hudson Rock ad count is one vendor’s. The Flock leak is the cleaner story structurally — stolen material laundered through a transparency intermediary to two named outlets — and it is exportable, because licence-plate-reader networks are being procured across the Gulf.

Digital Front MonitorMEFILES tracking
10/10reported severity of CVE-2026-76460 in Cisco Identity Services Engine, said to be actively exploited
Evidence4 cited sources · This Week in Security · SecurityWeek · Unit 42 · CISA
The file23 Jul: 1 story24 Jul: 1 story25 Jul: 2 stories26 Jul: 2 stories27 Jul: 2 stories28 Jul: 2 stories29 Jul: 2 stories30 Jul: 2 stories31 Jul: 2 stories1 Aug: 2 stories2 Aug: 2 stories3 Aug: 2 stories4 Aug: 2 stories5 Aug: 2 stories6 Aug: 2 stories7 Aug: 2 stories8 Aug: 2 stories9 Aug: 2 stories10 Aug: 2 stories11 Aug: 2 stories13 Aug: 2 stories14 Aug: 2 stories15 Aug: 2 stories16 Aug: 2 stories17 Aug: 2 stories18 Aug: 2 stories19 Aug: 2 stories20 Aug: 2 stories21 Aug: 2 stories22 Aug: 3 stories23 Aug: 2 stories24 Aug: 3 stories25 Aug: 3 stories26 Aug: 2 stories27 Aug: 2 stories28 Aug: 2 stories29 Aug: 2 stories30 Aug: 2 stories31 Aug: 2 stories1 Sept: 2 stories2 Sept: 2 stories3 Sept: 2 stories4 Sept: 2 stories5 Sept: 2 stories6 Sept: 3 stories7 Sept: 2 stories8 Sept: 2 stories9 Sept: 2 stories10 Sept: 2 stories11 Sept: 2 stories12 Sept: 2 stories13 Sept: 2 stories14 Sept: 2 stories15 Sept: 2 stories16 Sept: 2 stories17 Sept: 2 stories18 Sept: 2 stories19 Sept: 2 stories20 Sept: 2 stories21 Sept: 2 stories
Digital Front Monitor · 62 editions since 19 July 2026 · 124 stories filed · 2 in this edition · rail shows the last 60