Current threats. Clear scope. Direct vendor guidance.

The TechGeeks Security Notice Center turns authoritative vendor and government disclosures into concise operator guidance. Each CVE has a stable issue page with applicability, priority, remediation boundaries, investigation notes, and direct primary-source links.

Browse all Security Notices · Subscribe to the Security Notices feed

Quick Answer

Start with confirmed exploitation, then vendor severity and exposed management-plane risk. Match the exact product, platform, release, feature, and exposure against the live advisory; preserve relevant off-device evidence; apply the vendor-directed fix; and validate service and security behavior. Keep severity, exploitation, ransomware association, and forensic-triage status separate. Patching closes a documented flaw but does not prove an exposed system was never compromised.

Last verified: September 17, 2026 UTC. CISA and vendor status can change; each issue page links the live advisory that controls affected and fixed release information.

Context

Coverage At A Glance

182
CVE issue pages
103
CISA KEV notices
32
new Cisco advisories
79
CVEs in Cisco's new set

The center includes 103 in-scope vulnerabilities that CISA added to KEV during 2026, the complete 79-CVE set from Cisco's 32 final September 16 advisories, and one separate older Cisco advisory whose affected-platform scope changed materially. One Cisco CVE—CVE-2026-76460—appears in both the Cisco set and CISA KEV, so it has one canonical issue page.

Cisco PSIRT Publication Reconciliation

Cisco's finalized publication set contains 12 Critical, 8 High, and 12 Medium advisories. Across its 79 CVEs, the independent CVSS base-severity counts are 24 Critical, 25 High, 29 Medium, and 1 Low. Each issue page shows a CVE-specific Cisco SIR only when Cisco explicitly states one; otherwise it says the value was not separately stated. Cisco directly reported active exploitation only for CVE-2026-76460 in this set. Fifteen CVEs have a public announcement but no malicious use reported; two have related exploited-CVE context without direct malicious use reported; the remaining 61 carry Cisco's no-public-announcement-or-malicious-use-known wording. Each page preserves its exact bucket.

Hot Right Now

These notices lead because they combine exploitation evidence, privilege, management-plane exposure, or severe vendor impact. TechGeeks priority tiers support triage; they are not universal legal deadlines.

P0 — ACT NOWCISA KEVCISCO

CVE-2026-76460: Cisco ISE authentication bypass is actively exploited

Cisco — Identity Services Engine
CISA KEV added 2026-09-16; vendor and CISA details are separated on the issue page.

Restrict ISE management and control-plane access, preserve off-device evidence, review every deployment node, and upgrade to the fixed patch for the installed train. If malicious activity is suspected, follow Cisco TAC guidance and re-image affected nodes rather than treating patching as eradication.

Open TechGeeks notice · Vendor notice

P0 — ACT NOWCISA KEVCISCO

CVE-2026-76461: Cisco Secure Email Gateway crafted-email root command execution

Cisco — Secure Email Gateway
CISA KEV added 2026-09-14; vendor and CISA details are separated on the issue page.

Preserve relevant mail, DNS, firewall, and authentication evidence, confirm the AsyncOS release, and upgrade to an advisory-listed fixed release. Use Cisco TAC and incident-response procedures if exploitation is suspected.

Open TechGeeks notice · Vendor notice

P0 — ACT NOWCISA KEVGOOGLE

CVE-2026-58704: Pixel cellular-modem privilege escalation

Google — Pixel
CISA KEV added 2026-09-16; vendor and CISA details are separated on the issue page.

Install the current Pixel system update, restart the device, and verify that Android security update is 2026-09-05 or later.

Open TechGeeks notice · Vendor notice

P0 — ACT NOWCISA KEVMICROSOFT

CVE-2026-81963: Windows Update Stack privilege escalation to SYSTEM

Microsoft — Windows
CISA KEV added 2026-09-08; vendor and CISA details are separated on the issue page.

Install the applicable September 2026 or later Windows cumulative update and verify the resulting Windows build against the live MSRC table.

Open TechGeeks notice · Vendor notice

P0 — ACT NOWCISA KEVMICROSOFT

CVE-2026-85880: Windows ALPC local privilege escalation

Microsoft — Windows
CISA KEV added 2026-09-08; vendor and CISA details are separated on the issue page.

Install the applicable September 2026 or later Windows cumulative update and verify that the asset is on a fixed build listed by Microsoft.

Open TechGeeks notice · Vendor notice

P0 — ACT NOWCISA KEVCISCO

CVE-2026-20079: Cisco FMC unauthenticated authentication bypass to root

Cisco — Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
CISA KEV added 2026-09-09; vendor and CISA details are separated on the issue page.

Remove public access to the FMC management interface where possible, preserve evidence, run Cisco's documented indicator check, and upgrade to the fixed hardening release for the installed train. Contact Cisco TAC immediately if exploitation is suspected.

Open TechGeeks notice · Vendor notice

P1 — URGENTCISCO PSIRTADVISORY SIR: CRITICALDIRECT EXPLOITATION: NOT REPORTED

CVE-2026-20130: Cisco ISE hardening: Improper Neutralization Vulnerabilities

Cisco Identity Services Engine (ISE)
Cisco advisory SIR: Critical; CVE-specific SIR: Not separately stated; CVSS base: 10 (Critical). Cisco reported no public announcement or malicious use for this CVE at the last check.

Confirm the affected product, release, and configuration. Cisco provides no workaround; reduce exposure where operationally feasible. Upgrade to the CVE-specific First Fixed release in Cisco's advisory table.

Open TechGeeks notice · Cisco advisory

P1 — URGENTCISCO PSIRTADVISORY SIR: CRITICALDIRECT EXPLOITATION: NOT REPORTED

CVE-2026-20324: Cisco Secure Firewall Management Center sftunnel Root Arbitrary Code Execution Vulnerability

Cisco Secure Firewall Management Center (FMC)
Cisco advisory SIR: Critical; CVE-specific SIR: Not separately stated; CVSS base: 9.9 (Critical). Cisco reported no public announcement or malicious use for this CVE at the last check.

Confirm the affected product, release, and configuration. Cisco provides no workaround; reduce exposure where operationally feasible. Enter the exact installed product, platform, and release in Cisco Software Checker and upgrade to the returned First Fixed release; the September 2026 combined hardening baseline is a current fixed target.

Open TechGeeks notice · Cisco advisory

P1 — URGENTCISCO PSIRTADVISORY SIR: CRITICALDIRECT EXPLOITATION: NOT REPORTED

CVE-2026-20242: Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerability

Cisco Secure Firewall Management Center (FMC)
Cisco advisory SIR: Critical; CVE-specific SIR: Not separately stated; CVSS base: 9.8 (Critical). Cisco reported no public announcement or malicious use for this CVE at the last check.

Confirm the affected product, release, and configuration. Apply Cisco's documented mitigation as temporary risk reduction. Enter the exact installed product, platform, and release in Cisco Software Checker and upgrade to the returned First Fixed release; the September 2026 combined hardening baseline is a current fixed target.

Open TechGeeks notice · Cisco advisory

P1 — URGENTCISCO PSIRTADVISORY SIR: CRITICALDIRECT EXPLOITATION: NOT REPORTED

CVE-2026-20360: Cisco Nexus Dashboard hardening: Information Exposure & Insecure Handling

Cisco Nexus Dashboard
Cisco advisory SIR: Critical; CVE-specific SIR: Not separately stated; CVSS base: 8.8 (High). Cisco reported no public announcement or malicious use for this CVE at the last check.

Confirm the affected product, release, and configuration. Cisco provides no workaround; reduce exposure where operationally feasible. Upgrade to the CVE-specific First Fixed release in Cisco's advisory table.

Open TechGeeks notice · Cisco advisory

All Security Notices

Every CVE below has one canonical page. The groups keep confirmed exploitation separate from vendor severity and from the materially revised older advisory.

Find a Security Notice

Filter the complete issue index by vendor, technology, response tier, or CVE and keyword.

Showing 182 of 182 notices

No notices match those filters. Reset one or more fields and try again.

Microsoft — CISA KEV — 38 notices
Apple / macOS / iPhone / iPad — CISA KEV — 8 notices
Android / Pixel / components — CISA KEV — 4 notices
Network and edge vendors — CISA KEV — 53 notices
Cisco PSIRT — Critical / High advisory SIR — 54 notices
Cisco PSIRT — Medium advisory SIR — 24 notices
Cisco PSIRT — materially revised older advisory — 1 notices

Steps

If Your Product Matches

  1. Confirm: record the exact product, hardware or virtual platform, release, patch level, enabled feature, role, exposure, and advisory revision.
  2. Contain: restrict unnecessary management, VPN, portal, API, messaging, or service exposure using supported controls.
  3. Preserve: save external logs, accounts, sessions, configuration, and UTC context before evidence rotates.
  4. Prepare: verify off-device backups, console or out-of-band access, credentials, certificates, licenses, capacity, and the supported upgrade path.
  5. Remediate and validate: apply the vendor action, confirm the resulting version, then test service health, expected access, expected denial, dependencies, logging, failover, and monitoring.
  6. Investigate and recover: when exposure or evidence creates doubt, move from patch management to incident response and trusted recovery.

Notes

How To Read The Signals

  • P0 — Act now: TechGeeks operational priority for confirmed exploitation. It is not a CVSS score or universal legal deadline.
  • P1 — Urgent: Critical or High Cisco advisory SIR, or another urgent vendor impact, requiring prompt exact-match review and vendor-directed remediation.
  • P2 — Review: Medium Cisco advisory SIR, or another review-tier vendor impact, that still requires applicability, exposure, and compensating-control review.
  • CISA KEV: CISA has evidence the CVE was exploited; this does not state prevalence or prove a particular asset was compromised.
  • Advisory SIR / CVE SIR / CVSS: separate vendor impact and scoring signals supplied by Cisco; none establishes exploitation by itself.
  • Vendor 'not aware' wording: a time-bounded status statement, not proof of no exploitation.

Validation And Boundaries

This center is documentation-backed and does not replace vendor advisory databases, asset inventory, a vulnerability-management platform, or incident response. A KEV entry does not prove mass exploitation. A Critical rating does not prove exploitation. A clean indicator search does not prove a privileged attacker was absent. A successful update does not prove persistence was removed or every workflow is healthy. TechGeeks did not reproduce these exploits or independently test every patch.

Related TechGeeks Resources

References

Wrap-Up

Subscribe to the Security Notices feed, record exact product matches in your vulnerability queue, and assign owners by evidence and exposure. Open the linked vendor advisory immediately before each change because affected releases, fixed builds, and exploitation statements can be revised.

Correction policy: Material source changes trigger an issue-page update, an index reconciliation, and a new reader-visible verification date.