CISA KEV
CVE-2026-20349: Cisco ASA and FTD remote-access VPN denial of service
Affected Cisco ASA and FTD remote-access listeners can let unauthenticated attackers trigger a reload. Check SSL VPN, IKEv2 and ZTNA configuration, then install the branch-specific hardening release to address the service-disruption risk.
CVE-2026-20316: Cisco FMC static credential is exploited and ransomware-linked
A hard-coded FMC password can expose sensitive data through a low-privileged account. Restrict management access, install Cisco's current hardening release, and review indicators; the initial access is not itself root access.
CVE-2026-16812: Arista VeloCloud Orchestrator unauthenticated command injection
Command injection threatens on-premises VeloCloud Orchestrator hosts and their managed data. Restrict exposure, upgrade the orchestrator branch, and examine downstream edge state and trust material when compromise is suspected.
CVE-2026-76460: Cisco ISE authentication bypass is actively exploited
Cisco reports active exploitation of an ISE and ISE-PIC authentication bypass that can lead to root access. Check every node, preserve off-device evidence, and separate patch installation from investigation and trusted recovery.
CVE-2026-58704: Pixel cellular-modem privilege escalation
The exploited Pixel cellular-modem flaw can bypass permission checks. Install the current Pixel update, restart, and verify the security patch level; a successful update does not establish whether earlier exploitation occurred.
CVE-2026-76461: Cisco Secure Email Gateway crafted-email root command execution
Cisco Secure Email Gateway SQL injection can give unauthenticated attackers root command execution. Preserve mail and network evidence, match the AsyncOS upgrade path, and use Cisco TAC when compromise is suspected.
CVE-2026-86060: MikroTik RouterOS MikroTrick policy-mask privilege escalation
MikroTik RouterOS policy-mask manipulation can escalate privileges. Upgrade the affected release, restrict untrusted SSH access, and inspect users, scripts and configuration even when the router does not report a Flagged state.
CVE-2026-67277: MikroTik RouterOS btest unauthenticated memory disclosure and denial of service
Missing authentication in RouterOS btest can disclose kernel memory or interrupt service. Check the service and release, then install the supported fix; restricting SSH alone does not establish that this btest flaw is resolved.
CVE-2026-20079: Cisco FMC unauthenticated authentication bypass to root
Cisco FMC authentication bypass can give unauthenticated attackers root access. Restrict management exposure, preserve evidence, and follow release-specific hardening and compromise assessment; patching alone does not resolve an existing intrusion.
CVE-2026-19490: NetScaler Gateway and AAA authentication bypass
NetScaler appliances configured as Gateway or AAA virtual servers can permit unauthenticated access. Check the exact edition and build, upgrade affected customer-managed instances, and preserve evidence for the separate compromise review.
