ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
BoardBriefings › Cisco Rushes Emergency Patch for Actively Exploited ISE Zero-Day as Apple Ships Six Critical macOS Fixes
IT SECURITY DESK

Cisco Rushes Emergency Patch for Actively Exploited ISE Zero-Day as Apple Ships Six Critical macOS Fixes

An unauthenticated authentication-bypass flaw in Cisco Identity Services Engine is under active exploitation, while Apple patches six critical macOS holes and Microsoft investigates a Windows 11 update breaking domain trust.

SecurityWeek reported that Cisco has issued an emergency patch for a zero-day in Identity Services Engine (ISE) that is under active exploitation. According to SecurityWeek, remote, unauthenticated attackers can exploit the flaw to bypass authentication using crafted requests. Organizations running ISE should apply Cisco's emergency patch as a priority, given the combination of no authentication requirement and confirmed in-the-wild exploitation.

Apple has also pushed fixes for six critical macOS vulnerabilities, per the vendor's advisories. Five of the six affect macOS 15.0 up to the fix delivered in 15.8; the sixth, CVE-2026-84520, affects macOS from its earliest version up to the fix delivered in 27.0. Four of the six carry a CVSS 3.1 base score of 9.8 or higher: CVE-2026-84561 and CVE-2026-65414 (9.8, network vector, no privileges or user interaction required, full loss of confidentiality, integrity and availability), CVE-2026-84520 (9.8), and CVE-2026-65381 (10.0, with a changed scope). Two more score 9.1: CVE-2026-86881 (confidentiality and integrity impact, no availability impact) and CVE-2026-43790 (integrity and availability impact, no confidentiality impact). None of the six appear on CISA's Known Exploited Vulnerabilities catalog. Apple's advisories direct affected users to the vendor's published guidance and any interim mitigation for the fixed release.

Separately, BleepingComputer reported that Microsoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust relationships on some enterprise systems, preventing users from logging in with valid domain credentials. Enterprises that have deployed this update should watch for domain authentication failures and follow Microsoft's guidance as the investigation proceeds.

Elsewhere, The Record reported that House Energy and Commerce Chairman Brett Guthrie said action on the FRONTIER Act, federal AI safety legislation, will wait until 2027, saying he did not want to rush it in a lame-duck session. Krebs on Security reported that data broker Radaris lost domains following a lawsuit alleging violations of a New Jersey privacy law. BleepingComputer reported that Anthropic is testing "Claude Money," a feature that would connect Claude directly to users' bank accounts.

Related