W1RETAP Intel Report — 2026-09-18
W1RETAP INTEL REPORT
SEPTEMBER 18, 2026
================================================================
SEVERITY SCORE: 7/10 — HIGH
Two maximum-severity (CVSS 10.0) zero-days under active exploitation hit widely deployed enterprise infrastructure this week (Cisco ISE, Adobe Commerce/Magento), while ransomware crews are simultaneously weaponizing separate VMware and WatchGuard flaws and a state DMV database sits mid-extortion — a stack of concurrent, high-impact events rather than a routine patch week.
TOP STORY:
Cisco disclosed a maximum-severity zero-day in Identity Services Engine, CVE-2026-76460 (CVSS 10.0), already under active exploitation in the wild. The flaw stems from insufficient authentication control on an API endpoint — a crafted request lets an unauthenticated remote attacker bypass ISE's web-based management interface entirely. There is no workaround; patching is the only fix. CISA added the bug to its Known Exploited Vulnerabilities catalog on September 17 and gave federal agencies a three-day window to patch or pull ISE offline, a deadline expiring tomorrow, September 19. Given ISE's role as the identity and network-access control backbone in large enterprise and government networks, this is the single most consequential event of the window.
BREACHES & INCIDENTS:
The extortion group ShinyHunters is mid-campaign against Florida's DMV "DAVID" database, claiming theft of 200,000-plus driver records including license photos, signatures, addresses, and vehicle histories. Access reportedly came through credentials belonging to a Plant City Police Department user that were improperly stored on a personal device. ShinyHunters set and passed a September 11 extortion deadline and has since posted proof-of-breach material, including a screenshot of a high-profile individual's DMV record, to pressure the state. Florida has confirmed the intrusion; the situation remains active. No other major new breach disclosures broke in the last 24-48 hours beyond ongoing fallout from incidents reported earlier this month.
VULNERABILITIES & EXPLOITS:
Beyond the Cisco ISE zero-day above, Adobe patched a second CVSS 10.0 zero-day, CVE-2026-75650 ("StyleSmuggler"), an unauthenticated remote code execution flaw in Adobe Commerce and Magento's template engine. Attackers have been exploiting it since September 4 to plant a Rust-based Linux backdoor and a PHP web shell; CISA's KEV deadline for this one already passed on September 11, meaning unpatched instances have had a two-week exposure window. Separately, Microsoft's September Patch Tuesday was its largest on record at 974 CVEs, with two — CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack) — already under active exploitation. CISA logged roughly 14-15 additional KEV entries this week, notably CVE-2026-20079 (Cisco Secure Firewall), CVE-2026-86218 (N-able N-central), CVE-2026-84869 (ConnectWise ScreenConnect), CVE-2026-86060 (MikroTik RouterOS), CVE-2026-35273 (Oracle PeopleSoft), and CVE-2026-0257 (Palo Alto PAN-OS). Ransomware operators have also joined active exploitation of a previously patched VMware vCenter directory-traversal flaw (CVE-2026-59310) and a WatchGuard Firebox firewall vulnerability flagged as exploited back in December — both reminders that "patched" doesn't mean "remediated" across the install base.
TOOLS & TECH:
On the defensive side, Tuskira launched its Vector service, offering autonomous red-teaming that simulates external attacker behavior to validate exposed attack surface without manual engagement. Dataminr rolled out Dataminr Advanced for Corporate Security, an agentic AI product aimed at giving physical/corporate security teams earlier warning on emerging risk to people and sites. On the offensive tooling side, researchers tracking the open-source AI pentesting ecosystem now count roughly 70 AI-assisted offensive security tools in circulation, with the overwhelming majority released since GPT-4 — spanning autonomous exploitation agents, AI-assisted binary reverse engineering, and automated vulnerability discovery. That's not a single-day event, but it's the backdrop every new CVE this week is landing against.
U.S. GOVERNMENT CYBER MOVES:
CISA added Cisco ISE's CVE-2026-76460 to its KEV catalog with an unusually tight three-day federal remediation deadline, and is still operating under its updated Emergency Directive 26-03 covering Cisco SD-WAN systems, issued September 9. The agency also pushed out a batch of Industrial Control Systems advisories on September 17 (ICSA-26-260 series), continuing a steady cadence of ICS/OT disclosures this month. Notably, CISA plans to discontinue its long-running weekly Vulnerability Bulletin at the close of FY26 on September 28, shifting from severity-based reporting to a risk-based vulnerability prioritization model — a process change worth watching for anyone who relies on that feed. On the law enforcement side, the FBI's Anchorage Field Office, working with the Royal Canadian Mounted Police under Operation PowerOFF, seized the domains behind NightmareStresser on September 17 — a DDoS-for-hire "booter" service with more than 566,000 registered users that had been running since at least 2022. At Fort Meade, U.S. Cyber Command named Rear Adm. Ronzelle Green as its new Chief Artificial Intelligence Officer on September 15, while the NSA continues a broader reorganization into five mission centers (China, cybersecurity, AI, combat support, and global intelligence) under Gen. Joshua Rudd.
TRENDS TO WATCH:
Network-edge and identity infrastructure — VPNs, firewalls, and now identity/access platforms like Cisco ISE — remain the preferred initial-access vector for both ransomware crews and state-linked operators, and this week's back-to-back CVSS 10.0 disclosures in ISE and Adobe Commerce underline how little room there now is between disclosure and mass exploitation. The offensive tooling ecosystem's rapid AI-driven expansion (roughly 70 open-source AI pentesting tools, most born in the last two years) is compressing that window further, and industry surveys show AI-driven phishing is now cited by about half of security professionals as the top threat facing their organizations, with AI-enabled breaches running roughly $1 million costlier than the global average.
END OF REPORT — Coverage window: approximately September 16-18, 2026. Compiled from open-source reporting; treat any single-source claims (e.g., unconfirmed breach figures) as preliminary pending official confirmation.