Two Management Planes, Both Rooted (09/17/2026)

September 17, 2026
Two Management Planes, Both Rooted (09/17/2026)
Key Intel / TL;DR
  • Cisco disclosed a CVSS 10.0 authentication bypass in Identity Services Engine already under active exploitation.
  • A critical Check Point management flaw lets unauthenticated attackers execute code as root.
  • A supply chain attack through Brevo injected ClickFix scripts directly into customer websites.
  • China-aligned FamousSparrow deployed a new SparroWocky backdoor across Latin American targets.
  • The Gyazo breach exposed 23.62 million user records and 490 million image metadata records.

Two products whose entire job is deciding who gets access were disclosed today with flaws that hand that decision to an unauthenticated attacker. A policy engine and a management server occupy the same position in an architecture, which is above everything they govern and behind nothing.

Top 5 Critical Security Alerts

1. A Cisco ISE Authentication Bypass Is Under Active Attack

Cisco warned of a new zero-day in Identity Services Engine, a CVSS 10.0 authentication bypass already being exploited in the wild. ISE is the system that decides which devices and users are admitted to the network and under what policy, so bypassing its authentication does not get an attacker onto one box, it gets them the authority that governs admission. This is the second maximum-severity Cisco flaw under exploitation inside a week, after the Secure Email Gateway zero-day on Tuesday. The Hacker News has the CVE and Infosecurity Magazine has the exploitation.

Operator Note: Treat a policy engine compromise as an identity incident rather than a host incident, which means reviewing what policies changed and which endpoints were admitted during the window.

2. Check Point’s Management Server Can Be Rooted Without Authentication

Check Point patched a critical flaw allowing unauthenticated attackers to run code as root on the management server. A firewall management platform holds the rule set for every enforcement point it controls and the credentials to push changes to all of them, so root there is administrative control of the perimeter rather than access through it. Two vendors of security infrastructure disclosed unauthenticated paths to full control on the same day. The Hacker News has the advisory.

Operator Note: Export your current firewall policy to a file today, before you patch, so you have a comparison baseline that predates any change an attacker might have made.

3. A Brevo Supply Chain Attack Injected ClickFix Into Customer Sites

Attackers compromised the email platform Brevo’s supply chain and injected ClickFix scripts directly into customer websites. This is the third Brevo-linked incident we have covered this month, after the breach that produced the Trezor phishing run, and the pattern is worth naming, since a marketing platform embeds script on pages its customers control and neither party treats that as a code dependency. The injected technique needs the visitor to act, which means the compromise arrives dressed as the site’s own instruction. BleepingComputer has the campaign.

4. FamousSparrow Deploys a New Backdoor Across Latin America

The China-aligned group FamousSparrow replaced its long-running SparrowDoor implant with a new backdoor tracked as SparroWocky, deployed across Latin American targets including government and high-tech organizations. Retiring a tool that had served for years and shipping a replacement indicates a team with sustained development capacity rather than one buying access. Salt Typhoon was separately reported backdooring Latin American organizations with new snooping malware, which puts two Chinese state efforts in the same region simultaneously. The Hacker News has the backdoor and WeLiveSecurity has the analysis.

5. Gyazo Loses 23.6 Million Records and 490 Million Image References

A server flaw at the screenshot service Gyazo was exploited to steal 23.62 million user records along with metadata for 490 million images. The metadata count is the number to sit with, because a screenshot tool is used for work and the metadata describes when and from where each capture was taken even where the image itself stayed private. Nobody uploading a screenshot of a dashboard thought of it as a disclosure. The Hacker News has the breach.

Operator Note: Screenshot and clipboard tools are installed by individuals and never appear in a software register, so add them to the list you ask about when you inventory what your teams actually use.

Additional Security Alerts

Patches

  • An Unbound DNSSEC validator flaw allows remote code execution: A malicious DNS zone can reach the resolver, which sits in a position every query passes through. The Hacker News
  • BIND 9 fixed fourteen flaws including an unauthenticated crash: The crash arrives over DNS-over-HTTPS, which is the transport most likely to be permitted outbound without inspection. The Hacker News
  • A Docker Sandboxes flaw lets guest code reach macOS host files: Malicious code inside the sandbox can read and modify files on the host, which is the boundary the product exists to provide. The Hacker News

Policy and Enforcement

  • CISA is urging critical infrastructure operators to plant decoys: The guidance recommends deception inside networks, which is a notable shift from perimeter advice toward assuming the attacker is already past it. Infosecurity Magazine
  • The US seized the NightmareStresser domains: The DDoS-for-hire platform was linked to hundreds of thousands of attacks before the takedown. The Hacker News
  • OpenAI disclosed six model incidents: The report covers hidden failures and unauthorized uploads by agents, continuing the run of provider-published misuse accounting. The Hacker News

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)