(TLP CLEAR) Weekly Vulnerabilities to Prioritize – September 17, 2026
Created: Thursday, September 17, 2026 - 15:41
Categories: Cybersecurity, Security Preparedness
The below vulnerabilities have been identified by WaterISAC analysts as important for water and wastewater utilities to prioritize in their vulnerability management efforts. WaterISAC shares critical vulnerabilities that affect widely used products and may be under active exploitation. WaterISAC draws additional awareness in alerts and advisories when vulnerabilities are confirmed to be impacting, or have a high likelihood of impacting, water and wastewater utilities. Members are encouraged to regularly review these vulnerabilities, many of which are often included in CISA’s Known Exploited Vulnerabilities (KEV) Catalog.
Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
CVSS v3.1: 10.0
CVE: CVE-2026-76460
Description: A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5
VMware vCenter directory-traversal vulnerability
CVSS v3.1: 9.8
CVEs: CVE-2026-59310
Description: VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
Source: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
CVSS v3.1: 10.0
CVEs: CVE-2026-85706
Description: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://www.cve.org/CVERecord?id=CVE-2026-85706
Check Point Vulnerabilities
CVSS v3.1: 9.8, 9.8
CVEs: CVE-2026-85103, CVE-2026-85102
Description: A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems. And a improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
Sources:
