INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Cisco Warns of Active Exploitation of Critical ISE Flaw
| 2026-10-01 12:00 HIGH MEDIUM EXPLOITED VULNERABILITY
Executive Summary
AI-generated
A critical authorization flaw has been discovered in the Meari IoT Cloud Platform OpenAPI Service, allowing authenticated users to manipulate device configurations they do not own. The vulnerability affects all versions of the service, with a CVSS score of 7.7 and identified by CVE-2026-101104 and CVE-2026-96613. This issue impacts commercial facilities, information technology, and industrial control systems sectors worldwide, particularly in China. CISA has reported these vulnerabilities to Gabriel Adams and provides resources for improving cybersecurity strategies. Organizations are encouraged to implement recommended defense-in-depth strategies to protect ICS assets.
Technical Mitigations AI-generated
• Implement role-based access control to restrict device configuration manipulation and unauthorized behavior.
• Use secure authentication mechanisms, such as multi-factor authentication (MFA), to verify the identity of users requesting access to sensitive information.
• Isolate Meari IoT Cloud Platform OpenAPI Service behind firewalls and ensure it is not accessible from the internet.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ac•••••.log
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-20176CVE-2026-20176
CVE-2026-20211CVE-2026-20211
CVE-2026-20284CVE-2026-20284
CVE-2025-20337CVE-2025-20337
CVE-2026-101104CVE-2026-101104
CVE-2026-20307CVE-2026-20307
CVE-2026-76460CVE-2026-76460
CVE-2026-76423CVE-2026-76423
CVE-2026-96613CVE-2026-96613
Target & Sectors
CN
manufacturingmanufacturing
Incident Timeline
July 2025
Threat actors exploited the Cisco ISE zero-day vulnerability CVE-2025-20337 to deploy a custom web shell disguised as an IdentityAuditAction component on the Meari IoT Cloud Platform OpenAPI Service.
Click on any entity below to view its context and source!
vulnerability
CVE-2025-20337
In July 2025,
threat actors exploited
another Cisco ISE zero-day (CVE-2025-20337)
with a maximum severity score
in remote code execution attacks to deploy a custom "IdentityAuditAction" web shell disguised as a legitimate ISE component.
tactic
Remote Code Execution
In July 2025,
threat actors exploited
another Cisco ISE zero-day (CVE-2025-20337)
with a maximum severity score
in remote code execution attacks to deploy a custom "IdentityAuditAction" web shell disguised as a legitimate ISE component.
September 16
Threat actors successfully exploited a vulnerability in the Meari IoT Cloud Platform OpenAPI service, allowing unauthorized access to affected devices via the web-based management interface.
2026/09/16
Threat actors used unpatched authentication bypass flaws in Cisco ISE-PIC to target the Meari IoT Cloud Platform OpenAPI Service.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-76460
Yesterday, Cisco patched a second maximum-severity authentication bypass flaw (CVE-2026-76423) and
five other critical security issues
(tracked as CVE-2026-76460, CVE-2026-20176, CVE-2026-20211, CVE-2026-20307, and CVE-2026-20284) in Cisco ISE and Cisco ISE-PIC, but they have not yet been flagged as actively exploited.
vulnerability
CVE-2026-76423
Yesterday, Cisco patched a second maximum-severity authentication bypass flaw (CVE-2026-76423) and
five other critical security issues
(tracked as CVE-2026-76460, CVE-2026-20176, CVE-2026-20211, CVE-2026-20307, and CVE-2026-20284) in Cisco ISE and Cisco ISE-PIC, but they have not yet been flagged as actively exploited.
vulnerability
CVE-2026-20176
Yesterday, Cisco patched a second maximum-severity authentication bypass flaw (CVE-2026-76423) and
five other critical security issues
(tracked as CVE-2026-76460, CVE-2026-20176, CVE-2026-20211, CVE-2026-20307, and CVE-2026-20284) in Cisco ISE and Cisco ISE-PIC, but they have not yet been flagged as actively exploited.
vulnerability
CVE-2026-20211
Yesterday, Cisco patched a second maximum-severity authentication bypass flaw (CVE-2026-76423) and
five other critical security issues
(tracked as CVE-2026-76460, CVE-2026-20176, CVE-2026-20211, CVE-2026-20307, and CVE-2026-20284) in Cisco ISE and Cisco ISE-PIC, but they have not yet been flagged as actively exploited.
vulnerability
CVE-2026-20307
Yesterday, Cisco patched a second maximum-severity authentication bypass flaw (CVE-2026-76423) and
five other critical security issues
(tracked as CVE-2026-76460, CVE-2026-20176, CVE-2026-20211, CVE-2026-20307, and CVE-2026-20284) in Cisco ISE and Cisco ISE-PIC, but they have not yet been flagged as actively exploited.
vulnerability
CVE-2026-20284
Yesterday, Cisco patched a second maximum-severity authentication bypass flaw (CVE-2026-76423) and
five other critical security issues
(tracked as CVE-2026-76460, CVE-2026-20176, CVE-2026-20211, CVE-2026-20307, and CVE-2026-20284) in Cisco ISE and Cisco ISE-PIC, but they have not yet been flagged as actively exploited.
organisation
Cisco ISE-PIC
Yesterday, Cisco patched a second maximum-severity authentication bypass flaw (CVE-2026-76423) and
five other critical security issues
(tracked as CVE-2026-76460, CVE-2026-20176, CVE-2026-20211, CVE-2026-20307, and CVE-2026-20284) in Cisco ISE and Cisco ISE-PIC, but they have not yet been flagged as actively exploited.
2026/10/01
Threat actors exploited a vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), tracked as CVE-2026-76460, to bypass authentication.
Click on any entity below to view its context and source!
organisation
Platform OpenAPI Service
Worldwide
Company Headquarters Location:
China
Vulnerabilities
Expand All +
The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own.
infrastructure
7.7
The following versions of Meari IoT Cloud Platform OpenAPI Service are affected:
IoT Cloud Platform OpenAPI Service vers:all/* (CVE-2026-101104, CVE-2026-96613)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.7
Meari
Meari IoT Cloud Platform OpenAPI Service
Missing Authorization
Background
Critical Infrastructure Sectors:
Commercial Facilities, Information Technology
Countries/Areas Deployed:
organisation
CVSS
The following versions of Meari IoT Cloud Platform OpenAPI Service are affected:
IoT Cloud Platform OpenAPI Service vers:all/* (CVE-2026-101104, CVE-2026-96613)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.7
Meari
Meari IoT Cloud Platform OpenAPI Service
Missing Authorization
Background
Critical Infrastructure Sectors:
Commercial Facilities, Information Technology
Countries/Areas Deployed:
organisation
Vendor
Equipment
The following versions of Meari IoT Cloud Platform OpenAPI Service are affected:
IoT Cloud Platform OpenAPI Service vers:all/* (CVE-2026-101104, CVE-2026-96613)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.7
Meari
Meari IoT Cloud Platform OpenAPI Service
Missing Authorization
Background
Critical Infrastructure Sectors:
Commercial Facilities, Information Technology
Countries/Areas Deployed:
organisation
Initial Release Date
Revision History
Initial Release Date:
2026-10-01
Date
Revision
Summary
2026-10-01
1
Initial Publication
Legal Notice and Terms of Use
infrastructure
146 TIP-12
Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.
organisation
Meari IoT Cloud Platform OpenAPI Service
Meari IoT Cloud Platform OpenAPI Service.
organisation
Affected Products
View CVE Details
Affected Products
Meari IoT Cloud Platform OpenAPI Service
Vendor:
Meari
Product Version:
organisation
Virtual Private Networks
When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available.
organisation
API
The flaw,
CVE-2026-76460
, is due to insufficient control on an API endpoint.
"This vulnerability is due to insufficient authentication control on an API endpoint.
organisation
Cisco ISE Passive Identity Connector
The security flaw (tracked as
CVE-2026-76460
) lets remote attackers bypass authentication by exploiting a weakness in an API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) regardless of configuration.
The vulnerability affects Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC), regardless of device configuration.
organisation
API of Cisco Identity Services Engine
The security flaw (tracked as
CVE-2026-76460
) lets remote attackers bypass authentication by exploiting a weakness in an API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) regardless of configuration.
organisation
CVE-2026-76460
"
Cisco also warned customers on Wednesday to secure their systems since its Product Security Incident Response Team (PSIRT) flagged CVE-2026-76460 as actively exploited.
organisation
Product Security Incident Response Team
"
Cisco also warned customers on Wednesday to secure their systems since its Product Security Incident Response Team (PSIRT) flagged CVE-2026-76460 as actively exploited.
infrastructure
3.1
Cisco ISE or ISE-PIC Release
First Fixed Release
3.1
3.1 Patch 12
3.2
3.2 Patch 11
3.3
3.3 Patch 12
3.4
3.4 Patch 7
3.5
3.5 Patch 4
Cisco shared indicators of compromise and advised security teams to look for suspicious usernames in access.log files on every node and "strongly" recommended re-imaging the nodes and restoring them from backups if malicious activity is suspected.
infrastructure
3.2
Cisco ISE or ISE-PIC Release
First Fixed Release
3.1
3.1 Patch 12
3.2
3.2 Patch 11
3.3
3.3 Patch 12
3.4
3.4 Patch 7
3.5
3.5 Patch 4
Cisco shared indicators of compromise and advised security teams to look for suspicious usernames in access.log files on every node and "strongly" recommended re-imaging the nodes and restoring them from backups if malicious activity is suspected.
infrastructure
3.3
Cisco ISE or ISE-PIC Release
First Fixed Release
3.1
3.1 Patch 12
3.2
3.2 Patch 11
3.3
3.3 Patch 12
3.4
3.4 Patch 7
3.5
3.5 Patch 4
Cisco shared indicators of compromise and advised security teams to look for suspicious usernames in access.log files on every node and "strongly" recommended re-imaging the nodes and restoring them from backups if malicious activity is suspected.
infrastructure
3.4
Cisco ISE or ISE-PIC Release
First Fixed Release
3.1
3.1 Patch 12
3.2
3.2 Patch 11
3.3
3.3 Patch 12
3.4
3.4 Patch 7
3.5
3.5 Patch 4
Cisco shared indicators of compromise and advised security teams to look for suspicious usernames in access.log files on every node and "strongly" recommended re-imaging the nodes and restoring them from backups if malicious activity is suspected.
infrastructure
3.5
Cisco ISE or ISE-PIC Release
First Fixed Release
3.1
3.1 Patch 12
3.2
3.2 Patch 11
3.3
3.3 Patch 12
3.4
3.4 Patch 7
3.5
3.5 Patch 4
Cisco shared indicators of compromise and advised security teams to look for suspicious usernames in access.log files on every node and "strongly" recommended re-imaging the nodes and restoring them from backups if malicious activity is suspected.
organisation
ISE-PIC Release
Cisco ISE or ISE-PIC Release
First Fixed Release
3.1
3.1 Patch 12
3.2
3.2 Patch 11
3.3
3.3 Patch 12
3.4
3.4 Patch 7
3.5
3.5 Patch 4
Cisco shared indicators of compromise and advised security teams to look for suspicious usernames in access.log files on every node and "strongly" recommended re-imaging the nodes and restoring them from backups if malicious activity is suspected.
organisation
Cisco Identity Services Engine
Cisco has warned customers of the active exploitation of a maximum severity flaw affecting its Cisco Identity Services Engine (ISE) product.
organisation
Cisco ISE
The vulnerability affects Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC), regardless of device configuration.
Cisco ISE is a centralized policy platform that IT administrators use to manage endpoints, users, and device access to network resources, often while enforcing Zero Trust security models.
organisation
Zero Trust
Cisco ISE is a centralized policy platform that IT administrators use to manage endpoints, users, and device access to network resources, often while enforcing Zero Trust security models.
organisation
Cisco Customers Told
Cisco Customers Told to Check for Signs of Exploitation
Cisco also recommended that ISE customers look for indicators of attempted exploitation of the vulnerability.
organisation
IP
This includes unexpected uploads that were initiated from the affected device to external IP addresses or downloads from malicious IP addresses.
Admins should also cross-check firewall and network logs for signs of suspicious activity (including downloads and uploads from and to external or malicious IP addresses) because attackers may remove evidence of exploitation after obtaining command execution with root
privileges.
organisation
Admins
Admins should also cross-check firewall and network logs for signs of suspicious activity (including downloads and uploads from and to external or malicious IP addresses) because attackers may remove evidence of exploitation after obtaining command execution with root
privileges.
organisation
Identity Services Engine
Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Tactical Metrics
Metrics
infrastructure
7.7
Software Version
Click for context!
The following versions of Meari IoT Cloud Platform OpenAPI Service are affected:
IoT Cloud Platform OpenAPI Service vers:all/* (CVE-2026-101104, CVE-2026-96613)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.7
Meari
Meari IoT Cloud Platform OpenAPI Service
Missing Authorization
Background
Critical Infrastructure Sectors:
Commercial Facilities, Information Technology
Countries/Areas Deployed:
Metrics
infrastructure
146
Tip-12
Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.
Metrics
infrastructure
3.1
Software Version
Cisco ISE or ISE-PIC Release
First Fixed Release
3.1
3.1 Patch 12
3.2
3.2 Patch 11
3.3
3.3 Patch 12
3.4
3.4 Patch 7
3.5
3.5 Patch 4
Cisco shared indicators of compromise and advised security teams to look for suspicious usernames in access.log files on every node and "strongly" recommended re-imaging the nodes and restoring them from backups if malicious activity is suspected.
Metrics
infrastructure
3.2
Software Version
Cisco ISE or ISE-PIC Release
First Fixed Release
3.1
3.1 Patch 12
3.2
3.2 Patch 11
3.3
3.3 Patch 12
3.4
3.4 Patch 7
3.5
3.5 Patch 4
Cisco shared indicators of compromise and advised security teams to look for suspicious usernames in access.log files on every node and "strongly" recommended re-imaging the nodes and restoring them from backups if malicious activity is suspected.
Metrics
infrastructure
3.3
Software Version
Cisco ISE or ISE-PIC Release
First Fixed Release
3.1
3.1 Patch 12
3.2
3.2 Patch 11
3.3
3.3 Patch 12
3.4
3.4 Patch 7
3.5
3.5 Patch 4
Cisco shared indicators of compromise and advised security teams to look for suspicious usernames in access.log files on every node and "strongly" recommended re-imaging the nodes and restoring them from backups if malicious activity is suspected.
Metrics
infrastructure
3.4
Software Version
Cisco ISE or ISE-PIC Release
First Fixed Release
3.1
3.1 Patch 12
3.2
3.2 Patch 11
3.3
3.3 Patch 12
3.4
3.4 Patch 7
3.5
3.5 Patch 4
Cisco shared indicators of compromise and advised security teams to look for suspicious usernames in access.log files on every node and "strongly" recommended re-imaging the nodes and restoring them from backups if malicious activity is suspected.
Metrics
infrastructure
3.5
Software Version
Cisco ISE or ISE-PIC Release
First Fixed Release
3.1
3.1 Patch 12
3.2
3.2 Patch 11
3.3
3.3 Patch 12
3.4
3.4 Patch 7
3.5
3.5 Patch 4
Cisco shared indicators of compromise and advised security teams to look for suspicious usernames in access.log files on every node and "strongly" recommended re-imaging the nodes and restoring them from backups if malicious activity is suspected.
Intelligence Sources
BleepingComputer
2026-09-17
Cisco warns of max severity ISE zero-day exploited in attacks
BleepingComputer
Infosecurity-Magazine
2026-09-17
Cisco Warns of Active Exploitation of Critical ISE Flaw
Infosecurity-Magazine
CISA Advisories
2026-10-01
Meari IoT Cloud Platform OpenAPI Service
CISA Advisories
CISA
2026-10-01
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-03T15:40
Comprehensive Tactical Telemetry
Highly Correlated Entities
27x
organisation
Identified Entity
Platform OpenAPI Service
entity
11x
attribution
Attributing Entity
CISA
Legal Notice and Terms of Use
authority
9x
vulnerability
Exploited CVE
CVE-2026-101104
cve
7x
general metric
Patch
3
patch
6x
infrastructure
Software Version
7.7
version
4x
timeline
Temporal Reference
2026/10/01
Date
Revision
Summary
2026
date
3x
industry
Targeted Sector
Technology
sector
2x
tactic
Cyber Operation Type
Ransomware
tactic
Contextual Telemetry
Context Block
9 METRICS
target region
Target Country
China
country
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
general metric
Meari Meari
8
meari meari
general metric
Summary Publication Legal Notice
10
summary publication legal notice
general metric
Initial Publication
1
initial publication
infrastructure
Tip-12
146
tip-12
source region
Origin Country
United States
country
general metric
Security Flaws
99
security flaws
general metric
Cisco
4
cisco
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.