Cisco ISE Emergency Patch, Microsoft’s Record 974 Flaws, & Boston Scientific Disruption
This Week in Cybersecurity (TWiC), infrastructure and supply chains faced relentless pressure from high-severity disclosures and real-world operational halts.
granting unauthenticated root
patched in a single cycle
for federal agencies
Cisco issued emergency updates for a maximum-severity zero-day in its Identity Services Engine (ISE) that grants unauthenticated root access and is actively exploited in the wild. Microsoft set a new record by patching 974 vulnerabilities in a single cycle, including two exploited privilege escalation zero-days and 20 wormable bugs. Meanwhile, medical technology leader Boston Scientific suffered a cyberattack that caused a global operational network outage, crippling order processing, manufacturing, and shipping workflows.
Cisco ISE Zero-Day
CVE-2026-76460 / CVSS 10.0 / ISE and ISE-PIC · CISA KEV / 3-day federal deadline
Cisco released emergency patches for CVE-2026-76460, a 10.0 CVSS zero-day in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) that is actively exploited and grants unauthenticated root access. The flaw stems from insufficient authentication controls on an API endpoint, enabling unauthenticated remote attackers to bypass the web management interface via crafted requests. Active exploitation prompted CISA to add the vulnerability to its Known Exploited Vulnerabilities catalog with a tight three-day remediation deadline for federal agencies.
Because successful exploitation gains root privileges on the device, threat actors can alter or delete telemetry to cover their tracks.
access.log or running checks on ise-kong/access.log for suspicious entries may find cleared trails.Beyond this zero-day, Cisco released fixes for 77 total CVEs, including 21 critical flaws across ISE and 28 across its Secure Firewall suite.
Insights & Recommendations
- Validate local logs for anomalies, but rely heavily on upstream network and firewall logs to detect unexpected egress traffic or file transfers.
- Implement infrastructure Access Control Lists (iACLs) immediately to restrict management plane access to trusted sources only.
- Given the root level access granted, removing persistence requires re-imaging affected nodes and restoring from clean, verified configuration backups.
How nGuard Helps
- Continuous Vulnerability Management identifies unpatched network edge and identity infrastructure before threat actors can.
- External Penetration Testing verifies whether management interfaces like ISE are exposed to the public.
- If suspicious command execution or log wiping is observed, engaging Cybersecurity Incident Response ensures proper containment and forensically sound recovery.
Microsoft Patches Record 974 Flaws, Including Two Exploited Zero-Days
CVE-2026-85880 / CVSS 7.8 / ALPC heap overflow · CVE-2026-81963 / CVSS 7.8 / Update Stack
Microsoft delivered its largest security update on record, patching 974 vulnerabilities across Windows, Office, SQL Server, and enterprise platforms. The increase in disclosures reflects the growing use of automated and AI-assisted vulnerability discovery tools, pushing 2026 totals past 2,700 resolved bugs. Among the disclosures are over 110 Critical-rated bugs and 20 wormable remote code execution flaws.
Where to start in 974 patches
Bars show priority order, not scale. The two exploited zero-days go first.
The update resolves two actively exploited privilege escalation zero-days rated CVSS 7.8. CVE-2026-85880 is a heap buffer overflow in Windows Advanced Local Procedure Call (ALPC) that allows attackers executing code in a low-privilege AppContainer sandbox to break out and obtain SYSTEM access. CVE-2026-81963 is an improper link resolution defect in the Windows Update Stack, also allowing local elevation to SYSTEM. Both vulnerabilities have been added to CISA’s KEV catalog.
Insights & Recommendations
- Do not treat all 974 CVEs equally. Focus immediate deployment efforts on the two active zero-days (CVE-2026-85880 and CVE-2026-81963) and external-facing infrastructure like Exchange Server, Remote Desktop Services, and SQL Server.
- Massive disclosure cycles are creating administrative fatigue. Focus on contextual exploitability, asset exposure, and system criticality rather than chasing raw numbers.
How nGuard Helps
- Continuous Vulnerability Management provides continuous asset discovery and risk prioritization to filter out background noise from actionable threats.
- A Strategic Security Assessment evaluates patch management and asset management processes, turning overwhelming update cycles into a structured, risk-based cadence.
Cyberattack Causes Global Operational Disruption at Boston Scientific
Disclosed via / SEC filing · Impact / Core IT systems and business applications
Medical device giant Boston Scientific suffered a cyberattack that forced a network outage and caused global disruptions to its operations. Disclosed in SEC filings, the incident impacted core IT systems and business applications, disabling the company’s ability to process and ship customer orders, as well as halting sterilization and manufacturing workflows in facilities across the globe.
Halted
- Customer order processing
- Order shipping
- Sterilization workflows
- Manufacturing workflows
Backlogged
- New device activations
- Global supply lines
Kept Running
- Remote patient monitoring devices
- Patient data transmission
The attack shows the operational consequences when corporate IT breaches ripple into manufacturing, distribution, and logistics supply chains. While remote patient monitoring devices remained operational and data transmission continued safely, new device activations and global supply lines faced significant backlogs. Boston Scientific activated incident response protocols with third-party experts to contain the threat, isolate networks, and rebuild systems over a multi-week recovery effort.
Insights & Recommendations
- Isolate administrative IT networks from distribution, fulfillment, and manufacturing networks to prevent a corporate domain compromise from shutting down core operations.
- Ensure operational continuity by regularly backing up critical operational databases offline and testing manual order, inventory, and fulfillment procedures.
How nGuard Helps
- Tabletop Exercises evaluate executive and operational readiness during complex cyber disruptions, testing capabilities and incident communications.
- Web Application Testing and Internal Penetration Testing identify attack vectors and lateral movement paths before attackers can pivot into critical business applications.
Wrap
Whether dealing with zero-days in identity management engines, sorting through hundreds of monthly software patches, or managing global operational outages, modern cyber threats target core infrastructure and supply chain dependencies. Organizations must move beyond static patching assumptions by validating network segmentation, prioritizing risk-based remediation, and regularly exercising emergency incident response plans.
Not sure what you have exposed?nGuard validates it rather than assuming it, through penetration testing, configuration audits, and continuous vulnerability management.
Talk to nGuard
