VulnOps
2026-09-17Three critical vulnerabilities affecting major identity and access control platforms were disclosed today, with Microsoft Entra ID experiencing active exploitation in the wild. Vulnops practitioners must prioritize assessment and patching of these authentication and RCE vulnerabilities across enterprise infrastructure.
- →Critical Microsoft Entra ID RCE (CVE-2026-69836) exploited in the wild: Active exploitation of this Entra ID vulnerability demands immediate vulnerability scanning and patch prioritization given its RCE severity and real-world attack activity.
- →Citrix NetScaler authentication bypass (CVE-2026-19490) requires urgent remediation: Critical authentication bypass in widely-deployed ADC appliances necessitates rapid vulnerability assessment and patching across gateway infrastructure.
- →Cisco ISE privileged API misuse vulnerability (CVE-2026-76460) enables authentication bypass: This identity services vulnerability requires practitioners to assess exposure in ISE deployments and understand the privileged API exploitation path.
Immediately initiate vulnerability scans for Entra ID, NetScaler, and Cisco ISE in your environment and establish patch timelines for these three critical authentication-layer vulnerabilities.
Help Net Security newsletters: Daily and weekly news, cybersecurity jobs, open source projects, breaking news – subscribe here! Please turn on your JavaScript for this page to function normally. Sinisa Markovic Sinisa Markovic, Managing Editor, Help Net Security Share # Microsoft patches critical Entra ID vulnerability (CVE-2026-69836) Microsoft has patched a critical remote code execution vulnerability (CVE-2026-69836) in Entra ID, initially reported to have been exploited in the wild.
Citrix has patched two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical authentication bypass flaw tracked as CVE-2026-19490, and is urging customers to upgrade affected appliances as soon as possible. [...] Help Net Security newsletters: Daily and weekly news, cybersecurity jobs, open source projects, breaking news – subscribe here! Please turn on your JavaScript for this page to function normally. Sinisa Markovic Sinisa Markovic, Managing Editor, Help Net Securit
Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.