By: Network-Switch.com | September 21, 2026
- 1. Quick Summary
- 2. Cisco Secure Email Gateway Zero-Day Enables Root Command Execution
- 3. Cisco ISE Zero-Day Is Actively Exploited as Major Hardening Release Lands
- 4. Splunk .conf26 Brings AI POD, Tokenomics and Network Intelligence
- 5. Native Splunk Expands Inside Cisco Nexus One
- 6. Cisco Begins UCS Manager End-of-Life Transition to Intersight
- 7. Network-Switch.com Observation
- 8. Frequently asked questions (FAQs)
- 9. Sources
Quick Summary
Cisco's most important developments from September 13-20 were split between urgent security remediation and a broader shift in infrastructure operations. Two actively exploited zero-days affected Secure Email Gateway and Identity Services Engine, while Splunk .conf26 introduced new AI, observability and network-intelligence capabilities. Cisco also expanded Native Splunk inside Nexus One and formally began the end-of-life transition from UCS Manager toward Intersight.
Cisco Secure Email Gateway Zero-Day Enables Root Command Execution
On September 14, Cisco disclosed CVE-2026-76461, a critical SQL injection vulnerability in the email-parsing logic of Cisco AsyncOS for Secure Email Gateway. The flaw is rated CVSS 9.8 and can be exploited remotely without authentication by sending a specially crafted email through an affected device.
A successful exploit can execute arbitrary SQL statements and lead to command execution with root privileges on the underlying operating system. Cisco confirmed active exploitation and released fixed software. There is no workaround that fully addresses the issue.
CSO, Network World, SecurityWeek and The Register independently reported on the flaw, emphasizing that the attack vector is particularly serious because the affected product is itself responsible for inspecting inbound email.
Network-Switch.com view: Secure email appliances should be treated as high-value infrastructure, not passive filtering boxes. Teams should patch immediately, review compromise indicators, validate management access and treat any confirmed breach as an incident-response problem rather than assuming a software update removes persistence.
Cisco ISE Zero-Day Is Actively Exploited as Major Hardening Release Lands
On September 16, Cisco disclosed CVE-2026-76460, a maximum-severity authentication-bypass vulnerability affecting Cisco Identity Services Engine and ISE Passive Identity Connector. The flaw is rated CVSS 10.0 and can allow an unauthenticated remote attacker to bypass the web-based management interface through a crafted API request.
Cisco confirmed active exploitation. The same September 16 security cycle also included a large ISE hardening release covering multiple additional critical and high-severity vulnerabilities involving authentication, remote command execution, command injection, SQL injection, path traversal, cross-site scripting and RADIUS denial of service.
SC Media, Dark Reading, CSO and The Register separately covered the exploited zero-day. Cisco's advisory states that no workaround fully addresses CVE-2026-76460, making fixed software the required remediation path.
Network-Switch.com view: ISE often sits at the center of enterprise identity and network-access policy. A compromise can therefore affect more than one appliance. Organizations should verify administrative access, API exposure, credential rotation, policy integrity and downstream integrations after patching, especially where ISE connects to switches, wireless controllers, VPN infrastructure and directory services.
Splunk .conf26 Brings AI POD, Tokenomics and Network Intelligence
Cisco used Splunk .conf26, held September 14-17 in Denver, to announce a broad set of AI and observability updates. Cisco AI POD for Splunk brings Splunk AI capabilities to self-managed and air-gapped environments using Cisco infrastructure and NVIDIA acceleration.
Splunk Agent Observability now includes Tokenomics for tracking AI-agent and coding-agent consumption and cost. Cisco also introduced Observability Studio and the Network Intelligence App, which brings Cisco network topology, device health and event data into Splunk so operations teams can connect application alerts with network context.
Network World reported that the Network Intelligence App is particularly relevant to network engineers because it allows Splunk users to investigate network conditions without constantly switching between operational tools. TechTarget also highlighted Cisco's broader strategy of using Splunk as the context and control layer for enterprise AI agents.
Network-Switch.com view: The practical value is cross-domain correlation. Application latency, wireless conditions, WAN paths, device events and AI-agent behavior often appear in separate tools. Enterprises evaluating these capabilities should confirm data-source coverage, retention cost, network-controller integration and whether the platform can only recommend actions or is authorized to execute them.
Native Splunk Expands Inside Cisco Nexus One
On September 16, Cisco detailed an expanded Native Splunk architecture inside Nexus One. The integration embeds containerized Splunk services on supported Nexus Dashboard hardware so network telemetry can be analyzed locally rather than exported first to a separate external analytics platform.
Cisco says the architecture has expanded from a single-node model to a multi-node deployment, allowing larger data-center and AI environments to keep more analytics close to the network. The design is intended to correlate NetOps, ITOps and SecOps workflows while supporting organizations that have data-sovereignty or on-premises operational requirements.
Network-Switch.com view: Embedding analytics closer to network telemetry can reduce troubleshooting time and external data movement, but capacity planning still matters. Teams should size Nexus Dashboard compute, storage, retention and telemetry volume around the actual number of devices and event rates instead of assuming the management platform is operationally unlimited.
Cisco Begins UCS Manager End-of-Life Transition to Intersight
Cisco announced the end-of-life roadmap for UCS Manager on September 15 after more than 17 years of the platform. Cisco positions Intersight Managed Mode as the strategic management path for future supported UCS generations and environments.
For UCS Manager Release 6.0, Cisco lists December 31, 2027 as the end-of-sale date, December 31, 2028 as the end of software maintenance releases and December 31, 2030 as the planned last date of support. Cisco also published separate EOL milestones for UCS Manager Release 4.3.
Cisco states that M8 will be the final server generation supported by UCS Manager. Future supported C-Series and X-Series systems connected through fabric interconnects are intended to use Intersight Managed Mode.
Network-Switch.com view: The announcement is a lifecycle-planning signal rather than an immediate hardware replacement requirement. UCS customers should inventory server generations, firmware dependencies, service profiles, fabric-interconnect compatibility and support contracts before deciding whether to migrate management mode, refresh hardware or keep an existing environment through its remaining support period.
Network-Switch.com Observation
This week's Cisco news connects two sides of infrastructure operations: security exposure and operational consolidation. Secure Email Gateway and ISE show how management and security systems can become high-value attack targets, while Splunk, Nexus One and Intersight show Cisco moving more telemetry, automation and lifecycle control into unified management platforms.
For enterprise buyers, the implication is straightforward: software lifecycle, management architecture and security remediation now matter as much as port count or throughput. BOM review should include controller versions, support dates, telemetry requirements, identity dependencies and recovery procedures before hardware is deployed.
Frequently asked questions (FAQs)
What is CVE-2026-76461 in Cisco Secure Email Gateway?
CVE-2026-76461 is a critical SQL injection vulnerability in Cisco AsyncOS email parsing. An unauthenticated remote attacker can exploit it with a crafted email to execute commands with root privileges on affected Secure Email Gateway appliances.
Is the Cisco Secure Email Gateway vulnerability being actively exploited?
Yes. Cisco said CVE-2026-76461 was under active exploitation when it disclosed the issue. Cisco released fixed software and stated that there is no workaround that fully addresses the vulnerability.
What is CVE-2026-76460 in Cisco ISE?
CVE-2026-76460 is a critical authentication-bypass vulnerability in an API of Cisco Identity Services Engine and ISE-PIC. It is rated CVSS 10.0 and Cisco confirmed active exploitation.
What did Cisco announce for Splunk at .conf26?
Cisco announced Cisco AI POD for Splunk, expanded Splunk Agent Observability with Tokenomics, Observability Studio, a Network Intelligence App, new agentic security operations capabilities and an expanded partnership with NVIDIA.
When does Cisco UCS Manager reach end of support?
Cisco announced UCS Manager end-of-life milestones on September 15, 2026. The end-of-sale date is December 31, 2027, software maintenance ends December 31, 2028, and the planned last date of support is December 31, 2030.
Sources
- Cisco Security Advisory - Cisco Secure Email Gateway SQL Injection Vulnerability, September 14, 2026; updated September 17, 2026.
- SecurityWeek - Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation, September 15, 2026.
- Network World - Critical Cisco Secure Email Gateway Zero-Day Gives Attackers Root Access, September 15, 2026.
- The Register - Cisco Email Security Boxes Can Be Rooted by an Email, September 15, 2026.
- Cisco Security Advisory - Cisco Identity Services Engine Authentication Bypass Vulnerability, September 16, 2026.
- Cisco Security Advisory - Cisco Identity Services Engine Hardening Release: September 2026, September 16, 2026.
- SC Media - Cisco Patches 10.0 ISE Bug Exploited in the Wild, September 17, 2026.
- Dark Reading - Cisco Zero-Day Highlights API Endpoint Authentication Issues, September 18, 2026.
- The Register - Cisco Drops Another Exploited Zero-Day, This Time a Perfect 10, September 17, 2026.
- Cisco Newsroom - Cisco Delivers Trusted AI at Scale Through New Splunk Advancements, September 15, 2026.
- Network World - Cisco Brings Splunk AI On Premises, Expands Agent Observability, Monitors Token Costs, September 15, 2026.
- Network World - Splunk .conf26: What Network Engineers Need to Know, September 15, 2026.
- TechTarget - Splunk .conf26: Context and Control for Cisco's AI Agents at Scale, September 17, 2026.
- Cisco Blogs - Native Splunk Brings Real-Time Insights to Cisco Nexus One, September 16, 2026.
- Cisco Blogs - Cisco UCS Manager: Celebrating the Legacy, Shaping the Future with Cisco Intersight, September 15, 2026.
- Cisco - End-of-Sale and End-of-Life Announcement for Cisco UCS Manager Release 6.0, September 15, 2026.
- Cisco - UCS Manager End-of-Life FAQ, September 15, 2026.