Build1 publisher2 min readPublished
F5 and Cisco report live exploitation in two of the three security products Canada's Cyber Centre flagged
F5 and Cisco say attackers are exploiting flaws in BIG-IP APM and ISE, two of the three security products in Canada's September 2026 Cyber Centre alerts. Three alerts are too few to show a trend in attacker targeting, but the two exploited products need fixed software now.
The Engineer · Build desk

What happened
- The Cyber Centre's Forcepoint alert lists affected Security Engine versions but does not identify confirmed active exploitation of the policy bypass it describes.
- Three Cisco ISE and ISE-PIC flaws could allow authentication bypass, admin access, sensitive-data exposure and configuration changes, with CVE-2026-76460 the one Cisco named as exploited.
- Cisco says no workaround fully resolves the ISE issues, so installing the fixed software is the only remedy it offers.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- decision Forcepoint Security Engine owners can schedule their update behind the exploited F5 and Cisco work, though a first report of the bypass in use would remove that slack.
- constraint ISE owners have no configuration stopgap, so the upgrade has to be scheduled on the same system that decides which users and devices the network admits.
- exposure A compromised APM gateway puts an attacker without a login inside the device that controls remote access, a position the post says can be used to reach other systems.
F5 wrote the most useful line in the set. According to the dev.to summary of the alerts, its flaw needs an APM access policy and an OAuth profile on the same virtual server [6]. That means an operator can settle exposure from configuration alone: walk the virtual server list and flag any server that carries both objects. On a box that matches, an attacker with no valid login could run code and potentially take over the device [7]. F5 has reported exploitation in the wild [8]. I'd credit F5 for keeping the trigger that narrow, because it lets a team triage a fleet before the upgrade is even staged.
Two of the three alerts carry vendor-reported exploitation [1]. The dev.to post that collected them argues that what the products share is their position. Each one decides what traffic is allowed, who gets access and which devices are recognized [2]. The post also limits its own argument. "three advisories do not prove that attacks are becoming more advanced," it says [3]. I think that limit is right. The summary includes no attack counts or trend data. On that record, the September cluster justifies urgent work on three named products. It cannot show a change in what attackers prefer to target.
The post finds the operational risk somewhere duller than an exploit chain. It calls finding and fixing flaws normal vendor maintenance, and says the risk shows up when no one clearly owns the ongoing work [13]. The first job it lists as often unowned is keeping an inventory of security products and their versions [14]. The response sequence it recommends starts from that inventory [12]:
1. Identify the affected products. 2. Apply the vendor's update. 3. Check for signs of compromise. 4. Confirm the other security layers are still in place.
The list treats the compromise check as a separate step from the update [12]. On BIG-IP APM and ISE the vendors say attackers are already exploiting the flaws [8] [10], so I would not let the check slip behind the patch.
What to watch
- Whether Forcepoint ships fixed releases covering every Security Engine version on the Cyber Centre's list, since the alert advises updating as fixes become available.
- Any follow-up alert that adds exploitation reports for the two Cisco ISE flaws other than CVE-2026-76460, or for the Forcepoint bypass.