Patch Order Should Follow the Intrusion Chain, Not the CVSS Column
Three of the exploited products covered here distribute trust downstream, which is why a clean patch closes none of them — and why seven of them will not trigger your remediation SLA at all.
CVE-2026-76460 scores CVSS 10.0: unauthenticated, network-reachable, low-complexity. Identity Services Engine stores RADIUS shared secrets for switches and wireless controllers, TACACS+ keys, pxGrid/ERS/OpenAPI credentials, device and EAP certificates, and in most deployments an Active Directory join account. Post-compromise, every network device that trusts ISE trusts whoever walked out with that set. Remediation runs in two parts: patch every node persona (PAN, MnT, PSN) out of band, then rotate the entire credential set and re-issue certificates.
Confirmed exploitation now reaches the management plane
The CISA catalog additions chain. ConnectWise ScreenConnect (CVE-2026-84869, CVSS 9.9, KEV 09-11) gives remote access and remote execution on managed endpoints. N-able N-central (CVE-2026-86218, KEV 09-08) gives mass RMM deployment. Citrix NetScaler (CVE-2026-19490, KEV 09-09) gives perimeter auth bypass. Three Commvault flaws at CVSS 9.8 sit alongside them: CVE-2026-77089 API auth bypass, CVE-2026-77092 deserialization, CVE-2026-77098 SQL injection. That puts the recovery tier in scope.
ScreenConnect and N-central exist to push scripts and packages to endpoints. Patching blocks new access; admin accounts already created and deployments already queued survive it. Hunt session creation, new admin accounts and unexpected script pushes back to September 1 before closing the ticket.
Seven exploited CVEs a CVSS-keyed SLA will not see
Per the Internet Storm Center's tracking, NVD has not scored seven of these actively exploited entries: Cisco Secure Email Gateway SQL injection (CVE-2026-76461), two Chromium V8 flaws (CVE-2026-87491, CVE-2026-85046), MikroTik RouterOS (CVE-2026-86060, CVE-2026-67277), PaperCut (CVE-2026-82078, CVE-2026-81578), the Pixel modem privilege escalation (CVE-2026-58704), Adobe Commerce (CVE-2026-75650) and GitLab (CVE-2026-85706). A remediation trigger keyed to a CVSS threshold pulled from NVD will never fire on any of them while they are being exploited. Re-key priority on catalog membership.
Weaponization at five days, patching at 43
Wiz and watchTowr supply the velocity evidence from the adjacent build-infrastructure story: attackers hit internet-exposed instances four days after disclosure. Wiz's own customers, organizations funded enough to buy premium cloud security, sat at 49%, 62% and 59% unpatched at two, four and six weeks. Mandiant puts weaponization of new vulnerabilities at roughly five days. Verizon's DBIR 2026 puts median organizational patch time at 43 days. For CVE-2026-76460 the gap is negative, because exploitation preceded disclosure.
Closing a 38-day exposure window requires a pre-authorized emergency change lane for tier-0 identity, DNS and edge infrastructure.
The counterpoint is being sold hard, and part of it holds: severity scores genuinely do not tell you whether a flaw is reachable in your environment, and reachability-based prioritization is sound maturity work. It buys no deferral on the two patches already on the table. Vendor copy about AI-compressed timelines is marketing. Mandiant's five days and Verizon's 43 are the numbers the board needs.
What to do
Patch all Cisco ISE node personas out of band today, then rotate ISE admin passwords, RADIUS shared secrets, TACACS+ keys, pxGrid/ERS/OpenAPI credentials and the AD join account, and re-issue system and EAP certificates this week.
Hunt ScreenConnect and N-central for new admin accounts, anomalous session creation and unexpected script or package deployments back to September 1, before closing either patch ticket.
Re-key remediation SLAs to trigger on CISA catalog membership independent of CVSS within this sprint, and confirm the seven unscored exploited CVEs now land in the emergency queue.