Daily briefing · September 14, 2026

Cisco Secure Email Under Active Exploitation as 58 Critical CVEs Surface

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

September 14, 2026 presents a relatively calm threat landscape by volume standards, yet one actively exploited vulnerability demands immediate attention: CVE-2026-76461, a CVSS 9.8 flaw in Cisco Secure Email Gateway that allows unauthenticated remote attackers to execute arbitrary commands as root. The day's 58 critical CVEs span major platforms including Apple iOS/iPadOS, Apache Storm, IBM DataStage, and low-level UEFI firmware parsers, offering attackers a wide menu of targets. Defenders should treat the Cisco KEV entry as the day's top priority while assessing exposure across the broader critical list.

Today’s brief
  • KEV ALERT: CVE-2026-76461 in Cisco Secure Email Gateway enables unauthenticated root RCE — patch or mitigate immediately
  • Apple iOS/iPadOS (CVE-2026-65414) carries a CVSS 9.8 out-of-bounds write allowing remote code execution across multiple Apple OS families
  • Apache Storm (CVE-2026-82434, CVSS 10.0) leaks ZooKeeper credentials to read-only users, potentially enabling full cluster compromise
  • UEFI firmware parser flaws (CVE-2026-54333/54334) expose systems to heap corruption via malformed firmware blobs — a stealthy, low-visibility attack vector
58
critical
1
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-76461KEVCVSS 9.8affects Cisco Secure Email
Actively exploited and confirmed in CISA KEV, this unauthenticated root RCE in Cisco Secure Email Gateway's email parsing logic makes it the day's most urgent threat — any internet-facing Cisco Secure Email appliance should be treated as compromised until patched.
2
CVE-2026-82434CVSS 10affects Apache Storm Client
With a perfect CVSS 10.0, this Apache Storm flaw leaks ZooKeeper credentials to any user with read-only topology permissions, and since those credentials are reused across the cluster, exploitation can cascade into full infrastructure takeover.
3
CVE-2026-16338CVSS 9.9affects DataStage on Cloud Pak for Data
Authenticated remote attackers on IBM DataStage (Cloud Pak for Data 5.4.0.0) can write arbitrary files anywhere on the system, a primitive that typically leads to privilege escalation or persistent backdoor installation in enterprise data pipeline environments.
4
CVE-2026-65414CVSS 9.8affects iOS and iPadOS
An out-of-bounds write in iOS and iPadOS 26/27 and multiple macOS/tvOS/watchOS/visionOS releases allows a remote attacker to trigger app termination or arbitrary code execution, making unpatched Apple devices a significant target across consumer and enterprise fleets.
5
CVE-2026-54334CVSS 9.8affects uefi-firmware-parser
A heap array overflow in uefi-firmware-parser's Tiano decompression logic (prior to 1.14) can be triggered by a crafted firmware image, posing serious risk in any pipeline that processes untrusted BIOS or UEFI firmware blobs automatically.
6
CVE-2026-54333CVSS 9.8affects uefi-firmware-parser
A companion flaw to CVE-2026-54334 in the same uefi-firmware-parser library, this missing range validation in MakeTable() can corrupt memory when parsing malicious Tiano or EFI compressed sections — both issues should be patched together by upgrading to 1.14.
7
CVE-2026-55209CVSS 9.8affects resdata
Insufficient validation of numeric fields and grid dimensions in resdata's GRDECL file parser can lead to memory corruption via malformed reservoir simulation data, a concern for energy sector organizations relying on Eclipse simulator toolchains.
8
CVE-2026-59178CVSS 9.8affects device-builder
ESPHome Device Builder Dashboard (prior to 1.0.12) silently drops authentication when environment variable names changed, effectively bypassing login controls — any internet-exposed ESPHome dashboard running an older version is effectively unauthenticated.
9
CVE-2026-76443CVSS 9.8affects Cisco Secure Email
Part of Cisco's internal security review of Secure Email Gateway and Web Manager, this CVSS 9.8 flaw adds to the cluster of Cisco email platform vulnerabilities disclosed today — organizations should apply the hardening release addressing all Cisco Secure Email CVEs simultaneously.
10
CVE-2026-76440CVSS 9.8affects Cisco Secure Email
A third CVSS 9.8 vulnerability disclosed as part of the same Cisco Secure Email internal audit, CVE-2026-76440 reinforces the need to treat the entire Cisco Secure Email product line as a priority patching target this cycle rather than addressing each CVE individually.
Ransomware today

Two Brazilian companies were recently identified as ransomware victims: Alicotrans, a transportation firm, was hit by the Qilin group, while Tuboaços da Amazônia Ltda., a manufacturer, fell to NightSpire. Over the past 30 days, thegentlemen has emerged as the most active group targeting Brazil with seven confirmed victims, followed by krybit (3), dragonforce, direwolf, emperador, and the emerging Vexy Ransomware operation — each registering multiple Brazilian victims.

Alicotrans BRqilin · Transportation
Tuboaços da Amazônia Ltda. BRnightspire · Manufacturing
thegentlemen 7krybit 3direwolf 2dragonforce 2emperador 2Vexy Ransomware 2
Active groups & APTs

Several threat actor groups are currently tracked as active: mosesstaff (Iranian-linked), siegedsec (Russian-linked), and sinobi, spacebears, thegentlemen, and funksec are all flagged as operationally active in current intelligence feeds. While no new confirmed victims are attributed to each group individually at this time, their active status signals ongoing reconnaissance or campaign preparation that defenders should monitor closely.

Brazil focus

Brazil continues to face an elevated ransomware tempo, with at least eight organizations victimized across sectors including transportation (Alicotrans), manufacturing (Tuboaços da Amazônia, Zanini, Alurwalls), technology (Logar Network Solutions), healthcare (amorsaude.com.br), retail (Biotipo Jeans), and other sectors (Mutant) in recent weeks. The breadth of targeted industries and the involvement of multiple distinct ransomware groups — including lockbit5, thegentlemen, Vexy Ransomware, Dark Project, and Qilin — underscores that Brazilian organizations across all verticals remain high-value targets for both established and emerging threat actors.

Alicotransqilin · Transportation
Tuboaços da Amazônia Ltda.nightspire · Manufacturing
Logar Network SolutionsVexy Ransomware · Technology
amorsaude.com.brlockbit5 · Healthcare
Biotipo Jeansthegentlemen · Retail & E-Commerce
Zaninithegentlemen · Manufacturing
Mutantthegentlemen · Other
AlurwallsDark Project · Manufacturing
Today’s recommendation: Prioritize patching CVE-2026-76461 and the related Cisco Secure Email CVEs (CVE-2026-76443, CVE-2026-76440) immediately, as the KEV designation confirms active in-the-wild exploitation; simultaneously audit exposure to CVE-2026-82434 in Apache Storm environments and apply the Apple security updates for CVE-2026-65414 across all managed iOS, macOS, and watchOS devices.
With actively exploited vulnerabilities in widely deployed email security infrastructure and a broad set of critical flaws spanning cloud platforms, mobile OSes, and firmware parsers, now is the moment to validate whether your organization's asset inventory and patch prioritization processes would catch these exposures before attackers do.Don’t wait to become a statistic: validate today, at no cost, whether any of these vectors reach your systems.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 20, 2026Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →
Share