Daily briefing · September 14, 2026
Cisco Secure Email Under Active Exploitation as 58 Critical CVEs Surface
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
September 14, 2026 presents a relatively calm threat landscape by volume standards, yet one actively exploited vulnerability demands immediate attention: CVE-2026-76461, a CVSS 9.8 flaw in Cisco Secure Email Gateway that allows unauthenticated remote attackers to execute arbitrary commands as root. The day's 58 critical CVEs span major platforms including Apple iOS/iPadOS, Apache Storm, IBM DataStage, and low-level UEFI firmware parsers, offering attackers a wide menu of targets. Defenders should treat the Cisco KEV entry as the day's top priority while assessing exposure across the broader critical list.
Today’s brief
- KEV ALERT: CVE-2026-76461 in Cisco Secure Email Gateway enables unauthenticated root RCE — patch or mitigate immediately
- Apple iOS/iPadOS (CVE-2026-65414) carries a CVSS 9.8 out-of-bounds write allowing remote code execution across multiple Apple OS families
- Apache Storm (CVE-2026-82434, CVSS 10.0) leaks ZooKeeper credentials to read-only users, potentially enabling full cluster compromise
- UEFI firmware parser flaws (CVE-2026-54333/54334) expose systems to heap corruption via malformed firmware blobs — a stealthy, low-visibility attack vector
Critical highlights
1
Actively exploited and confirmed in CISA KEV, this unauthenticated root RCE in Cisco Secure Email Gateway's email parsing logic makes it the day's most urgent threat — any internet-facing Cisco Secure Email appliance should be treated as compromised until patched.
2
With a perfect CVSS 10.0, this Apache Storm flaw leaks ZooKeeper credentials to any user with read-only topology permissions, and since those credentials are reused across the cluster, exploitation can cascade into full infrastructure takeover.
3
Authenticated remote attackers on IBM DataStage (Cloud Pak for Data 5.4.0.0) can write arbitrary files anywhere on the system, a primitive that typically leads to privilege escalation or persistent backdoor installation in enterprise data pipeline environments.
4
An out-of-bounds write in iOS and iPadOS 26/27 and multiple macOS/tvOS/watchOS/visionOS releases allows a remote attacker to trigger app termination or arbitrary code execution, making unpatched Apple devices a significant target across consumer and enterprise fleets.
5
A heap array overflow in uefi-firmware-parser's Tiano decompression logic (prior to 1.14) can be triggered by a crafted firmware image, posing serious risk in any pipeline that processes untrusted BIOS or UEFI firmware blobs automatically.
6
A companion flaw to CVE-2026-54334 in the same uefi-firmware-parser library, this missing range validation in MakeTable() can corrupt memory when parsing malicious Tiano or EFI compressed sections — both issues should be patched together by upgrading to 1.14.
7
Insufficient validation of numeric fields and grid dimensions in resdata's GRDECL file parser can lead to memory corruption via malformed reservoir simulation data, a concern for energy sector organizations relying on Eclipse simulator toolchains.
8
ESPHome Device Builder Dashboard (prior to 1.0.12) silently drops authentication when environment variable names changed, effectively bypassing login controls — any internet-exposed ESPHome dashboard running an older version is effectively unauthenticated.
9
Part of Cisco's internal security review of Secure Email Gateway and Web Manager, this CVSS 9.8 flaw adds to the cluster of Cisco email platform vulnerabilities disclosed today — organizations should apply the hardening release addressing all Cisco Secure Email CVEs simultaneously.
10
A third CVSS 9.8 vulnerability disclosed as part of the same Cisco Secure Email internal audit, CVE-2026-76440 reinforces the need to treat the entire Cisco Secure Email product line as a priority patching target this cycle rather than addressing each CVE individually.
Ransomware today
Two Brazilian companies were recently identified as ransomware victims: Alicotrans, a transportation firm, was hit by the Qilin group, while Tuboaços da Amazônia Ltda., a manufacturer, fell to NightSpire. Over the past 30 days, thegentlemen has emerged as the most active group targeting Brazil with seven confirmed victims, followed by krybit (3), dragonforce, direwolf, emperador, and the emerging Vexy Ransomware operation — each registering multiple Brazilian victims.
Alicotrans BRqilin · Transportation
Tuboaços da Amazônia Ltda. BRnightspire · Manufacturing
thegentlemen 7krybit 3direwolf 2dragonforce 2emperador 2Vexy Ransomware 2
Active groups & APTs
Several threat actor groups are currently tracked as active: mosesstaff (Iranian-linked), siegedsec (Russian-linked), and sinobi, spacebears, thegentlemen, and funksec are all flagged as operationally active in current intelligence feeds. While no new confirmed victims are attributed to each group individually at this time, their active status signals ongoing reconnaissance or campaign preparation that defenders should monitor closely.
Brazil focus
Brazil continues to face an elevated ransomware tempo, with at least eight organizations victimized across sectors including transportation (Alicotrans), manufacturing (Tuboaços da Amazônia, Zanini, Alurwalls), technology (Logar Network Solutions), healthcare (amorsaude.com.br), retail (Biotipo Jeans), and other sectors (Mutant) in recent weeks. The breadth of targeted industries and the involvement of multiple distinct ransomware groups — including lockbit5, thegentlemen, Vexy Ransomware, Dark Project, and Qilin — underscores that Brazilian organizations across all verticals remain high-value targets for both established and emerging threat actors.
Alicotransqilin · Transportation
Tuboaços da Amazônia Ltda.nightspire · Manufacturing
Logar Network SolutionsVexy Ransomware · Technology
amorsaude.com.brlockbit5 · Healthcare
Biotipo Jeansthegentlemen · Retail & E-Commerce
Zaninithegentlemen · Manufacturing
Mutantthegentlemen · Other
AlurwallsDark Project · Manufacturing
Today’s recommendation: Prioritize patching CVE-2026-76461 and the related Cisco Secure Email CVEs (CVE-2026-76443, CVE-2026-76440) immediately, as the KEV designation confirms active in-the-wild exploitation; simultaneously audit exposure to CVE-2026-82434 in Apache Storm environments and apply the Apple security updates for CVE-2026-65414 across all managed iOS, macOS, and watchOS devices.
With actively exploited vulnerabilities in widely deployed email security infrastructure and a broad set of critical flaws spanning cloud platforms, mobile OSes, and firmware parsers, now is the moment to validate whether your organization's asset inventory and patch prioritization processes would catch these exposures before attackers do.Don’t wait to become a statistic: validate today, at no cost, whether any of these vectors reach your systems.Meet the Autonomous AI Pentest Agent →Previous briefings
September 20, 2026 — Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026 — Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026 — WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026 — Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026 — Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026 — Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026 — Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026 — WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026 — WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026 — GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026 — Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026 — Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →