Cyber Threat Brief — September 15 2026
1. Cisco ESA SQLi → Root RCE — CVE-2026-76461
TL;DR: Cisco advisory 2026-09-14 + CISA KEV same day: unauthenticated CVE-2026-76461 in AsyncOS email parsing on Secure Email Gateway (physical/virtual, any config) — crafted email with malicious SQL → root OS command execution (CVSS 9.8). No workarounds. Patch AsyncOS 15.5.5-014 / 16.0.4-302 / 16.5.0-780 (prefer 16.5.0-780). Federal KEV due 2026-09-17; forensic triage required.
What’s New:
- Cisco PSIRT aware of ITW exploitation in September 2026; actor/campaign undisclosed; Secure Email Cloud already moved to 16.5.0-780
- Not affected: Secure Email and Web Manager; Secure Web Appliance
- Cisco IoC: on each cluster member, CLI
grep -i "COPY.*TO PROGRAM"against IronPort mail_logs (default log namemail_logs) — any hit may indicate malicious SQL - Root can erase local IoCs — cross-check external firewall/network logs for unexpected uploads from the ESA to external IPs / downloads from malicious IPs
- Cisco lists Snort SIDs 67109–67110; related critical AsyncOS CVEs (CVE-2026-76440/76441/20353/76443) disclosed same day with no ITW evidence
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
| Cisco Secure Email Gateway AsyncOS < 15.5.5-014 (≤15.5), < 16.0.4-302 (16.0), < 16.5.0-780 (16.5) — CVE-2026-76461 | Vulnerable appliance | T1190 / T1059 | CMDB / Cisco ESA web UI System Administration → System Upgrade / CLI version | Upgrade to fixed release (prefer 16.5.0-780); no workaround — if virtual + suspected compromise: forensics first, then rebuild on fixed image + rotate credentials/crypto material |
IronPort mail_logs line matching COPY … TO PROGRAM (Cisco example: grep -i "COPY.*TO PROGRAM") | Exploit SQL / RCE indicator | T1190 / T1059 | Cisco ESA CLI / forwarded Syslog mail_logs (each cluster member) | Alert any match; preserve logs off-box; assume root may wipe local evidence; open TAC for physical appliances |
| Snort / Talos SIDs 67109 and 67110 (Cisco advisory) | Network IDS signatures | T1190 | Snort/Suricata IPS | Enable/verify SIDs; alert + capture PCAP for crafted SMTP toward ESA |
| Outbound connection from ESA management/mail interface to unexpected external IP (upload/download) | Post-exploit egress | T1041 / T1105 | Perimeter firewall / NetFlow / proxy (logs outside the appliance) | Hunt egress initiated by ESA IPs; block unknown destinations; correlate with mail_logs IoC window |
| CISA KEV CVE-2026-76461 due 2026-09-17 (BOD 26-04 forensic triage Yes) | Compliance / patch SLA | N/A | Vulnerability management / KEV tracker | Patch by due date; complete BOD forensic triage before declaring clean |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | None — verified search for CVE-2026-76461 / AsyncOS / IronPort / Secure Email Gateway / COPY TO PROGRAM in mail_logs | ESCU SQL Injection with Long URLs reads Web datamodel URLs — would not catch ESA mail_logs SQL; no IronPort/AsyncOS analytic story |
| Elastic | None — verified search for ESA/AsyncOS/IronPort mail_logs | PostgreSQL COPY PROGRAM Command Execution matches copy*to*program* on pgsql network_traffic — wrong product/log source vs Cisco ESA mail_logs |
| Sigma | None — verified search for CVE-2026-76461 / IronPort / AsyncOS | SQL Injection Strings In URI is webserver GET access-log keywords — misses SMTP/email-parser path |
Hunt hint: (1) Inventory all physical/virtual ESA; confirm AsyncOS ≥ fixed builds above. (2) On every cluster member: grep -i "COPY.*TO PROGRAM" on mail_logs; forward mail_logs off-box going forward. (3) Enable Snort 67109/67110. (4) Firewall: list connections sourced from ESA IPs to non-mail peers. On hit: treat as root compromise — preserve external logs, rotate credentials/certs, rebuild virtuals on 16.5.0-780, TAC for hardware.
Sources: Cisco SA cisco-sa-esa-inj-2bLVGmhX, CISA KEV alert 2026-09-14, The Hacker News, BleepingComputer, SecurityWeek, GitHub tracker
Status Updates
- CVE-2026-85706 (GitLab) / CVE-2026-84869 (ScreenConnect) / PaperCut CVE-2026-81578/82078: CISA KEV due was 2026-09-14 — confirm remediation (GitLab 19.1.8/19.2.6/19.3.2; ScreenConnect clients ≥26.6.5 + remove TransferFiles; PaperCut AI-swarm hunts). Sep 12 · Sep 14 staging
- MikroTrick CVE-2026-67277 / CVE-2026-86060: KEV due was 2026-09-13 — confirm RouterOS 7.24.2 / 7.23.4 / 6.49.21. Sep 6 · Sep 13 staging
- Check Point CVE-2026-85102/85103: Dutch NCSC still imminent — LivePatch Take 24 / Jumbo R81.20 Take 166 / R82 Take 126 / R82.10 Take 44. Sep 11
- CVE-2026-42016/42018 (JFrog): KEV due 2026-09-25 — continue
POST /access/api/v1/aws/token/+token:anonymoushunts. Sep 12 - Chrome CVE-2026-85046 (due Sep 18) / Windows CVE-2026-81963+85880 (due Sep 22) / Chrome CVE-2026-87491 (due Sep 23): THN 2026-09-15 amplifies Volexity UTA0560 → GRIMWEDGE — block
cloud.shinewrist.net,ocr.opusaccel.top, IP206.166.251.164; hunt%TEMP%\msgbox.exe,wsc.dllsideload, scheduled taskWindows Scheduled System, Chrome ext IDckiknalbeplpcpofpnabcnhjcegckfei(LONGTALE). Sep 11 · Sep 9 · Volexity - CVE-2026-51990 / GRAYRABBIT (UNC3569): No material change — keep
sgbiz:/ Public7z.dll/mail.uaiubifas.tophunts. Sep 14 staging - Storm-3121/3032 Passkey + SGLang CVE-2026-86793: No material change — keep prior hunts. Sep 13 staging