Cyber Threat Brief — September 15 2026

⚠️ This report is AI-generated. Always validate findings.

1. Cisco ESA SQLi → Root RCE — CVE-2026-76461

TL;DR: Cisco advisory 2026-09-14 + CISA KEV same day: unauthenticated CVE-2026-76461 in AsyncOS email parsing on Secure Email Gateway (physical/virtual, any config) — crafted email with malicious SQL → root OS command execution (CVSS 9.8). No workarounds. Patch AsyncOS 15.5.5-014 / 16.0.4-302 / 16.5.0-780 (prefer 16.5.0-780). Federal KEV due 2026-09-17; forensic triage required.

What’s New:

  • Cisco PSIRT aware of ITW exploitation in September 2026; actor/campaign undisclosed; Secure Email Cloud already moved to 16.5.0-780
  • Not affected: Secure Email and Web Manager; Secure Web Appliance
  • Cisco IoC: on each cluster member, CLI grep -i "COPY.*TO PROGRAM" against IronPort mail_logs (default log name mail_logs) — any hit may indicate malicious SQL
  • Root can erase local IoCs — cross-check external firewall/network logs for unexpected uploads from the ESA to external IPs / downloads from malicious IPs
  • Cisco lists Snort SIDs 67109–67110; related critical AsyncOS CVEs (CVE-2026-76440/76441/20353/76443) disclosed same day with no ITW evidence

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
Cisco Secure Email Gateway AsyncOS < 15.5.5-014 (≤15.5), < 16.0.4-302 (16.0), < 16.5.0-780 (16.5) — CVE-2026-76461Vulnerable applianceT1190 / T1059CMDB / Cisco ESA web UI System Administration → System Upgrade / CLI versionUpgrade to fixed release (prefer 16.5.0-780); no workaround — if virtual + suspected compromise: forensics first, then rebuild on fixed image + rotate credentials/crypto material
IronPort mail_logs line matching COPYTO PROGRAM (Cisco example: grep -i "COPY.*TO PROGRAM")Exploit SQL / RCE indicatorT1190 / T1059Cisco ESA CLI / forwarded Syslog mail_logs (each cluster member)Alert any match; preserve logs off-box; assume root may wipe local evidence; open TAC for physical appliances
Snort / Talos SIDs 67109 and 67110 (Cisco advisory)Network IDS signaturesT1190Snort/Suricata IPSEnable/verify SIDs; alert + capture PCAP for crafted SMTP toward ESA
Outbound connection from ESA management/mail interface to unexpected external IP (upload/download)Post-exploit egressT1041 / T1105Perimeter firewall / NetFlow / proxy (logs outside the appliance)Hunt egress initiated by ESA IPs; block unknown destinations; correlate with mail_logs IoC window
CISA KEV CVE-2026-76461 due 2026-09-17 (BOD 26-04 forensic triage Yes)Compliance / patch SLAN/AVulnerability management / KEV trackerPatch by due date; complete BOD forensic triage before declaring clean

Detection

SourceRuleGap
Splunk ESCUNone — verified search for CVE-2026-76461 / AsyncOS / IronPort / Secure Email Gateway / COPY TO PROGRAM in mail_logsESCU SQL Injection with Long URLs reads Web datamodel URLs — would not catch ESA mail_logs SQL; no IronPort/AsyncOS analytic story
ElasticNone — verified search for ESA/AsyncOS/IronPort mail_logsPostgreSQL COPY PROGRAM Command Execution matches copy*to*program* on pgsql network_traffic — wrong product/log source vs Cisco ESA mail_logs
SigmaNone — verified search for CVE-2026-76461 / IronPort / AsyncOSSQL Injection Strings In URI is webserver GET access-log keywords — misses SMTP/email-parser path

Hunt hint: (1) Inventory all physical/virtual ESA; confirm AsyncOS ≥ fixed builds above. (2) On every cluster member: grep -i "COPY.*TO PROGRAM" on mail_logs; forward mail_logs off-box going forward. (3) Enable Snort 67109/67110. (4) Firewall: list connections sourced from ESA IPs to non-mail peers. On hit: treat as root compromise — preserve external logs, rotate credentials/certs, rebuild virtuals on 16.5.0-780, TAC for hardware.

Sources: Cisco SA cisco-sa-esa-inj-2bLVGmhX, CISA KEV alert 2026-09-14, The Hacker News, BleepingComputer, SecurityWeek, GitHub tracker


Status Updates

  • CVE-2026-85706 (GitLab) / CVE-2026-84869 (ScreenConnect) / PaperCut CVE-2026-81578/82078: CISA KEV due was 2026-09-14 — confirm remediation (GitLab 19.1.8/19.2.6/19.3.2; ScreenConnect clients ≥26.6.5 + remove TransferFiles; PaperCut AI-swarm hunts). Sep 12 · Sep 14 staging
  • MikroTrick CVE-2026-67277 / CVE-2026-86060: KEV due was 2026-09-13 — confirm RouterOS 7.24.2 / 7.23.4 / 6.49.21. Sep 6 · Sep 13 staging
  • Check Point CVE-2026-85102/85103: Dutch NCSC still imminent — LivePatch Take 24 / Jumbo R81.20 Take 166 / R82 Take 126 / R82.10 Take 44. Sep 11
  • CVE-2026-42016/42018 (JFrog): KEV due 2026-09-25 — continue POST /access/api/v1/aws/token/ + token:anonymous hunts. Sep 12
  • Chrome CVE-2026-85046 (due Sep 18) / Windows CVE-2026-81963+85880 (due Sep 22) / Chrome CVE-2026-87491 (due Sep 23): THN 2026-09-15 amplifies Volexity UTA0560 → GRIMWEDGE — block cloud.shinewrist.net, ocr.opusaccel.top, IP 206.166.251.164; hunt %TEMP%\msgbox.exe, wsc.dll sideload, scheduled task Windows Scheduled System, Chrome ext ID ckiknalbeplpcpofpnabcnhjcegckfei (LONGTALE). Sep 11 · Sep 9 · Volexity
  • CVE-2026-51990 / GRAYRABBIT (UNC3569): No material change — keep sgbiz: / Public 7z.dll / mail.uaiubifas.top hunts. Sep 14 staging
  • Storm-3121/3032 Passkey + SGLang CVE-2026-86793: No material change — keep prior hunts. Sep 13 staging