Five days since our last digest brought a steady run of actively-exploited KEV additions, a root-level Cisco mail gateway bug, and a state-sponsored spyware exposure. Here’s what’s new and still relevant for your patch queue.
Vulnerability watch: CISA adds a CVSS 10.0 Cisco ISE auth bypass and an actively exploited Acronis backup privilege-escalation flaw
CISA added two more actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog on September 16. CVE-2026-76460 (CVSS 10.0) is an authentication bypass in an API endpoint of Cisco Identity Services Engine — insufficient authentication control lets an unauthenticated remote attacker send a crafted request and gain unauthorized access to the device’s management interface entirely. Cisco says the flaw surfaced while resolving a TAC support case, meaning at least one customer environment was already compromised before the bug was identified. The same KEV batch adds CVE-2026-87886 (CVSS 7.8), an incorrect-default-permissions flaw in Acronis’s Backup plugin for cPanel & WHM (fixed builds: 1.9.3.1021+) and Plesk (1.8.11.638+). A low-privileged local user on a shared host can exploit the loose file permissions to escalate privileges with no user interaction required; Acronis confirmed exploitation “in limited, targeted attacks” against the cPanel plugin specifically. The federal remediation deadline for both is September 19. CISA — ISE · CISA — Acronis
If you run Cisco ISE anywhere in your identity infrastructure, treat CVE-2026-76460 as a today problem — a compromised ISE node means an attacker can rewrite network access policy and pull credentials for everything ISE authenticates. If you’re a hosting provider or MSP running Acronis’s cPanel plugin across shared tenants, patch before you do anything else this week; incorrect permissions on backup tooling is exactly the kind of bug that turns one compromised customer account into control of the whole box.
Vulnerability watch: A single crafted email gives root on Cisco Secure Email Gateway — exploited before the patch shipped
Cisco disclosed CVE-2026-76461 (CVSS 9.8) on September 14 after its PSIRT became aware of active exploitation. The bug is a SQL injection flaw in the email-parsing logic of AsyncOS Software for Cisco Secure Email Gateway: an unauthenticated remote attacker sends a single crafted email containing malicious SQL statements through an affected gateway, and the resulting injection chain leads to OS command execution with root privileges — no admin interface access and no authentication required. A compromised gateway gives an attacker a foothold to modify configuration, read everything the appliance has processed, establish persistence, or pivot further into the mail environment. Cisco shipped fixes in AsyncOS 15.5.5-014, 16.0.4-302, and 16.5.0-780, and is pushing customers toward 16.5.0-780 specifically. CISA added the CVE to its KEV catalog the same day. The Hacker News · Cisco PSIRT
Email gateways sit directly in your inbound attack surface by design, which makes an unauthenticated pre-auth RCE here especially dangerous — patch immediately rather than waiting for a maintenance window, and if you can’t patch today, check gateway logs for anomalous SQL error patterns or unexpected outbound connections since September 4, when related exploitation activity is believed to have started.
Threat intel watch: Iran’s CHOSEN BRICK spyware campaign against journalists and dissidents goes public
The UK’s NCSC, the FBI’s Internet Crime Complaint Center, and the Netherlands’ AIVD published a joint advisory on September 15 exposing an Iranian state-linked spyware family dubbed CHOSEN BRICK, active since at least 2025 against dissidents, activists, and journalists perceived as a threat to the Iranian government — including targets in the UK, US, and Netherlands. Delivery is social-engineering-driven: operators build rapport with a target on social media, often impersonating a known contact or the technical-support account of a messaging platform, then persuade the victim to install what looks like a legitimate app (Telegram, Adobe Flash Player, Norton Antivirus, and AI tools like Pictory and RunwayML have all been used as lures). Once installed, CHOSEN BRICK rides on Telegram’s own infrastructure as a command channel and exfiltrates contacts, messages, files, screenshots, and microphone audio. The advisory notes stolen material has already surfaced on pro-Iranian leak sites, which raises the physical-safety stakes for anyone targeted, not just the data-exposure risk. NCSC · Infosecurity Magazine
This isn’t a typical enterprise-network story, but it matters if your organization works with journalists, human-rights groups, or diaspora communities — CHOSEN BRICK’s lure pattern (a trusted-seeming contact pushing an app install) is exactly the social-engineering vector your security-awareness training should already be covering, and it’s worth a reminder to any at-risk contacts in your ecosystem this week.
Also noted
A member of the Scattered Spider group pleaded guilty. Ahmed Hossam Eldin Elbadawy of College Station, Texas entered a guilty plea to wire fraud conspiracy and aggravated identity theft tied to intrusions against dozens of organizations; prosecutors are now seeking forfeiture of 175 Bitcoin and 1,306 Ethereum (roughly $16.5M combined at current rates) traced to the scheme. Krebs on Security
Google patched an actively exploited Pixel flaw. CVE-2026-58704, an improper-authorization bug in Android/Pixel, was added to CISA’s KEV catalog on September 16 as a known attack vector; if you manage a fleet of Pixel devices, push the update. CISA
Browser patch stack. Chrome 153 closed 42 vulnerabilities including three rated critical, and Firefox’s same-week release fixed 73 bugs — both are routine but high-volume enough that any fleet still on auto-update-disabled builds is carrying real exposure.
Final thought
Two of today’s headline bugs — the Cisco ISE bypass and the Secure Email Gateway RCE — share a pattern with last week’s Cisco Firewall Management Center flaw: identity and mail infrastructure that sits at the center of trust decisions, hit by unauthenticated attackers before defenders even knew to look. If patch cycles are the only thing standing between “vulnerable” and “compromised” on your identity and email infrastructure, it’s worth checking whether your logging would actually catch exploitation in the gap. See our how-to guides or book a discovery call if you want help closing that gap.