- Previously exploited Cisco AsyncOS flaw
- Other critical vulnerability affecting Secure Email Gateway
- Cisco Secure Email Gateway zero-day vulnerability
- Other critical vulnerability affecting Secure Email Gateway
- Other critical vulnerability affecting Secure Email Gateway
- Other critical vulnerability affecting Secure Email Gateway
ThreatNoir Afternoon Brief — September 15
Afternoon Review in IT Security — September 15, 2026
The afternoon security briefing for September 15, 2026, highlights critical vulnerabilities affecting major technology platforms, including active exploitation of Cisco infrastructure and coordinated attacks targeting non-governmental organizations. Organizations are urged to prioritize patching efforts across multiple vendors as threat actors continue to exploit zero-day flaws in widely deployed systems.
Cisco Patches Secure Email Gateway Zero-Day Exploited in Attacks
Cisco has issued urgent guidance for customers to patch a critical Secure Email Gateway zero-day vulnerability that threat actors have already begun exploiting in active attacks. The vulnerability allows unauthenticated attackers to execute arbitrary commands on the underlying operating system with root privileges, representing a severe threat to email infrastructure worldwide. Source: Cisco patches Secure Email Gateway zero-day exploited in attacks
Multiple CVE identifiers have been assigned to related flaws in this product family, including CVE-2025-20393, CVE-2026-20353, CVE-2026-76440, CVE-2026-76441, CVE-2026-76443, and CVE-2026-76461. The active exploitation of these vulnerabilities underscores the critical nature of immediate patching, particularly given the central role email gateways play in organizational security infrastructure.
Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation
Security researchers have confirmed that CVE-2026-76461, a root-level remote code execution vulnerability in Cisco Secure Email Gateway, is currently being exploited by threat actors in the wild. The vulnerability permits unauthenticated attackers to execute arbitrary commands with the highest system privileges, enabling complete system compromise. Source: Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation
Organizations operating Cisco Secure Email Gateway deployments face immediate risk and should treat this vulnerability as a priority-one patching requirement. The exploitation of this flaw has been documented across multiple threat campaigns, indicating widespread reconnaissance and attack attempts against vulnerable instances.
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
A Chinese threat actor tracked as UTA0560 has been conducting spear-phishing campaigns that exploit a coordinated chain of zero-day vulnerabilities in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE. The campaign, first observed on September 1, 2026, targeted multiple non-governmental organizations through social engineering and compromised infrastructure. Source: China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
Volexity's threat intelligence team identified the attack chain as leveraging CVE-2026-85046, CVE-2026-85880, and CVE-2026-87491 to establish persistent access on victim systems. The targeting of NGOs suggests a campaign focused on intelligence gathering and long-term network access, with the GRIMWEDGE backdoor enabling command execution and data exfiltration capabilities.
Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases
Apple has released iOS 27 and macOS Golden Gate 27, addressing a comprehensive set of 200 vulnerabilities across its operating system ecosystem. The updates resolve critical kernel vulnerabilities that could result in memory corruption, privilege escalation, denial of service, and unauthorized information disclosure. Source: Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases
The scope of this patch release reflects the ongoing discovery of security flaws in Apple's kernel and core system components. Users of both iOS and macOS platforms are strongly advised to apply these updates immediately to remediate exposure to the identified vulnerabilities.
Organizations should prioritize patching efforts across all affected platforms—Cisco email infrastructure, Google Chrome, Microsoft Windows, Apple iOS, and macOS—to address the convergence of active exploitation and newly disclosed vulnerabilities documented in today's threat landscape.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Vulnerability used to inject code into the Chrome browser process for arbitrary code execution.
- Vulnerability used to escape the browser sandbox.
- Vulnerability in Google Chrome used for arbitrary read/write within V8 sandbox.
- Root RCE zero-day in Cisco Secure Email Gateway
- Cisco Secure Firewall Management Center vulnerability exploited by Russian state-sponsored hackers and cybercriminals
- Cisco Secure Firewall Management Center vulnerability exploited by Russian state-sponsored hackers and cybercriminals
- Previous Cisco Secure Email Gateway vulnerability exploited by China-linked actors
- Memory corruption issue in CoreMedia framework in iOS.
- Medium-severity heap-based buffer overflow in Samba (within Heimdal) in macOS Tahoe 26.7.