U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog
2026-09-16T08:51:37Z•2dda4ed1d39b68b78eb74760e22f11f815cfc0265c63eb6406cbccaf17649ab4
CVE-2026-76461AI-enabled attacksCISA KEVCheck Point VPNChina-linked threat actorsChromeCisco Secure Email GatewayConnectWise ScreenConnectGitLabJFrog ArtifactoryLiteSpeed EnterpriseTelegram DesktopVPN vulnerabilitiesWindowsactive exploitationdata exposureemail securityespionageremote code executionroot accessshared hostingstored XSSzero-day
What happened
Security Affairs reports widespread high-impact vulnerability activity, including active exploitation of Cisco Secure Email Gateway zero-day CVE-2026-76461 (CVSS 9.8) for unauthenticated root access, CISA KEV additions affecting Cisco, GitLab, JFrog Artifactory, and ConnectWise ScreenConnect, and critical flaws in LiteSpeed Enterprise, Check Point VPN, Telegram Desktop, and a government VPN deployment. Additional reporting covers Chrome/Windows zero-day exploitation in China-linked espionage campaigns and the accelerating use of frontier AI in cyberattacks.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 2dda4ed1d39b68b78eb74760e22f11f815cfc0265c63eb6406cbccaf17649ab4
- Enrichment time
- 2026-09-16T08:51:37Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.