U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog
2026-09-16T02:51:38Z•d8d648a7de9555d8551c4ce695b2171f484961a753e09f78cad59679beec97cb
CVE-2026-42016CVE-2026-76461AI-enabled cyberattacksAPTCISA KEVCheck Point VPNChromeCisco Secure Email GatewayConnectWise ScreenConnectGitLabJFrog ArtifactoryLiteSpeed EnterpriseTelegram DesktopVPN breachWindowsactive exploitationcontainer escapedata exposureemail securityespionageprivilege escalationremote code executionroot accessstored XSSzero-day
What happened
SecurityAffairs reports widespread active exploitation and urgent vulnerability disclosures, led by the critical Cisco Secure Email Gateway zero-day CVE-2026-76461, which enables unauthenticated remote attackers to gain root access through crafted emails and has been added to CISA's KEV catalog. Additional coverage includes critical LiteSpeed Enterprise shared-hosting escape flaws, Chrome/Windows zero-day exploitation in China-linked espionage campaigns, a Telegram Desktop stored XSS issue affecting exported chats, a VPN breach exposing approximately 246,000 Japanese government records, and KE
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- d8d648a7de9555d8551c4ce695b2171f484961a753e09f78cad59679beec97cb
- Enrichment time
- 2026-09-16T02:51:38Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.