Cisco Secure Email Gateway · Apache Storm Nimbus/Client · IBM DataStage on Cloud Pak for Data
Date: 2026-09-15 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership
Executive Summary
CISA added CVE-2026-76461 to the Known Exploited Vulnerabilities catalog after confirming active exploitation of an unauthenticated Cisco Secure Email Gateway SQL-injection flaw that can lead to root-level command execution. New EUVD records also identify critical issues in Apache Storm, IBM DataStage, Langflow and WHMCS. German BSI reporting includes a new high-severity PCRE2 advisory and updates to multiple Linux, GNU libc and enterprise-software advisories.
Critical Vulnerabilities
CVE-2026-76461 — Cisco Secure Email Gateway
- Severity: CVSS 9.8
- EPSS: Not supplied
- Technical detail: Cisco AsyncOS email-parsing functionality contains a SQL-injection vulnerability exploitable by an unauthenticated remote attacker. Successful exploitation can result in arbitrary command execution with root privileges on the underlying appliance. Multiple Cisco Secure Email software trains are affected.
- Exploitation status: NEW — actively exploited; added to CISA KEV on 2026-09-14. CISA remediation deadline is 2026-09-17.
- Remediation: Apply the Cisco security update immediately and confirm the running AsyncOS version is fixed. If patching cannot be completed before the deadline, restrict management and mail-processing exposure where feasible, monitor appliance processes and outbound connections, and investigate for unauthorized accounts, configuration changes or command execution.
CVE-2026-82434 — Apache Storm Nimbus/Client
- Severity: CVSS 10.0
- EPSS: 0 — no elevated exploitation probability supplied
- Technical detail: In Apache Storm 3.0.0 through versions before 3.1.0, topology configuration can retain ZooKeeper authentication material. Nimbus may subsequently serve sensitive authentication payloads through topology-related functionality. The exposure is most relevant to Storm clusters where topology or administrative interfaces are reachable by insufficiently trusted users or services.
- Exploitation status: NEW — no confirmed exploitation supplied.
- Remediation: Upgrade Apache Storm components to 3.1.0 or the vendor-recommended fixed release. Review Storm topology configurations and Nimbus access logs, rotate ZooKeeper credentials if exposure is possible, and restrict cluster interfaces to trusted management networks.
CVE-2026-16338 — IBM DataStage on Cloud Pak for Data
- Severity: CVSS 9.9
- EPSS: 0 — no elevated exploitation probability supplied
- Technical detail: IBM DataStage on Cloud Pak for Data 5.4.0.0 permits a remote authenticated attacker to perform arbitrary file writes through improper file-path validation. Exploitation requires valid access, but arbitrary writes in a data-processing platform may enable configuration tampering, persistence or follow-on code execution depending on service privileges.
- Exploitation status: NEW — no confirmed exploitation supplied.
- Remediation: Apply IBM’s fix for Cloud Pak for Data 5.4.0.0 and restrict DataStage access to authenticated, least-privileged users. Audit recently modified files, jobs and project configurations, and investigate unexpected activity by DataStage service accounts.
CVE-2026-12944 — IBM Langflow OSS
- Severity: CVSS 9.6
- EPSS: Not supplied
- Technical detail: Langflow OSS 1.0.0 through 1.10.0 allows attackers to submit crafted components containing socket or URL-handling imports, resulting in arbitrary Python-code execution with root privileges on the Langflow server. Internet-exposed development or AI workflow environments are at particular risk.
- Exploitation status: NEW — no confirmed exploitation supplied.
- Remediation: Upgrade to the vendor-fixed release when available and remove unnecessary internet exposure. Run the service as a non-root account, restrict component creation and execution privileges, review workflow definitions and server processes, and rotate credentials accessible from the host.
CVE-2026-67399 — WebPros WHMCS
- Severity: CVSS 9.3
- EPSS: Not supplied
- Technical detail: WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 contain an unsafe-deserialization flaw that permits remote attackers to execute arbitrary code. Internet-facing billing and customer-management installations should be treated as high-value targets because compromise may expose customer data, payment-related workflows and administrative credentials.
- Exploitation status: NEW — no confirmed exploitation supplied.
- Remediation: Upgrade to WHMCS 9.0.8, 8.13.7 or later as applicable. Restrict administrative access, review web and application logs for anomalous serialized requests or unexpected PHP activity, and rotate credentials and API keys if compromise is suspected.
ONGOING
CVE-2026-85706(GitLab CE/EE): actively exploited; patch immediately and investigate arbitrary-file access.CVE-2026-84869(ConnectWise ScreenConnect): active exploitation reported; remediation deadline has passed.CVE-2026-42016/CVE-2026-42018(JFrog Artifactory): actively exploited and reportedly chained; patch and rotate tokens.CVE-2026-67277/CVE-2026-86060(MikroTik RouterOS): actively exploited; restrict management interfaces.CVE-2026-75650(Adobe Commerce/Magento): actively exploited; hunt for web shells and payment-file changes.CVE-2026-86218(N-able N-central): actively exploited; upgrade to 2026.3.1.14 or later.CVE-2026-81963/CVE-2026-85880(Windows): actively exploited; complete September updates.CVE-2026-63520(Microsoft SharePoint): exploitation and public PoC reported; verify patching and hunt for web shells.CVE-2026-81578/CVE-2026-82078(PaperCut): exploitation reported; deploy current maintenance releases.
European Advisories
- BSI WID-SEC-2026-3334 is NEW for multiple high-severity PCRE2 vulnerabilities, including risks involving security-control bypass, memory corruption, information disclosure and denial of service. Update PCRE2 packages through the relevant operating-system or application vendor and assess applications that process attacker-controlled regular expressions.
- BSI issued updates for GNU libc, Linux Kernel, GitLab, Angular, libssh, CPython, Red Hat Enterprise Linux/OpenShift, Apache Tomcat, Go and GStreamer. Prioritize the GitLab update because active exploitation was already reported; the remaining updates should be correlated with installed package versions and exposure.
CVE-2026-76461is covered in Critical Vulnerabilities. CISA’s KEV advisory confirms active exploitation and a 2026-09-17 remediation deadline.- BSI reports that GitLab vulnerabilities were targeted shortly after disclosure. See the BSI assessment.
Active Threats and Campaigns
- GitLab exploitation — ONGOING: Active probing of
CVE-2026-85706continues; investigate traversal payloads and access to configuration, credential or runner files. - JFrog Artifactory exploitation — ONGOING: Attackers are reportedly chaining flaws to obtain administrator access and deploy Rust backdoors.
- GrayRabbit deployment through Sogou Input Method — ONGOING: Review vulnerable Tencent Sogou Input Method installations, endpoint persistence and suspicious process creation.
- Passkey-themed Microsoft 365 phishing — ONGOING: Hunt for unusual OAuth grants, unfamiliar authentication methods, impossible-travel events and suspicious mailbox access.
Security News and Context
- SANS ISC reports Apple’s annual platform update, covering 261 vulnerabilities across Apple operating systems. Accelerate updates for managed iOS, macOS, iPadOS and other Apple assets.
- BleepingComputer reports emergency Windows updates addressing Remote Desktop Services failures, Hyper-V issues and USB-audio problems caused by September updates. Validate production RDS environments before broad deployment.
Recommended Actions
- Patch or isolate Cisco Secure Email Gateway immediately; investigate for root-level compromise before remediation.
- Complete remediation of
CVE-2026-76461before the CISA deadline of 2026-09-17. - Identify Apache Storm, IBM DataStage, Langflow and WHMCS deployments and apply vendor fixes.
- Restrict internet access to Langflow, WHMCS, Storm and DataStage administrative interfaces.
- Review logs and file integrity for GitLab, Artifactory and other actively exploited systems.
- Validate September Windows updates and deploy Microsoft’s emergency fixes where RDS failures are present.
- Continue remediation of previously reported items: GitLab, ScreenConnect, Artifactory, RouterOS, Magento, N-central, Windows, SharePoint and PaperCut.