Tuesday, September 15, 2026
Daily digest
Heavy vulnerability day: critical, actively-exploited flaws landed for Cisco Secure Email Gateway, GitLab, and VMware vCenter simultaneously — patch triage should be top priority today.
Cisco Secure Email Gateway Zero-Day Exploited for Root Command Execution
Cisco confirmed active exploitation of CVE-2026-76461, a critical (CVSS 9.8) flaw in AsyncOS Software for Secure Email Gateway caused by insufficient validation in email parsing logic. An unauthenticated remote attacker can execute commands as root. Cisco has released patches.
Why it matters: If Secure Email Gateway sits in your mail flow alongside M365 GCC High, this is a root-compromise-in-the-wild scenario — patch immediately and check logs for indicators.
CISA: Ransomware Gangs Now Exploiting Critical VMware vCenter RCE
CISA warned that ransomware operators have joined ongoing attacks against a critical VMware vCenter vulnerability patched in July. The flaw allows remote code execution and is now under wider criminal exploitation beyond the original threat actors.
Maximum-Severity GitLab Path Traversal Flaw Under Active Exploitation
CVE-2026-85706, a path traversal vulnerability scoring a perfect 10.0 CVSS, affects both GitLab Community and Enterprise Edition. CISA confirmed active exploitation days after the patch was released, with watchTowr observing scans of internet-facing instances.
Why it matters: If GitLab underpins any Ansible playbook or IaC repository in your CMMC-scoped environment, treat this as an immediate patch-and-audit item — path traversal at CVSS 10 can expose CUI-adjacent source and secrets.
Sandworm Chains Cisco Vulnerabilities to Redeploy Cyclops Blink Botnet
The Russian state-linked Sandworm group is exploiting Cisco vulnerabilities to spread an upgraded version of the Cyclops Blink botnet malware, which the FBI previously disrupted in 2022. The activity marks a resurgence of the malware with new capabilities.
Why it matters: Cyclops Blink historically targets edge networking gear (routers/firewalls); confirm Cisco device patch levels on your perimeter, especially anything facing GovCloud or M365 GCC High connectivity.
New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing
Researchers disclosed DDRop, a hardware attack that silently drops writes to server memory, causing the processor to read stale encrypted data as current, defeating Intel TDX and AMD SEV-SNP confidential computing protections. The attack requires an adversary who already controls server software and briefly has physical access to insert a small circuit.
Why it matters: If your self-hosted AI stack relies on confidential computing enclaves for model or data isolation, this undermines a core assumption — physical access controls on host hardware become the real mitigation, not the enclave itself.
China-Linked Actor Exploits Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE Backdoor
A Chinese threat cluster tracked as UTA0560 is using a spear-phishing campaign exploiting recently patched Chrome and Windows flaws to deliver a JavaScript backdoor called GRIMWEDGE. Volexity observed the activity targeting NGOs starting September 1, 2026.
Why it matters: Confirm the referenced Chrome and Windows patches are fully deployed across your Intune-managed Windows 11 fleet — this chain targets endpoints already patched by vendors but not yet updated in the field.
Mass-Scanning Campaign Exploits Vite Flaw to Steal AWS and Azure Credentials
F5 Labs disclosed an automated scanning campaign targeting internet-exposed Vite development servers to extract cloud credentials, configuration data, and infrastructure state files from AWS and Azure instances. The campaign appears broad and opportunistic against exposed dev environments.
Why it matters: Verify no dev/test Vite servers are exposed outside your AWS GovCloud VPC boundaries — leaked credentials or Terraform state files here could cascade into a CUI-scope compromise.
Microsoft Ships Emergency Out-of-Band Windows Updates to Fix RDS Failures
Microsoft released emergency updates to address Remote Desktop Services failures, along with Hyper-V and USB audio issues, introduced by this month's Windows security updates. The fixes are out-of-band and separate from the regular Patch Tuesday cycle.
Why it matters: If RDS or Hyper-V is part of your Nutanix AHV or Windows 11 Intune deployment path, hold or re-sequence this month's patch rollout until the emergency fix is validated in a test ring.
Microsoft Confirms September Excel Update Breaks Copy-and-Paste
Microsoft confirmed that the September 2026 KB5002914 security update can cause copy-and-paste to silently fail for some Excel users. No workaround or fix timeline has been published yet.
Why it matters: Expect helpdesk tickets from GCC High users after this update lands — worth a heads-up notice to end users before it rolls out broadly.
AWS Publishes Security Reference Architecture Deep Dive for PCI DSS
AWS released an extension to its Security Reference Architecture providing prescriptive, architecture-level guidance for organizations storing, processing, or transmitting cardholder data on AWS. The guide builds on the core AWS SRA framework.
Why it matters: Even without PCI scope, the underlying AWS SRA control mappings are a useful cross-reference when documenting AWS GovCloud architecture for NIST 800-171 SSP evidence.
Cyber AB's Matthew Travis Calls for CMMC Transition Plan Amid Pentagon Reform
As the Pentagon reconsiders elements of the CMMC program, Cyber AB CEO Matthew Travis is pushing for a formal transition plan to preserve program momentum. The discussion comes amid ongoing uncertainty about the shape of CMMC rollout timelines.
Why it matters: Any transition plan changes could shift assessment timelines or requirements for your CMMC L2 certification path — worth monitoring closely before committing to a C3PAO assessment date.
Pentagon Issues Formal Procedures for AI-Assisted Software Development
DoD CIO Kirsten Davies signed guidance on "Accelerated Mission Software" governing AI-assisted software development practices, effective September 8, 2026. The procedures set formal expectations for how AI tools may be used in DoD software delivery pipelines.
Why it matters: If you support DoD software delivery or use AI-assisted coding (e.g., Copilot) on contract work, this guidance may define new documentation or approval requirements applicable to your development environment.