New KEV entry: Cisco Secure Email Gateway SQL injection
CISA added CVE-2026-76461, a SQL injection vulnerability in Cisco Secure Email Gateway, to the Known Exploited Vulnerabilities catalog on September 14. A KEV listing means confirmed exploitation in the wild, so this moves from patch eventually to patch now. If you run Cisco Secure Email Gateway on the perimeter, treat this as your first job today: identify affected appliances, confirm current firmware, and apply the fixed release.
This is a mail gateway sitting in front of inbound and outbound traffic. SQL injection there can expose configuration and stored data and give an attacker a foothold in a system most defenders assume is hardened. Do not wait for a maintenance window if you have not already patched.
Exploitation picture: worm-like ScreenConnect and JFrog backdoors
SecurityWeek reports ConnectWise has patched a ScreenConnect vulnerability that is being exploited in worm-like attacks, meaning it can spread across connected instances rather than needing one-by-one compromise. Remote management tools are high value, so if you run ScreenConnect, apply the vendor patch and review recent sessions for unexpected activity.
Separately, three JFrog Artifactory flaws are being exploited to deploy backdoors. Artifactory is core build and artifact infrastructure, so compromise there is a supply chain problem, not just one server. Patch and audit for unexpected artifacts or accounts.
The hottest KEV movers this week remain a set of critical perimeter and infrastructure bugs. CVE-2026-20079 in Cisco Firewall Management Center carries a CVSS of 10 with an EPSS around 0.76. Three ransomware-linked KEV entries stand out: SonicWall SMA1000 SSRF CVE-2026-15409, Broadcom VMware vCenter path traversal CVE-2026-59310, and WebPros cPanel and WHM missing authentication CVE-2026-41940, the last with an EPSS of 0.98. If any of these are in your estate, they belong at the top of the list.
What the press adds: Windows update fallout
BleepingComputer reports the September Windows updates introduced two operational problems worth planning around. One breaks audio on some Windows PCs, tied to KB5124012. Another causes Remote Desktop Services failures on Windows Server, and Microsoft has since released emergency updates to fix the RDS issue. If you deployed September updates and lost RDS, the emergency fix is the path forward.
This is the usual tension: the same September rollups close hundreds of vulnerabilities, several KEV-listed, but a few break things. Do not let a couple of known issues stall your patch cycle for the KEV-tagged fixes.
Dark Reading and Rapid7 continue to cover CVE-2026-85706, the maximum severity GitLab path traversal already exploited in the wild. It remains KEV-listed. If you self-host GitLab and have not patched, that is still an open supply chain exposure.
Do this first
Work the confirmed exploitation before anything else.
- Patch Cisco Secure Email Gateway for CVE-2026-76461, newly KEV-listed on September 14.
- Apply the ConnectWise ScreenConnect patch and review sessions given the worm-like spread.
- Patch JFrog Artifactory and audit for backdoors and unexpected artifacts.
- Prioritize the ransomware-linked KEV entries you run: CVE-2026-15409, CVE-2026-59310, and CVE-2026-41940.
- Deploy the emergency Windows update for RDS failures if September updates broke Remote Desktop Services.
- Confirm GitLab is patched for CVE-2026-85706 if you self-host.
Checking your own state
To see where your Microsoft patches stand against these exploitation signals, the free Microsoft Patch Tracker in Siemserva by Senserva ranks open Microsoft patches by CISA KEV, EPSS, and ransomware linkage. For the Cisco, SonicWall, VMware, and cPanel items above, the non-Microsoft exploited-CVE tracker in Siemserva follows CISA KEV additions daily so you can match today's new entry against your inventory.
Sources
- SecurityWeek: ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks (2026-09-14)
- SecurityWeek: Three JFrog Artifactory Flaws Exploited for Backdoor Deployment (2026-09-14)
- Dark Reading: Maximum Severity GitLab Flaw Puts Supply Chains at Risk (2026-09-14)
- BleepingComputer: Microsoft: September updates break audio on some Windows PCs (2026-09-14)
- BleepingComputer: Microsoft: September updates cause RDS failures on Windows Server (2026-09-14)
- BleepingComputer: Microsoft releases emergency Windows updates to fix RDS failures (2026-09-14)
- Rapid7: CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild (2026-09-14)
Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-09-15.
Senserva is a Microsoft security company and a member of the Microsoft Intelligent Security Association. Senserva audits your Microsoft 365, Intune, Defender, and Entra ID environment: complete patch state, 650+ security checks, and full reports, with clear guidance on what to fix first.