Skip to main content

Overview

Cisco has released a security advisory which addresses a recent critical vulnerability within the email parsing of Cisco AsyncOS Software (for Cisco Secure Email Gateway). If this vulnerability is successfully exploited, then an unauthenticated, remote attacker could execute arbitrary commands with root privileges. This vulnerability affects Cisco Secure Email Gateway, both physical and virtual, regardless of device configuration.

  • CVE-2026-76461 – SQL Injection Vulnerability – CVSSv3.1 Score: 9.8

Affected Versions:

  • Cisco Async OS 15.5 and earlier; first fixed release is 15.5.5-014
  • Cisco Async OS 16.0 until 16.0.4-302
  • Cisco Async OS 16.5 until 16.5.0-780
  • Cisco highly recommends migrating to 16.5.0-780.

 

GitLab has released new security patches for both the Community and Enterprise editions for their software.  These patches address multiple critical and high severity vulnerabilities such as CVE-2026-85706. The path traversal vulnerability allows an unauthenticated user to read files due to missing authentication enforcement in the repository commits API.

  • CVE-2026-85706 – Path Traversal Vulnerability – CVSSv3.1 Score: 10

Affected Versions:

  • GitLab versions from 18.7 until 19.1.8
  • GitLab versions from 19.2 until 19.2.6
  • GitLab versions from 19.3 until 19.3.2

 

ConnectWise has released a security update for their remote desktop software, ScreenConnect. The update addresses a condition within the client that if exploited, can allow files to be transferred and executed within an active remote session without any authorisation required.

  • CVE-2026-84869 – Improper Privilege Management and Missing Authorisation Vulnerability – CVSSv3.1 Score 9.9.


Affected Versions:

  • Please upgrade to ScreenConnect version 26.6.5; all versions prior are vulnerable to an attack.

 

Microsoft Patches

Following last week's Patch Tuesday (8th of September), Microsoft released security updates addressing over 900, including 2 zero-day exploits that were being actively exploited in attacks. These patched vulnerabilities spanned across Windows, Microsoft Office, SQL Server, Exchange, SharePoint, Azure and Developer tools.

The two actively exploited zero-day patches were for CVE-2026-85880 and CVE-2026-81963, both of which are elevation of privilege exploits. Elevation-of-privilege exploits seem to be most common within the security updates, as 438 of the vulnerabilities that were patched were related to privilege escalation.

These patches feature in the latest Microsoft update and do not require installing individually.

 

Recommended Action

Organisations are encouraged to review the appropriate security advisory pages and apply the updates:

Cisco: Cisco Security Advisory

GitLab: GitLab Patch Documentation

ConnectWise: ScreenConnect Security Bulletin

Microsoft Patches: Security Update Guide - Microsoft

Topics

  • Advisory
  • Vulnerability
  • Exploit
  • Patches and Updates