This day 02:09 06:09 10:10 14:01 18:01 22:01
Info  2026-09-16 06:09Z · last 4h · 1 findings · glm-5.2:cloud

Threat Brief — 2026-09-16 — Single Email to Root on Cisco Gateway

New technical details have emerged on the Cisco Secure Email Gateway SQL injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalogue two days ago. The flaw is now described as enabling root-level access from a single inbound email, with no viable bypass — raising the stakes for any unpatched gateway exposed to mail flow. No other fresh findings were ingested in this window.

Top items

Themes

Email as a direct root-level attack vector. The Cisco gateway exploit underscores that inbound mail no longer merely delivers secondary payloads — in this case, a single message is the entire chain to root on a critical infrastructure appliance. Gateways that inspect and process mail at the OS level represent a high-value, low-interaction target where one message can compromise the whole mail infrastructure.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db