Published: 09/15/26
Tuesday’s clock is short on the mail gateway, with three reminders that “clean” can still mean compromised: Cisco Secure Email Gateway SQL injection already in KEV and due Wednesday, a Sogou one-click chain dropping GRAYRABBIT, a Windows ALPC zero-day that walks AppContainer to SYSTEM (separate from the Update Stack bug), and PoisonedRefresh — a fileless PHP web shell on F5 BIG-IP APM that a patch alone won’t remove.
Lead Story
Cisco ESA: Crafted Mail → Root — Due Wednesday
A critical SQL injection in Cisco Secure Email Gateway email parsing lets unauthenticated attackers reach root on the appliance. Fixed builds are out; CISA wants federal agencies done by September 17, 2026, with forensic triage.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Why it matters: Patch now, hunt suspicious SQL in mail logs, and check external network logs — local evidence may be gone after root.
Read more on CyberExperts: Read the analysis
Also Worth Your Attention
Sogou: One Click → GRAYRABBIT
A widely installed Chinese-language IME can be abused with a single crafted link to drop the GRAYRABBIT backdoor. Update Sogou Input Method to a fixed release, or remove it where you don’t need it.
Why it matters: No macros, no “enable content” — just a click on an endpoint that may not be in your usual app inventory.
Read more on CyberExperts: Read more
Windows ALPC: AppContainer → SYSTEM
An exploited ALPC elevation bug lets low-privilege sandboxed code climb to SYSTEM. It is not the Update Stack zero-day from the same Patch Tuesday. Ship September cumulatives and verify build numbers; federal KEV due is September 22.
Why it matters: Classic finishing move after browser or document sandbox escapes.
Read more on CyberExperts: Read more
F5 PoisonedRefresh: Patch ≠ Clean
After initial access via a known APM RCE, PoisonedRefresh can inject a PHP web shell into memory while leaving on-disk scripts untouched. Rebuild and run a compromise assessment — don’t stop at “patched.”
Why it matters: File scanners that only hash APM PHP scripts can miss it.
Read more on CyberExperts: Read the analysis
Go Deeper
Identity & access: IAM library · Tools & playbooks: Cybersecurity Tools · Subscribe: Daily Brief
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.