The 5-Minute Cyber Brief: September 15, 2026

By George Bailey   Published: 09/14/26   Updated: 09/14/26   2 min read

Published: 09/15/26

Tuesday’s clock is short on the mail gateway, with three reminders that “clean” can still mean compromised: Cisco Secure Email Gateway SQL injection already in KEV and due Wednesday, a Sogou one-click chain dropping GRAYRABBIT, a Windows ALPC zero-day that walks AppContainer to SYSTEM (separate from the Update Stack bug), and PoisonedRefresh — a fileless PHP web shell on F5 BIG-IP APM that a patch alone won’t remove.

Lead Story

Cisco ESA: Crafted Mail → Root — Due Wednesday

A critical SQL injection in Cisco Secure Email Gateway email parsing lets unauthenticated attackers reach root on the appliance. Fixed builds are out; CISA wants federal agencies done by September 17, 2026, with forensic triage.

Why it matters: Patch now, hunt suspicious SQL in mail logs, and check external network logs — local evidence may be gone after root.

Read more on CyberExperts: Read the analysis

Also Worth Your Attention

Sogou: One Click → GRAYRABBIT

A widely installed Chinese-language IME can be abused with a single crafted link to drop the GRAYRABBIT backdoor. Update Sogou Input Method to a fixed release, or remove it where you don’t need it.

Why it matters: No macros, no “enable content” — just a click on an endpoint that may not be in your usual app inventory.

Read more on CyberExperts: Read more

Windows ALPC: AppContainer → SYSTEM

An exploited ALPC elevation bug lets low-privilege sandboxed code climb to SYSTEM. It is not the Update Stack zero-day from the same Patch Tuesday. Ship September cumulatives and verify build numbers; federal KEV due is September 22.

Why it matters: Classic finishing move after browser or document sandbox escapes.

Read more on CyberExperts: Read more

F5 PoisonedRefresh: Patch ≠ Clean

After initial access via a known APM RCE, PoisonedRefresh can inject a PHP web shell into memory while leaving on-disk scripts untouched. Rebuild and run a compromise assessment — don’t stop at “patched.”

Why it matters: File scanners that only hash APM PHP scripts can miss it.

Read more on CyberExperts: Read the analysis

Go Deeper

Identity & access: IAM library · Tools & playbooks: Cybersecurity Tools · Subscribe: Daily Brief

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.