Security1 publisher2 min readPublished
Attackers hit Cisco's email gateway with a SQL injection zero-day before the patch shipped
CVE-2026-76461 is one of three flaws confirmed under active attack in a single week. Revolut's customer records left by a different route, a request sent from an email address on a government agency's own domain.
The Watch · Security desk

What happened
- Cisco confirmed on Monday that attackers had exploited CVE-2026-76461, a SQL injection zero-day, to compromise Secure Email Gateway appliances.
- Two days later Cisco confirmed a second product under attack, CVE-2026-76460, an authentication bypass in an Identity Services Engine API that unauthenticated attackers are using against the management interface.
- Acronis warned that CVE-2026-87886, a Linux privilege escalation in its backup extensions for cPanel, WHM and Plesk, is being used in targeted attacks.
- JFrog disclosed CVE-2026-90894, dubbed ParaShells, which lets any local user on a Mac running Parallels Desktop gain root on the host.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Cisco shipped indicators of compromise alongside the fix. A patched gateway that nobody has hunted through is still an untested appliance in the mail path.
- constraint The system that grants ISE access is the same one writing the log you would use to check it, and an unauthenticated bypass weakens that audit trail.
- decision The sending domain in the Revolut case was the agency's own. Anyone who answers agency data requests now has to verify the requester out of band.
- cost The Acronis privilege escalation sits in cPanel, WHM and Plesk estates. One exploited host exposes a hosting provider's tenants, and the provider pays for the cleanup.
Help Net Security dates Cisco's confirmation of CVE-2026-76461 to Monday, in a roundup published on September 20, 2026 [1][4]. The same item puts Cisco PSIRT's awareness of active exploitation in September 2025 [3]. Read literally, that is about twelve months between the vendor knowing and the customer patching [5]. One of those years may be a typo. If it is not, the indicator hunt on every Secure Email Gateway appliance has to cover a year of appliance history.
The Revolut case ran through email. Someone impersonating a government agency, writing from an email address on that agency's domain, obtained sensitive customer records, and the bank confirmed the incident on Saturday, September 12 [6][7]. A sender on the real domain passes the checks a recipient can automate. Verification then falls to a person: whoever decides an agency request is genuine before the records go out. Help Net Security does not say how the sender came to have an address on the agency's domain, or how many customers' records were taken [8].
Both Cisco flaws are in equipment other controls depend on. ISE checks a connecting user's identity, profiles the device, checks its security posture, grants the right type of access and logs all of it [10]. The email gateway handles the mail. Counting the Acronis backup extensions, three of the four CVEs in the week's roundup are reported under active exploitation [14].
The fourth, ParaShells in Parallels Desktop, is the exception. The risk concentrates on developer laptops, where a poisoned Homebrew formula or a malicious npm preinstall script goes from local user to full control, according to JFrog vulnerability research team lead Yuval Moravchick, who also flagged shared university and corporate machines with many local accounts [13].
The week's remaining item is policy. European Commission President Ursula von der Leyen told the European Parliament in Strasbourg on Wednesday that she wants frontier AI development slowed, and that she will invite the leading AI labs to discuss how the EU can support their own efforts to do that [15].
What to watch
- Whether Cisco corrects or confirms the September 2025 exploitation date for CVE-2026-76461; a year-long window changes how far back the hunt goes.
- Whether Revolut or the impersonated agency identifies the agency and the number of customers whose records were handed over.
- Whether Cisco issues indicators of compromise for the ISE authentication bypass as it did for the email gateway zero-day.