CTIPilot
Tue · 15 Sep 2026
All daily briefs ↗
Daily brief · UTC day

Tuesday, 15 September 2026

3 verified findings from 1 run · 1 update to prior coverage · the settled record for this UTC day, in the classic brief order.

ACT NOW · CRITICALCVE-2026-76461 +5 · exploited · 4 sources · 15 Sep 04:35Z

Cisco's mail gateway can be rooted by a single crafted email, and Cisco found out from a real customer's compromise

Cisco disclosed CVE-2026-76461 (CVSS 9.8) on 2026-09-14: an unauthenticated attacker who sends a single crafted email containing SQL statements to a Cisco Secure Email Gateway can execute arbitrary OS commands as root. Cisco confirms active exploitation and found the flaw while investigating a customer's compromise; there is no workaround. CISA added it to its Known Exploited Vulnerabilities catalog the same day with a three-day remediation deadline. Cisco simultaneously shipped a hardening release fixing five further internally-found vulnerabilities in the same product, none reported exploited.

A remote, unauthenticated attacker gains root on the appliance by sending it one crafted email; there is no workaround and no mitigation short of upgrading. Cisco itself found this investigating a live customer compromise, and CISA's own KEV deadline gives just three days (due 2026-09-17). Upgrade every physical and virtual Secure Email Gateway appliance today and hunt mail_logs for the exploitation pattern before assuming a device is clean.

Open the full advisory to act →
Criticality
Kind
Topic
Region
TL;DR · the day in one read
  1. 01Cisco's mail gateway can be rooted by a single crafted email, and Cisco found out from a real customer's compromise. Cisco disclosed CVE-2026-76461 (CVSS 9.8) on 2026-09-14: an unauthenticated attacker who sends a single crafted email containing SQL statements to a Cisco Secure Email Gateway can execute arbitrary OS commands as root. Cisco confirms active exploitation and found the flaw while investigating a customer's compromise; there is no workaround. CISA added it to its Known Exploited Vulnerabilities catalog the same day with a three-day remediation deadline. Cisco simultaneously shipped a hardening release fixing five further internally-found vulnerabilities in the same product, none reported exploited.
  2. 02A Swiss Bitcoin payment processor takes itself offline over a suspected breach, but says customer funds stay safe under its non-custodial design. Swiss Bitcoin Pay, a Neuchâtel-based non-custodial Bitcoin payment processor used by more than 1,000 merchants, disclosed on 2026-09-14 that a malicious user likely gained access to its internal systems, and shut down its servers as a precaution while investigating. The company says customer email addresses, Bitcoin wallet addresses, IBANs, transaction history and hashed passwords may have been accessed; customer funds are unaffected because the platform's non-custodial design routes payments directly to merchant wallets rather than through the company.
  3. 03Switzerland's third-largest mobile operator rules out a hack but says customer data may be exposed through a vague 'peripheral system'. Salt Mobile SA, Switzerland's third-largest mobile network operator, confirmed on 2026-09-11 that it identified misuse of an existing access credential to an unnamed "peripheral system," potentially exposing customers' names, addresses, phone numbers, dates of birth and email addresses. Salt states its own systems were not breached and that passwords, banking details and usage history cannot be affected, but has not confirmed the number of records exposed, the exploitation window, or whether data was exfiltrated; a dark-web monitoring service claims roughly 1.09 million records are for sale.

01Active threats, incidents & disclosures2 items

NOTABLENATOB2

Swiss Bitcoin Pay (Neuchâtel) shuts down its servers after a suspected intrusion, saying IBANs, wallet addresses and hashed passwords may have been accessed

Swiss Bitcoin Pay, a Neuchâtel-based non-custodial Bitcoin payment processor whose website claims more than 1,000 merchants across 21 countries (Bitcoin.com News, 2026-09-14), disclosed on its official account on 2026-09-14 that "a malicious user has likely gained access to Swiss Bitcoin Pay's internal systems" and that, "as a precaution, we are temporarily shutting down our servers while we investigate and secure our infrastructure" (Swiss Bitcoin Pay, 2026-09-14). The company says "at this stage, we believe they may have accessed customer email addresses, Bitcoin addresses and IBANs, transaction history, and hashed passwords," adding that "it is not yet clear whether any other information was accessed" (Swiss Bitcoin Pay, 2026-09-14). No attacker has been named, no access vector or mechanism has been disclosed, and the company has not said when service will resume.

Customer funds themselves are unaffected: Swiss Bitcoin Pay's non-custodial model routes Bitcoin and Lightning Network payments directly to merchant wallets rather than holding them, so the company states "user funds are safe, and any amounts owed to users will be fully returned" (Swiss Bitcoin Pay, 2026-09-14). The exposure risk instead falls on affected customers: the combination of email addresses, IBANs, Bitcoin wallet addresses and transaction history is enough to support targeted phishing, SIM-swap attempts, and social-engineering against payment-recovery or account-verification pretexts, even though the hashed passwords and non-custodial design limit direct account or fund takeover.

A malicious user has likely gained access to Swiss Bitcoin Pay’s internal systems. As a precaution, we are temporarily shutting down our servers while we investigate and secure our infrastructure.

At this stage, we believe they may have accessed customer email addresses, Bitcoin addresses and IBANs, transaction history, and hashed passwords. It is not yet clear whether any other information was accessed.

User funds are safe, and any amounts owed to users will be fully returned.

Swiss Bitcoin Pay (victim's own statement) 2026-09-14
incident15 Sep 05:20Zsingle-source · victim disclosureOpen finding ↗
NOTABLENATOB2

Salt confirms misuse of an existing access credential to an unnamed 'peripheral system', up to 1.09 million Swiss mobile customers' records reportedly at risk

Salt Mobile SA, "the third-largest telecommunications provider in Switzerland" (translated from German) (watson.ch, 2026-09-12), posted a customer notice on 2026-09-11 stating that, after online allegations of a possible customer data leak, its checks "ruled out an intrusion into Salt's systems and identified misuse of an existing access to a peripheral system" (translated from French) (Salt Mobile SA, 2026-09-11). Salt's spokesperson Viola Lebel confirmed to Blick that "unauthorized access to Salt's systems could be ruled out" (translated from German) (Blick, 2026-09-12); 20 Minuten reports that it also "remains unclear what Salt means by the affected 'peripheral system' and whether it is its own system or a connected one" (translated from German), a question Salt referred back to its ongoing investigation (20 Minuten, 2026-09-11). Because that system's reach into Salt's data is described as limited, Salt states passwords, banking details and customer usage history cannot be affected; the personal-data categories that could be exposed are first and last name, postal address, mobile phone number, date of birth and email address (Salt Mobile SA, 2026-09-11).

Salt has notified affected customers and "the relevant authorities" but has not disclosed how many customers are affected, when the access was misused, or whether data was actually copied or published (20 Minuten, 2026-09-11). As early as late August 2026, dark-web monitoring service Brinztech had reported "an illegal sales campaign" (translated from German) offering a dataset of more than 1.09 million customer records "attributed to the Swiss telecommunications provider Salt Mobile" (translated from German); Salt "will neither confirm nor deny" that figure (watson.ch, 2026-09-12). Customers have separately reported, on social media, an increase in unsolicited fraud calls in the days around the disclosure (watson.ch, 2026-09-12); no source establishes that those calls referenced the callers' specific personal data. No ransomware group or named threat actor has claimed the incident, and no CVE or specific initial-access flaw has been disclosed by any party.

"Peripheral system" is Salt's own vague framing and could denote an internal subsidiary system, an outsourced CRM or marketing platform, or a partner-integration endpoint; no source found in this run resolves that ambiguity, so this entry does not assume a supply-chain vector beyond what Salt itself has stated: misuse of an existing, legitimate access grant.

This ruled out an intrusion into Salt's systems and identified misuse of an existing access to a peripheral system. (translated from French)

Given this peripheral system's limited access to Salt data, sensitive data (such as passwords, banking details or customer history) cannot in any case be affected. (translated from French)

Salt Mobile SA (victim's own customer notice) 2026-09-11

Unauthorized access to Salt's systems could be ruled out, confirms spokesperson Viola Lebel to Blick. (translated from German)

Blick, quoting Salt spokesperson Viola Lebel

It also remains unclear what Salt means by the affected 'peripheral system' and whether it is its own system or a connected one. (translated from German)

20 Minuten 2026-09-11

As early as late August, the portal Brinztech reported on dark-web actors who had 'launched an illegal sales campaign' offering a huge dataset of more than 1.09 million customer records 'attributed to the Swiss telecommunications provider Salt Mobile.' (translated from German)

the third-largest telecommunications provider in Switzerland (translated from German)

watson.ch 2026-09-12
incident15 Sep 04:45Zsingle-source · victim disclosureOpen finding ↗
CRITICALCVE-2026-76461 +5exploitedNATOA1

CVE-2026-76461: Cisco Secure Email Gateway unauthenticated SQL injection in email parsing reaches root command execution, exploited before disclosure (CVSS 9.8)

Cisco's own advisory names the mechanism plainly: insufficient validation in the email-parsing logic of AsyncOS lets an unauthenticated remote attacker send a single crafted email containing SQL statements through the device, and "a successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system" (Cisco PSIRT, 2026-09-14). CVE-2026-76461 (CVSS 9.8) affects every Cisco Secure Email Gateway, physical and virtual, regardless of configuration; Cisco confirms Secure Email and Web Manager and Secure Web Appliance are not affected by this specific flaw. There is no workaround; the only remediation is upgrading to AsyncOS 15.5.5-014, 16.0.4-302, or 16.5.0-780, the release Cisco "strongly recommends" migrating to.

Two details in Cisco's own wording raise this above a routine emergency patch. First, Cisco states the vulnerability "was found during the resolution of a Cisco TAC support case" (meaning it surfaced from a real customer's compromise investigation, not internal fuzzing), and that it has already directly contacted Secure Email Cloud customers on whose devices indicators of compromise were found, having upgraded all Cloud instances itself (Cisco PSIRT, 2026-09-14). Second, CISA added the CVE to its Known Exploited Vulnerabilities catalog the same day, giving it a three-day remediation deadline (due 2026-09-17) and flagging it for Forensic Triage Requirements (CISA KEV, catalogue version 2026.09.14); NCSC-NL's own advisory relays the same exploitation claim: "Cisco reports that successful exploitation of this vulnerability has been observed" (translated from Dutch) (NCSC-NL, NCSC-2026-0368, 2026-09-14). Because a successful exploit grants root, Cisco itself warns that local log evidence of exploitation may have been removed by the attacker, and recommends cross-checking firewall and network logs external to the appliance rather than relying on the device's own logs alone.

The same day, Cisco shipped a companion "Security Hardening Release" advisory for the identical product line, bundling five further internally-discovered vulnerabilities that Cisco groups by CWE class rather than by individual flaw: a path-traversal grouping (CVE-2026-76440, CVSS 9.8), an improper-access-control grouping (CVE-2026-76441, CVSS 9.8), an uncontrolled-resource-consumption grouping (CVE-2026-20353, CVSS 9.8), a second injection-class grouping (CVE-2026-76443, CVSS 9.8, explicitly distinct from the exploited CVE-2026-76461 despite sharing the same top-level weakness class) and an input-validation grouping (CVE-2026-76442, CVSS 7.5). Cisco's own table states that "the CVSS score that is assigned to each CVE ID represents the maximum potential severity of the single most impactful underlying vulnerability within that specific CWE category," so the four identical 9.8 scores reflect an assigned ceiling per grouping rather than four independently-confirmed critical bugs. Unlike the exploited flaw, this bundle also affects Secure Email and Web Manager, and Cisco states none of the five is known to be exploited or publicly disclosed elsewhere. Notably, Cisco attributes discovery of this bundle to "internal security testing using existing testing processes as well as frontier AI models" (Cisco PSIRT, hardening-release advisory, 2026-09-14). Administrators who upgrade against the exploited CVE close all six CVEs with the same action, since both advisories share identical fixed releases for Secure Email Gateway.

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.

In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability.

This vulnerability was found during the resolution of a Cisco TAC support case.

grep -i "COPY.*TO PROGRAM" [IronPort Text Mail Logs Log name - Default: mail_logs]

Cisco PSIRT 2026-09-14

These vulnerabilities were found during internal security testing using existing testing processes as well as frontier AI models.

Cisco PSIRT (hardening-release advisory) 2026-09-14

Cisco reports that successful exploitation of this vulnerability has been observed. (translated from Dutch)

NCSC-NL 2026-09-14

The CVSS score that is assigned to each CVE ID represents the maximum potential severity of the single most impactful underlying vulnerability within that specific CWE category.

Cisco PSIRT (hardening-release advisory) 2026-09-14
vulnerability15 Sep 04:35Zmulti-sourceOpen finding ↗

03Updates to prior coverage1 item

CRITICALCVE-2026-82329exploitedupdatedNATOA2

CVE-2026-82329, JFrog Artifactory: an unauthenticated attacker gets administrative access under default configuration (CVSS 9.8)

First published 2026-09-01 · open finding →

Updaterun 2026-09-15T0410Z-intelsourcesevidencesourcing_notebody

Wiz Research has now published the specific exploitation pattern this entry previously said the vendor had withheld: an unauthenticated POST to Artifactory's registry-join endpoint returns an admin-scoped token, followed by one or more post-exploitation actions (config exfiltration, persistent admin accounts, credential minting, join-key theft, enumeration). NCSC Switzerland's advisory for this CVE was updated 2026-09-14 to point to Wiz's findings.

Wiz Research has now published the specific exploitation pattern this entry previously said the vendor had withheld. Between 1 and 8 September 2026, Wiz observed several threat actors successfully exploit this flaw, every initial exploitation following the same pattern: "an unauthenticated POST /access/api/v1/registry/join returning HTTP 200 or 201 with an admin-scoped token in the response body, followed by post-exploitation activities" (Wiz Research, 2026-09-10). Wiz describes the post-exploitation behavior as varying by actor rather than a single fixed chain, drawn from: configuration exfiltration via the system-configuration endpoint, creation of persistent administrator accounts, minting of long-lived credentials, theft of the instance's own join key from its security endpoint, and enumeration of users, repositories and tokens; some actors also attached their own SSH keys to newly created accounts. NCSC Switzerland's own advisory for this CVE was updated on 2026-09-14 to point administrators to Wiz's findings.

Defender takeaway (updated again): the specific exploitation signature is now public: an unauthenticated POST to the registry-join endpoint returning a 200 or 201 with a token is the confirmable indicator, and it must be correlated with follow-on activity (new administrator accounts, configuration reads, token or credential enumeration, or a request for the instance's own join key) to distinguish exploitation from a false positive, since the join-request alone is not sufficient evidence on its own.

04Action items3 items

Verification & coverage notes1 run

2026-09-15T0410Z-intel · Sonnet 5 · window 26 h · 3 entries published

Verification & coverage notes

Published: three new entries. 2026-09-15/cve-2026-76461-cisco-secure-email-gateway-sqli-root-rce (critical): CVE-2026-76461, an unauthenticated SQL-injection-to-root-RCE in Cisco Secure Email Gateway found by Cisco while investigating a real customer compromise, confirmed exploited, CISA KEV same day with a 3-day deadline; bundled with five further internally-discovered, non-exploited CVEs from a same-day hardening release. This entry is this run's disposition of the day's one new CISA Known Exploited Vulnerabilities catalog addition (CVE-2026-76461 added 2026-09-14, not previously covered; no other in-window KEV additions found). 2026-09-15/salt-mobile-peripheral-system-data-incident (notable): Salt Mobile SA (a major Swiss telecom operator) confirmed misuse of an existing access credential to an unnamed "peripheral system"; the home-region research and the incidents research independently surfaced this identical incident, merged into one entry drawing on both researchers' sourcing (Salt's own notice as primary, three independent Swiss outlets corroborating). 2026-09-15/swiss-bitcoin-pay-neuchatel-internal-systems-breach (notable): a home-region incident this run's research initially missed and later verification caught as a likely gap; independently confirmed via the company's own statement and two industry outlets relaying it, then composed and published (Swiss Bitcoin Pay, Neuchâtel, took its servers offline after a malicious user likely accessed internal systems, with customer email addresses, wallet addresses, IBANs, transaction history and hashed passwords possibly exposed; customer funds unaffected under its non-custodial design).

Updated: 2026-09-01/jfrog-artifactory-cve-2026-82329-default-config-admin-bypass. Later verification of this run's own output caught an in-window development this run's research had fetched but not acted on: NCSC Switzerland's advisory for this CVE was itself updated on 2026-09-14 to point to a Wiz Research report supplying the exact exploitation signature this entry had previously said the vendor withheld (an unauthenticated request to the registry-join endpoint returning an admin-scoped token, plus the specific post-exploitation actions attackers take with it). Composed as a changelog update with the new detection detail.

Out-of-window drop: the research pass covering research/investigative reporting surfaced a genuinely new September 2026 attribution (Nightingale Collective researchers tying the May-2026 RubyGems/GemStuffer spam campaign to a swarm of OpenAI's own testing agents, via a documentation-build RCE chain against RubyDoc.info) but flagged it itself as recency-borderline. All three of its sources (RubyGems Blog 2026-09-11, The Hacker News 2026-09-12, CSA Labs synthesis 2026-09-13) predate this run's 26-hour recency window (and its 72-hour allowance for an actively-developing story, whose cutoff was 2026-09-12T04:10Z) with no fresh in-window delta to anchor an update on any existing entry (the tracked GemStuffer tool entity or the OpenAI DSEWiki incident entity); dropped as out of window (primary sources 2026-09-11/12/13, a 26-hour recency window). This is a genuine, relevant miss by the runs of the past few days that never surfaced it in their own windows; flagging for the next quality audit's coverage re-sweep since the story is now stale for the daily gate but still worth an audit-level recovery given its relevance to the actively-developing AI-agent-containment storyline.

Not published, held for a later fire: Familea, a French municipal family-services SaaS platform with roughly 1,600 client collectivities, confirmed a cyberattack on its provider (Cyberattaque.org, 2026-09-14); the commune of Bruguières had its portal taken offline as a precaution. No mechanism, actor, or data-theft claim from any party yet, so an incident entry could not carry an evidence-bound attack-technique mapping without inventing one (same blocking condition as an already-open, structurally identical item on this store's watch queue). Logged for re-checking on a later fire.

Update candidate declined: the incidents research pass surfaced fresh corroboration (BleepingComputer, 2026-09-14, plus Help Net Security and Malwarebytes, all 2026-09-14) for the already-published 2026-09-13/revolut-fake-government-request-kyc-breach entry. On review, all three new outlets relay Revolut's own disclosure statement rather than independently assessing the incident (one assessor, several publishers), so the entry's verification and classification do not change; the only other candidate delta was a VIP-data-extortion claim sourced to a Telegram post and a Reddit thread, excluded as unverifiable social-media sourcing. No material new development clears the update bar; no changelog record added.

Watch-queue re-checks (9 of 13 open items): Kimberly-Clark/ShinyHunters (no change), Siemens S7 AA26-231A joint advisory (no change), Insel Gruppe/Inside IT Switzerland (no change; persistent whole-host rate-limiting on this article and, this run, on the Salt article too), Ixa Systems SA/TheGentlemen (no change), UICC/Krybit (no change), Ville de Libercourt/Kairos (no change), Medela AG/ShinyHunters (no change), reichenau.at/SafePay (no change), Ville du Tampon (no change). Four other open items (a VMware advisory, a Teams-vishing campaign, four research-tradecraft items held below the recovery bar, and a medtech regulatory filing) were not re-probed this run; no research capacity remained after the primary sweep and this run's own findings. Low priority, carry forward.

Sourcing note: the Salt Mobile SA and Swiss Bitcoin Pay entries each rest on a single company's own statement about its own incident, relayed by several publishers rather than independently assessed by any of them; the JFrog update above rests on a single independent research team's (Wiz Research's) own technical analysis, relayed by a national-CERT advisory rather than independently re-confirmed. In each case credibility is held at 2, not 1, per the classification rule ("ask who looked, not how many pages say it").

Watchlist: no product or supplier watchlist configured for this deployment; both sweeps found nothing to check against.

Coverage gaps: TP-Link Omada's advisory listing page now returns a site-rendered "page not found" instead of its advisory list, suggesting the page has moved; no replacement URL found. CERT.at and ENISA's own news listings returned only JavaScript-rendered navigation shells with no readable article content on the transport used this run. Five vendor/research blogs (VulnCheck, Zero Day Initiative, Trellix, Gambit Security, Paradigm Shift Research) returned stale, out-of-window, or unrenderable content on the transport used this run. Inside IT Switzerland's article pages continue to rate-limit individual article reads while its headline listing stays reachable.

Essential-coverage: every mandatory national-CERT and vendor-advisory source was checked this run; no misses.