Security Roundup: Cisco AsyncOS Root RCE, Linux Kernel Netfilter in CISA KEV, Google Pixel Modem Zero-Day (Weekend Edition - September 21, 2026)

ColibriSec Weekend Security Roundup September 21 2026

Executive Summary: Over the September 19–21 weekend, critical perimeter and infrastructure zero-day disclosures reached peak urgency. Cisco released emergency updates for an actively exploited unauthenticated root Remote Code Execution (RCE) flaw in Cisco Secure Email Gateway (AsyncOS), tracked as CVE-2026-76461. Simultaneously, CISA added Linux kernel Netfilter bridge memory corruption (CVE-2026-53266) and Google Pixel cellular baseband modem logic bypass (CVE-2026-58704) to the Known Exploited Vulnerabilities catalog. We also examine the critical CVSS 9.8 Use-After-Free flaw in Windows SSTP VPN (CVE-2026-73009) and provide an actionable gateway defense blueprint.

🏛️
Incident Overview:

Key Threat Disclosures at a Glance

1. Cisco Secure Email Gateway (AsyncOS) SQLi to Root RCE (CVE-2026-76461)

Cisco AsyncOS software contains an unauthenticated remote SQL injection vulnerability in its MIME header and message envelope parsing logic. Attackers send specially crafted SMTP payloads that break out of SQL sanitization routines, directly executing arbitrary shell commands with root privileges on the underlying FreeBSD-based operating system. CISA has added this flaw to the KEV catalog with mandatory federal mitigation deadlines.

2. Linux Kernel Netfilter Bridge ebtables SNAT Out-of-Bounds Write (CVE-2026-53266)

A critical memory corruption flaw located in the Linux netfilter bridge module's ebtables SNAT target allows attackers to overwrite adjacent kernel memory during ARP address translation. Active exploitation has been detected in multi-tenant cloud environments to achieve container breakouts and full kernel ring-0 execution.

3. Google Pixel Modem Firmware Privilege Escalation (CVE-2026-58704)

An improper authorization logic vulnerability within the cellular modem baseband firmware of Google Pixel devices allows proximal or adjacent attackers to bypass permission boundaries and execute arbitrary baseband code without user interaction. Google and CISA confirmed targeted exploitation in the wild.

4. Windows SSTP VPN Remote Code Execution (CVE-2026-73009)

Microsoft’s Secure Socket Tunneling Protocol (SSTP) listener daemon suffers from a critical Use-After-Free (UAF) flaw. Remote unauthenticated attackers sending malformed SSTP handshake packets over TCP port 443 can trigger arbitrary code execution in the context of the routing and remote access service (RRAS).

Technical Deep Dives in This Series

Weekend Action Checklist for Security Operations

  1. Patch Cisco Email Gateways Immediately: Deploy Cisco AsyncOS fixed releases (15.5.5-014, 16.0.4-302, 16.5.0-780) and inspect mail filter logs for anomalous SQL injection syntax in MIME headers.
  2. Update Linux Kernels: Apply distribution kernel patches addressing ebtables netfilter modules across bare-metal hosts and Kubernetes worker nodes.
  3. Enforce Mobile Patching: Ensure corporate-managed Google Pixel devices receive the September 2026 security bulletin update to neutralize modem-level exploitation.
  4. Restrict Windows SSTP Exposure: Place RRAS / SSTP listeners behind application-layer firewalls or migrate legacy SSTP endpoints to WireGuard or IPsec IKEv2 tunnels.

Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther