Security Roundup: Cisco AsyncOS Root RCE, Linux Kernel Netfilter in CISA KEV, Google Pixel Modem Zero-Day (Weekend Edition - September 21, 2026)
Executive Summary: Over the September 19–21 weekend, critical perimeter and infrastructure zero-day disclosures reached peak urgency. Cisco released emergency updates for an actively exploited unauthenticated root Remote Code Execution (RCE) flaw in Cisco Secure Email Gateway (AsyncOS), tracked as CVE-2026-76461. Simultaneously, CISA added Linux kernel Netfilter bridge memory corruption (CVE-2026-53266) and Google Pixel cellular baseband modem logic bypass (CVE-2026-58704) to the Known Exploited Vulnerabilities catalog. We also examine the critical CVSS 9.8 Use-After-Free flaw in Windows SSTP VPN (CVE-2026-73009) and provide an actionable gateway defense blueprint.
Key Threat Disclosures at a Glance
1. Cisco Secure Email Gateway (AsyncOS) SQLi to Root RCE (CVE-2026-76461)
Cisco AsyncOS software contains an unauthenticated remote SQL injection vulnerability in its MIME header and message envelope parsing logic. Attackers send specially crafted SMTP payloads that break out of SQL sanitization routines, directly executing arbitrary shell commands with root privileges on the underlying FreeBSD-based operating system. CISA has added this flaw to the KEV catalog with mandatory federal mitigation deadlines.
2. Linux Kernel Netfilter Bridge ebtables SNAT Out-of-Bounds Write (CVE-2026-53266)
A critical memory corruption flaw located in the Linux netfilter bridge module's ebtables SNAT target allows attackers to overwrite adjacent kernel memory during ARP address translation. Active exploitation has been detected in multi-tenant cloud environments to achieve container breakouts and full kernel ring-0 execution.
3. Google Pixel Modem Firmware Privilege Escalation (CVE-2026-58704)
An improper authorization logic vulnerability within the cellular modem baseband firmware of Google Pixel devices allows proximal or adjacent attackers to bypass permission boundaries and execute arbitrary baseband code without user interaction. Google and CISA confirmed targeted exploitation in the wild.
4. Windows SSTP VPN Remote Code Execution (CVE-2026-73009)
Microsoft’s Secure Socket Tunneling Protocol (SSTP) listener daemon suffers from a critical Use-After-Free (UAF) flaw. Remote unauthenticated attackers sending malformed SSTP handshake packets over TCP port 443 can trigger arbitrary code execution in the context of the routing and remote access service (RRAS).
Technical Deep Dives in This Series
- CVE-2026-76461: Cisco AsyncOS Root RCE Under Active Attack: Deep-dive reverse engineering of the AsyncOS MIME parser breakout and root command execution.
- CVE-2026-53266: Linux Kernel Netfilter OOB Write in CISA KEV: Memory layout, ARP packet rewrite mechanics, and kernel heap exploitation.
- CVE-2026-58704: Google Pixel Modem Zero-Day Exploitation: Baseband packet telemetry, RF attack surfaces, and mobile endpoint defense.
- CVE-2026-73009: Windows SSTP VPN CVSS 9.8 Remote Code Execution: SSTP connection handshake analysis and buffer memory management.
- Hardening Enterprise Gateways: AsyncOS, VPN & Baseband Defense: Architectural guide for hardening email gateways, VPN listeners, and baseband interfaces.
Weekend Action Checklist for Security Operations
- Patch Cisco Email Gateways Immediately: Deploy Cisco AsyncOS fixed releases (15.5.5-014, 16.0.4-302, 16.5.0-780) and inspect mail filter logs for anomalous SQL injection syntax in MIME headers.
- Update Linux Kernels: Apply distribution kernel patches addressing
ebtablesnetfilter modules across bare-metal hosts and Kubernetes worker nodes. - Enforce Mobile Patching: Ensure corporate-managed Google Pixel devices receive the September 2026 security bulletin update to neutralize modem-level exploitation.
- Restrict Windows SSTP Exposure: Place RRAS / SSTP listeners behind application-layer firewalls or migrate legacy SSTP endpoints to WireGuard or IPsec IKEv2 tunnels.