Threat Alerts
Your place for the latest CyberProof cyber threat intelligence alerts and updates
Speak with an ExpertCritical Cisco Secure Email Gateway Vulnerability Enables Remote Code Execution
A critical vulnerability, tracked as CVE-2026-76461 (CVSS 9.8), affects Cisco Secure Email Gateway appliances running vulnerable versions of AsyncOS. The flaw stems from insufficient validation within email-parsing logic and can be exploited remotely by an unauthenticated attacker through a specially crafted email containing malicious SQL statements. Successful exploitation may enable arbitrary SQL execution followed by command execution with root privileges on the underlying operating system.
The vulnerability affects both physical and virtual Secure Email Gateway deployments regardless of configuration, and no workaround is available. Active exploitation was identified in September 2026, increasing the urgency for organizations operating affected systems. Attackers obtaining root-level access may also be capable of modifying or removing evidence from the compromised appliance, making external network and firewall telemetry particularly important during investigations.
MongoDB Libraries Affected by Critical Security Flaws
Multiple security vulnerabilities affecting Mongoid, the MongoDB C Driver, and the Entity Framework Core Provider create risks to data confidentiality, integrity, and system availability. The most severe issue, CVE-2026-93765 (CVSS 9.1), affects Mongoid and stems from an unsafe reflection weakness that can allow attacker-controlled input to trigger unintended internal method calls. An unauthenticated attacker may be able to manipulate stored records or cause the affected application to become unresponsive.
Additional vulnerabilities include injection flaws that can allow unauthorized manipulation or deletion of database records, as well as a heap buffer overflow in the MongoDB C Driver’s Windows TLS implementation. The Entity Framework Core Provider also contains encryption-related weaknesses that can cause protected fields to be stored in plaintext under certain configurations, while debug-level logging may expose sensitive information such as passwords and cloud credentials. MongoDB has issued fixes across affected release branches, and organizations using these libraries should review their deployed versions and apply the corresponding security updates.
Check Point Management Server Vulnerability RCE
A critical vulnerability, tracked as CVE-2026-91843 (CVSS 9.8), affects multiple Check Point Security Management and Log Server products. The flaw is a stack overflow within the unauthenticated login process and may allow a remote attacker to execute arbitrary code without requiring valid administrative credentials. Successful exploitation could result in root-level access to the affected server.
Affected products include Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server, across several R80, R81, and R82 releases. Check Point Smart-1 Cloud environments are not affected. A security update and LivePatch have been released, with systems configured for supported automatic updates receive the protection automatically.
Actively Exploited Linux Kernel Vulnerabilities
Three Linux kernel vulnerabilities β CVE-2025-39682 (CVSS 9.8), CVE-2026-53266 (CVSS 8.8), and CVE-2025-39964 (CVSS 7.8 ) β have been added to CISAβs Known Exploited Vulnerabilities (KEV) catalog following confirmed exploitation in real-world attacks. The flaws affect different Linux kernel components and may enable remote exploitation, privilege escalation, memory corruption, or denial-of-service conditions depending on system configuration.
CVE-2025-39682 (CVSS 9.8 β Critical) affects the kernel TLS (kTLS) receive path and can potentially be triggered remotely on systems using the affected functionality. CVE-2026-53266 (CVSS 8.8 β High) is an out-of-bounds write flaw in the netfilter ebtables SNAT functionality that could allow a local attacker to cause memory corruption, denial of service, or potentially escalate privileges. CVE-2025-39964 (CVSS 7.8 β High) is a race condition in the AF_ALG cryptographic interface that can leave the kernel in an inconsistent state and potentially affect confidentiality, integrity, and availability.
Critical Cisco ISE Authentication Bypass Vulnerability
A critical vulnerability, tracked as CVE-2026-76460 (CVSS 10.0), affects Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). The flaw results from insufficient authentication controls on an API endpoint and allows an unauthenticated remote attacker to bypass authentication by sending a specially crafted request to a vulnerable system.
Successful exploitation can provide unauthorized access through the web-based management interface and may ultimately allow command execution with root privileges. The vulnerability affects vulnerable ISE and ISE-PIC releases regardless of device configuration, and Cisco has confirmed active exploitation in the wild. Because root-level access may allow attackers to remove or conceal evidence, organizations should also rely on external firewall and network telemetry when investigating potential compromise.
Cozy Bear Uses AI to Autonomously Rebuild Malware and Evade Detection
In a notable evolution of AI-enabled cyber operations, a Russian state-linked espionage actor whose activity is consistent with Cozy Bear (Midnight Blizzard) has been observed using AI agents to automatically modify and rebuild malware in response to security detections. Rather than using AI only to assist with coding or reconnaissance, the actor configured AI-driven workflows to monitor whether deployed implants were detected and, when flagged, autonomously modify, recompile, and redeploy the malware, iterating until a variant successfully evaded detection. AI was also integrated across other stages of the operation, including reconnaissance, phishing infrastructure development, credential harvesting, persistence, C2, and data exfiltration. This represents a significant evolution in the operational use of AI, where malware can be rapidly regenerated in response to defensive detections, reducing the effectiveness of static indicators and increasing the importance of behavioral and TTP-based detection.




