This cybersecurity brief for September 16, 2026, covers multiple critical zero-day vulnerabilities under active exploitation. Cisco has patched a root remote code execution flaw (CVE-2026-76461) in its Secure Email Gateway. Google addressed a high-severity privilege escalation bug (CVE-2026-58704) in Pixel modems. Both were added to CISA's KEV catalog. Additionally, a critical authentication bypass in WSO2's API platform (CVE-2026-5430) is being actively exploited, and two Chinese APT groups were found using the same Chrome zero-day in separate espionage campaigns.
Help others stay informed about cybersecurity threats
Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.
Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.
Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.