// CISA KEV
Active Exploitation Wave: Cisco, GitLab, Tencent, and Supply Chain Threats Demand Immediate Action
By NeoShield AI Threat Desk · Published 2026-09-15 · 5 min read
#CISA KEV#Cisco Secure Email Gateway#CVE-2026-76461#GitLab#CVE-2026-51990#Tencent Sogou#GrayRabbit#Revolut
September 15, 2026 brings a surge of critical, actively exploited vulnerabilities and breach disclosures spanning enterprise gateways, developer infrastructure, consumer software, and browser extensions. Security teams must prioritize patching, credential hygiene, and supply chain vigilance today.
Cisco Secure Email Gateway — SQL Injection Under Active Exploitation
CISA has added CVE-2026-76461, a SQL injection vulnerability in Cisco Secure Email Gateway, to its Known Exploited Vulnerabilities catalog. SQL injection in a mail security appliance is particularly dangerous because these devices sit at the perimeter, process untrusted external input by design, and often hold sensitive policy configurations and message logs. Successful exploitation can allow an attacker to extract data, manipulate filtering rules to allow malicious mail through, or pivot deeper into the network. CISA's KEV listing confirms this is not theoretical — exploitation is occurring in the wild. Organizations running Cisco Secure Email Gateway must treat this as an emergency patch event. If immediate patching is not possible, restrict management interface access to trusted IP ranges and increase logging verbosity on the appliance to catch anomalous query behavior.
GitLab Maximum-Severity Flaw Now Actively Exploited
CISA has also confirmed active exploitation of a maximum-severity GitLab vulnerability. GitLab instances host source code, CI/CD pipelines, secrets, and deployment keys — a compromise here can cascade into full software supply chain infiltration. Attackers who gain unauthorized access to a GitLab instance can inject malicious code into repositories, steal credentials stored in pipeline variables, or use the platform as a launchpad for downstream attacks on customers and partners. Any organization running self-managed GitLab must apply the relevant patch immediately. In parallel, audit all active sessions, rotate CI/CD secrets and deploy keys, and review recent pipeline execution logs for unexpected jobs or external network calls.
Tencent Sogou Input Method and the GrayRabbit Backdoor
CVE-2026-51990 in Tencent's Sogou Input Method is being actively exploited by China-aligned threat actors to deploy the GrayRabbit backdoor. Input method editors run with elevated privileges and deep OS integration, making them high-value targets for persistent access. GrayRabbit is described as a backdoor, meaning compromised endpoints likely provide ongoing remote access to attackers. Organizations that permit or manage Sogou Input Method on corporate endpoints should patch immediately and run endpoint detection scans for indicators associated with GrayRabbit. Network defenders should monitor for unusual outbound connections from endpoints running input method software, particularly to unfamiliar external infrastructure.
Malicious Twitch Browser Extension Leaks OAuth Tokens at Scale
A malicious browser extension targeting Twitch users has exfiltrated OAuth tokens from approximately 31,000 users, sending stolen credentials to Russian bot service infrastructure. OAuth token theft is especially damaging because tokens often grant persistent access without requiring a password, bypass multi-factor authentication, and can be used to take over accounts silently. This incident is a sharp reminder that browser extensions represent a significant and often undermonitored supply chain risk. Enterprise security teams should enforce extension allowlisting policies through browser management platforms, and end users should be advised to audit and remove unrecognized extensions immediately. Any user who had the malicious extension installed should revoke all active OAuth tokens for their Twitch account and review connected applications.
Revolut Data Breach — Social Engineering Hits Financial Services
Revolut has disclosed a data breach in which a threat actor impersonated a government agency to gain access to customer financial information and passport data. This breach underscores that technical controls alone are insufficient when human verification processes can be manipulated. For security leaders, this is a prompt to review vendor and partner identity verification procedures. For individuals and organizations with Revolut accounts, immediate credential rotation is advised, and fraud monitoring should be elevated. Exposed passport data creates long-tail risk for identity fraud that extends well beyond the immediate incident.
Defensive Priorities for September 15, 2026
- Patch Cisco Secure Email Gateway for CVE-2026-76461 immediately; restrict management access if patching is delayed
- Apply the GitLab security update, rotate all pipeline secrets and deploy keys, and audit recent repository activity
- Patch Tencent Sogou Input Method for CVE-2026-51990 and scan endpoints for GrayRabbit indicators of compromise
- Enforce browser extension allowlisting across managed endpoints and revoke OAuth tokens for users exposed by the Twitch extension incident
- Review identity verification procedures for third-party and vendor interactions in light of the Revolut social engineering breach
- Ensure all five CVEs and breach indicators are loaded into your SIEM and EDR platforms for active alerting
- Cross-reference your asset inventory against each affected product family before end of business today
The convergence of gateway exploits, developer platform compromise, endpoint malware, supply chain abuse, and social engineering in a single day illustrates why defense-in-depth and rapid response capability are non-negotiable. Prioritize patching, validate your detections, and communicate urgency to asset owners without delay.
This briefing is informational and does not substitute for official vendor advisories and CISA guidance — always consult primary sources for the most current remediation details.
Related articles
KEV Surge: Artifactory, ScreenConnect, GitLab, and RouterOS Under Active Attack
CISA has added eight vulnerabilities across JFrog Artifactory, ConnectWise ScreenConnect, GitLab, and MikroTik RouterOS to its…
CISA KEVCISA KEV Surge: Artifactory, ScreenConnect, GitLab & RouterOS Under Active Attack
CISA added eight vulnerabilities across JFrog Artifactory, ConnectWise ScreenConnect, MikroTik RouterOS, and GitLab to its Known…
CISA KEVCritical Exploits in the Wild: JFrog, GitLab, Cisco FMC, and ScreenConnect Under Active Attack
CISA's KEV catalog expanded with five critical vulnerabilities across JFrog Artifactory, GitLab, Cisco FMC, and ConnectWise…
NeoShield Security publishes defensive cybersecurity guides for developers, small teams, SOC learners, and MSPs. AI-assisted content is reviewed for safety, defensive purpose, and practical security value.