Today's threat landscape reads like a stress test for every layer of the enterprise stack. In a single news cycle, defenders are contending with actively exploited flaws in email security appliances, developer platforms, and consumer input software, alongside a large-scale browser extension supply chain compromise and a significant financial services data breach. The common thread is speed: threat actors are moving from vulnerability disclosure to active exploitation faster than many patch cycles allow, and social engineering remains a reliable force multiplier. Here is what your team needs to know and act on right now.

Cisco Secure Email Gateway — SQL Injection Under Active Exploitation

CISA has added CVE-2026-76461, a SQL injection vulnerability in Cisco Secure Email Gateway, to its Known Exploited Vulnerabilities catalog. SQL injection in a mail security appliance is particularly dangerous because these devices sit at the perimeter, process untrusted external input by design, and often hold sensitive policy configurations and message logs. Successful exploitation can allow an attacker to extract data, manipulate filtering rules to allow malicious mail through, or pivot deeper into the network. CISA's KEV listing confirms this is not theoretical — exploitation is occurring in the wild. Organizations running Cisco Secure Email Gateway must treat this as an emergency patch event. If immediate patching is not possible, restrict management interface access to trusted IP ranges and increase logging verbosity on the appliance to catch anomalous query behavior.

GitLab Maximum-Severity Flaw Now Actively Exploited

CISA has also confirmed active exploitation of a maximum-severity GitLab vulnerability. GitLab instances host source code, CI/CD pipelines, secrets, and deployment keys — a compromise here can cascade into full software supply chain infiltration. Attackers who gain unauthorized access to a GitLab instance can inject malicious code into repositories, steal credentials stored in pipeline variables, or use the platform as a launchpad for downstream attacks on customers and partners. Any organization running self-managed GitLab must apply the relevant patch immediately. In parallel, audit all active sessions, rotate CI/CD secrets and deploy keys, and review recent pipeline execution logs for unexpected jobs or external network calls.

Tencent Sogou Input Method and the GrayRabbit Backdoor

CVE-2026-51990 in Tencent's Sogou Input Method is being actively exploited by China-aligned threat actors to deploy the GrayRabbit backdoor. Input method editors run with elevated privileges and deep OS integration, making them high-value targets for persistent access. GrayRabbit is described as a backdoor, meaning compromised endpoints likely provide ongoing remote access to attackers. Organizations that permit or manage Sogou Input Method on corporate endpoints should patch immediately and run endpoint detection scans for indicators associated with GrayRabbit. Network defenders should monitor for unusual outbound connections from endpoints running input method software, particularly to unfamiliar external infrastructure.

Malicious Twitch Browser Extension Leaks OAuth Tokens at Scale

A malicious browser extension targeting Twitch users has exfiltrated OAuth tokens from approximately 31,000 users, sending stolen credentials to Russian bot service infrastructure. OAuth token theft is especially damaging because tokens often grant persistent access without requiring a password, bypass multi-factor authentication, and can be used to take over accounts silently. This incident is a sharp reminder that browser extensions represent a significant and often undermonitored supply chain risk. Enterprise security teams should enforce extension allowlisting policies through browser management platforms, and end users should be advised to audit and remove unrecognized extensions immediately. Any user who had the malicious extension installed should revoke all active OAuth tokens for their Twitch account and review connected applications.

Revolut Data Breach — Social Engineering Hits Financial Services

Revolut has disclosed a data breach in which a threat actor impersonated a government agency to gain access to customer financial information and passport data. This breach underscores that technical controls alone are insufficient when human verification processes can be manipulated. For security leaders, this is a prompt to review vendor and partner identity verification procedures. For individuals and organizations with Revolut accounts, immediate credential rotation is advised, and fraud monitoring should be elevated. Exposed passport data creates long-tail risk for identity fraud that extends well beyond the immediate incident.

Defensive Priorities for September 15, 2026

- Patch Cisco Secure Email Gateway for CVE-2026-76461 immediately; restrict management access if patching is delayed
- Apply the GitLab security update, rotate all pipeline secrets and deploy keys, and audit recent repository activity
- Patch Tencent Sogou Input Method for CVE-2026-51990 and scan endpoints for GrayRabbit indicators of compromise
- Enforce browser extension allowlisting across managed endpoints and revoke OAuth tokens for users exposed by the Twitch extension incident
- Review identity verification procedures for third-party and vendor interactions in light of the Revolut social engineering breach
- Ensure all five CVEs and breach indicators are loaded into your SIEM and EDR platforms for active alerting
- Cross-reference your asset inventory against each affected product family before end of business today

The convergence of gateway exploits, developer platform compromise, endpoint malware, supply chain abuse, and social engineering in a single day illustrates why defense-in-depth and rapid response capability are non-negotiable. Prioritize patching, validate your detections, and communicate urgency to asset owners without delay.

This briefing is informational and does not substitute for official vendor advisories and CISA guidance — always consult primary sources for the most current remediation details.