Welcome to Threat Thursday, Galactic's weekly threat intelligence roundup.
Every Thursday, we cover the cybersecurity stories that matter most for protecting organizations from emerging threats, and we break each one down into what happened, what it could mean for your organization, and what to do about it.
This week is heavy on the infrastructure that sits between an organization and the outside world: the appliance filtering your email, the tool your IT team connects through, the router at the edge of your network, the phone in your pocket. Several of those were attacked before a patch existed, which is the part worth reading closely.
before a patch existed, which is the part worth reading closely.
This Week’s Cycle
1. Cisco Secure Email Gateway Has a Zero-Day Exploitable by Sending an Email: CVE-2026-76461
Cisco's Secure Email Gateway, the appliance many organizations use to filter phishing, malware, and spam before it reaches inboxes, has a critical flaw that gives an attacker full control of the device by sending it a specially crafted email. No login is required. Cisco discovered the vulnerability while working a support case, which means attacks were already happening before the patch existed. There's no workaround. CISA added it to its Known Exploited Vulnerabilities catalog on September 14 with a September 17 federal deadline. Cisco has already updated all cloud-hosted instances; on-premises appliances are the organization's responsibility.
Potential impact: The appliance sits in the path of every inbound and outbound email. A compromise exposes that content and gives attackers a foothold inside the network perimeter through a system that's trusted to be there.
What to do: Upgrade on-premises appliances to the fixed release for your branch: 15.5.5-014, 16.0.4-302, or 16.5.0-780. After upgrading, check the appliance's mail logs for suspicious activity and rotate any credentials and certificates it stores. Cisco Secure Email and Web Manager and Cisco Secure Web Appliance are not affected.
Source: BleepingComputer
2. ConnectWise ScreenConnect Has a Flaw That Lets Attackers Quietly Drop and Run Files During Active Sessions: CVE-2026-84869
ConnectWise ScreenConnect is a remote access tool IT teams use to connect to and support computers. A flaw in its client software allows an attacker with an active support session to silently transfer and run files on the machine being accessed, without the host knowing or approving it. Huntress confirmed three incidents where threat actors used this to deliver malicious files to connected machines, and observed the exploit spreading automatically from host to host. ConnectWise patched it on September 8 in version 26.6.5. CISA added it to its Known Exploited Vulnerabilities catalog on September 11.
Potential impact: Because this affects the client rather than the server, a compromised machine can become a source of further spread during future sessions. That's what Huntress observed. The payloads seen so far suggest attackers are using the access to establish persistent footholds on managed endpoints.
What to do: Upgrade ScreenConnect servers to 26.6.5, then reinstall host clients and update access agents separately — the server update alone isn't enough. As an immediate temporary step, ConnectWise recommends disabling the file transfer permission in Administration > Security > Roles until the client refresh is complete.
Source: The Hacker News
3. Apple Patched 250+ Vulnerabilities Across Every Platform in a Single Release
Apple released a sweeping security update on September 14, covering 250+ vulnerabilities across iPhone, iPad, Mac, Apple Watch, Apple TV, and Vision Pro. It's among the largest coordinated security releases in the company's history. No vulnerabilities in this batch are confirmed as actively exploited at time of writing, but the scope and severity distribution make it a priority update.
Potential impact: In environments with a mix of managed and unmanaged Apple devices, MDM compliance reporting often lags behind the actual installation state. That gap matters when the update covers this many components across this many platforms.
What to do: Update every Apple device to the latest available software. For organizations managing Apple devices through MDM, verify updates have applied rather than relying on compliance status alone.
Source: Cyber Security News
4. A Zero-Click Flaw in Google Pixel's Cellular Modem Is Being Used in Targeted Surveillance Attacks: CVE-2026-58704
CVE-2026-58704 is a privilege escalation flaw in the cellular modem of Google Pixel smartphones. An attacker who is physically close enough to share the same cellular network segment can exploit it without the user doing anything. Google describes the exploitation as "limited and targeted," language it has historically used for attacks by commercial spyware vendors or state-sponsored groups. Google patched it in the September 15 Pixel security bulletin.
Potential impact: Modem-level access is difficult to detect and sits close to the hardware layer. Historically, attacks like this target executives, journalists, lawyers, and people in sensitive or high-value roles rather than the general public.
What to do: Update Google Pixel devices to security patch level 2026-09-05 or later. All supported Pixel models from the Pixel 6 through Pixel 11, Pixel Tablet, and Fold are receiving the update.
Source: BleepingComputer
5. A Two-Stage Attack Chain Is Giving Attackers Full Control of MikroTik Routers Before Most Organizations Even Knew to Patch: CVE-2026-86060
MikroTik makes networking hardware used heavily by small businesses and internet service providers for routing and gateway functions. CERT Polska disclosed a two-stage attack chain against it, called MikroTrick, on September 5. The chain pairs two vulnerabilities to give an unauthenticated attacker full administrative control of any MikroTik device with SSH reachable from the internet. Exploitation was already confirmed by September 2, three days before the disclosure and a day before fixed builds shipped. Shadowserver found more than 122,500 internet-facing MikroTik SSH instances in a single scan. CISA added CVE-2026-86060 to its Known Exploited Vulnerabilities catalog on September 10 with a September 13 federal deadline, and specifically required forensic triage under Binding Operational Directive 26-04. MikroTik has published fixed builds: 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable).
Potential impact: An attacker with administrative control of a router can see all traffic flowing through it, alter routing rules, create persistent accounts, and use the device as a surveillance or pivot point inside the network. Routers typically receive less monitoring attention than endpoints, which means compromises at this layer can persist undetected. The forensic triage requirement from CISA reflects that devices exposed before September 3 may already be compromised.
What to do: Update RouterOS to the fixed build for your branch. Because exploitation preceded the patches, CISA's guidance is explicit: patch and investigate. Review the device for unrecognized user accounts, unexpected routing rule changes, and unfamiliar traffic configurations. Restricting SSH access to trusted IP ranges rather than leaving it open to the internet closes the exposure going forward.
Source: The Hacker News
The Big Picture
Three of this week's stories share a detail that's easy to skim past. Cisco found its email gateway flaw while working a support case, meaning attacks were underway before a patch existed. MikroTik exploitation was confirmed on September 2, three days before disclosure and a day before fixed builds shipped. ScreenConnect was in Huntress incident reports before it hit the KEV catalog.
CISA's response to the MikroTik chain is worth noting. Alongside the September 13 deadline, the agency required forensic triage under Binding Operational Directive 26-04, which is a formal acknowledgment that installing the update doesn't answer the question federal agencies need answered.
Patch, then go find out whether anyone was already inside. That's the right posture for all three of these. The update closes the entry point. It tells you nothing about who came through it first.
Check back next week for another Threat Thursday. See you then!


