Skip to main content
Table of Contents

Roundup: Highest Zero-day Attacks and CVEs Reported and Patched Last Week

... min read
Share

The week of September 21 was the busiest in cybersecurity this quarter, in terms of zero-day attacks. On September 8, Microsoft Patch Tuesday identified around 114 to 119 critical vulnerabilities. It fixed 966 flaws, making it the largest security update batch in Microsoft history.

Image: Max Bender/Unsplash

Kiteworks, which offers enterprises a secure file-sharing platform with data governance and compliance controls, issued a precautionary advisory urging customers to shut down their servers for a brief period. The warning followed credible threat intelligence from federal authorities about possible zero-day targeting. On September 25, Kiteworks advised its government, financial services and enterprise customers worldwide to take their servers offline for six hours. In a statement, the company said, “All known vulnerabilities are addressed in our current release, 9.5.1.”

Separately, CISA added three actively exploited Linux kernel flaws to its Known Exploited Vulnerabilities (KEV) catalog and set tight patch deadlines for federal agencies. The most severe is CVE-2025-39682 (CVSS 9.8), a flaw in the kernel’s TLS receive path that can cause memory disclosure or denial of service.

Cisco disclosed an actively exploited zero-day in its Secure Email Gateway, tracked as CVE-2026-76461 (CVSS 9.8). The SQL injection flaw in AsyncOS lets an unauthenticated remote attacker gain root access by sending a single crafted email. CISA has added it to the KEV catalog, and no workarounds are available. Cisco has already applied mitigations for its cloud customers, but customers with on-premises gateways must install the emergency updates themselves.

In a related development, Russia’s Sandworm group is chaining two Cisco Secure Firewall Management Center flaws, CVE-2026-20079 and CVE-2026-20316, to deploy an updated variant of the Cyclops Blink botnet malware. A separate threat cluster is exploiting CVE-2026-20316 to deliver Qilin ransomware.

Mobile platforms were not spared either. A security researcher disclosed two chained, unpatched vulnerabilities in OxygenOS 16, OnePlus’s Android 16-based operating system. The flaws affect OnePlus and OPPO devices and let a malicious app installed on the phone gain root privileges without any permissions, bypassing Android’s core app-sandbox protections.

On September 8, Microsoft Patch Tuesday identified around 114 to 119 critical vulnerabilities. It fixed 966 flaws, making it the largest security update batch in Microsoft history.

 

We tell stories about how technology impacts and transforms business and lives. We write about tech for societal and business impact.

Designed, Developed and Managed by DARIS

Copyright ©2026 – DIGITAL CREED, Mumbai, India. All rights reserved.