CVE Digest — September 14, 2026
7 CVE
1 KEV
Digest for September 14, 2026: 1 new entry in the CISA KEV catalog and 6 advisories from ACN, the Italian cybersecurity agency. KEV entries are known to be exploited in the wild: patch the affected products as soon as possible.
ACN advisories (Italy)
- Cisco: sfuttamento in rete della CVE-2026-76461 relativa a Secure Email Gateway
- Risolta vulnerabilità in Parallels Desktop for Mac
- Risolta vulnerabilità in MISP
- Risolta vulnerabilità in MongoDB Server
- JFrog: rilevato sfruttamento in rete delle vulnerabilità CVE-2026-42016 e CVE-2026-42018 in Artifactory
- Rilevato sfruttamento della CVE-2026-84869 relativa al prodotto ConnectWise ScreenConnect
| CVE | Product | CVSS | Severity | Summary | References |
|---|---|---|---|---|---|
| CVE-2026-76461 KEV | Cisco Secure Email Gateway | – | Unknown | Cisco Secure Email Gateway (AsyncOS) has a SQL injection flaw letting an unauthenticated remote attacker execute arbitrary commands as root. Listed in CISA KEV; apply vendor mitigations per BOD 26-04. | |
| CVE-2026-76461 | – | – | Unknown | Cisco released security updates fixing 6 vulnerabilities (5 critical, 1 high) in Secure Email Gateway and Secure Email and Web Manager. Active exploitation of CVE-2026-76461 is reported; patch promptly. | |
| risolta-vulnerabilita-in-parallels-desktop-for-mac | – | – | Unknown | Parallels released security updates fixing a high-severity vulnerability in Parallels Desktop for Mac, software for running virtual machines on macOS. Users should update to the latest version. | |
| risolta-vulnerabilita-in-misp-1 | – | – | Unknown | A high-severity vulnerability in MISP, the open-source platform for sharing and analyzing cyber threat intelligence, has been fixed. Users should apply the available updates. | |
| risolta-vulnerabilita-in-mongodb-server | – | – | Unknown | Security updates fix a high-severity flaw in MongoDB Server. An authenticated attacker with read/write database privileges could compromise service availability and manipulate data on affected systems. | |
| CVE-2026-42016 | – | – | Unknown | Active exploitation of two high-severity, already-patched vulnerabilities (CVE-2026-42016, CVE-2026-42018) in JFrog Artifactory, a software artifact management and distribution platform, has been detected. | |
| CVE-2026-84869 | – | – | Unknown | Active exploitation of the critical, already-patched vulnerability CVE-2026-84869 in ConnectWise ScreenConnect has been detected. Users should update immediately. |
Disclaimer
This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.