LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server
Cisco confirmed active exploitation of CVE-2026-76461, an unauthenticated SQL-injection flaw in Secure Email Gateway's AsyncOS email parsing that yields root command execution; CISA added it to the KEV catalog with a September 17 patch deadline, and Cisco published IoCs directing defenders to inspect cluster mail_logs for suspicious SQL statements. Volexity attributed the BlueMoon Chrome-Windows chain (CVE-2026-85046, -87491, -85880) to two China-linked actors, UTA0560 and APT31, who targeted NGOs on September 1 through a patch gap in which Chromium source carried the fixes before any stable Chrome release shipped them.
Read this edition