Cisco Patches Actively Exploited Email Gateway Zero-Day As AWS Confirms Permanent Data Loss in Middle East

Security and enterprise cloud operations faced intense pressure this week as Cisco rushed patches for actively exploited zero-day vulnerabilities, AWS acknowledged permanent infrastructure data losses, and new authentication flaws emerged across major enterprise platforms.

Cisco issued emergency patches for an actively exploited SQL injection zero-day vulnerability tracked as CVE-2026-76461 affecting Cisco Secure Email Gateway appliances. According to Cisco’s Product Security Incident Response Team, threat actors leveraged the flaw in targeted compromises, building on indicators of commerce first observed in the wild in September 2025. Just two days following that disclosure, Cisco confirmed a second critical vulnerability, CVE-2026-76460, an unauthenticated identity services engine management interface and API bypass affecting Cisco Identity Services Engine (ISE).

Cloud infrastructure providers also absorbed severe operational blows as Amazon Web Services formally acknowledged the permanent loss of customer data in its Middle East (Bahrain) region (me-south-1) and an availability zone in its Middle East (UAE) region (me-central-1). The permanent data loss stems from Iranian drone strikes that tore through AWS physical facilities six months prior, leaving stored resources beyond recovery despite prolonged restoration efforts.

Meanwhile, the vulnerability landscape expanded across endpoint and virtualization tools. A Linux privilege escalation vulnerability tracked as CVE-2026-87886 affecting Acronis backup extensions for cPanel, WebHost Manager, and Plesk came under active exploitation. Simultaneously, the JFrog vulnerability research team detailed a local privilege escalation flaw in Parallels Desktop, tracked as CVE-2026-90894 and dubbed “ParaShells,” which allows any local user to gain root privileges on host macOS systems.

Enterprise governance frameworks continued scrambling to address rapid artificial intelligence integration and autonomous agent proliferation. European Commission President Ursula von der Leyen called for a slowdown in frontier AI development during her State of the Union address, while the EU Agency for Cybersecurity activated the Cyber Resilience Act Single Reporting Platform on September 11, 2026, enforcing strict reporting obligations for exploited software vulnerabilities.

As organizations struggle to secure automated workflows, security leaders emphasize that traditional perimeter controls remain inadequate against autonomous threats. “Real control means checking proposed actions before they reach production systems, such as pausing a large refund for human approval,” noted Gourab Basu, Global Head of Engineering at meshIQ.



Leave a Reply

Your email address will not be published. Required fields are marked *