Sep 15, 2026 · Subject: Cisco Email Gateway RCE (9.8) + Office heap overflow
Cisco email gateway RCE at 9.8, two Office buffer overflows, and a hardcoded JWT key
Two CVSS 9.8s and a trio of 8.8s landed today, none exploited in the wild yet, but don't let that make you comfortable. The headliner is CVE-2026-76461: unauthenticated root-level code execution on Cisco Secure Email Gateway via a poisoned email. No creds, no clicks, just a crafted message passing through your gateway. If you run Cisco SEG, bump this to the top of your queue right now.
One item / urgency verdict
CVE-2026-78517
An attacker can send a malicious Word document that triggers a heap buffer overflow, giving them code execution on the victim's machine over the network.
Apply the latest Microsoft Office security update via Windows Update or the Microsoft 365 admin center.