Cisco Email Gateway Backdoored, D-Link Routers Riddled: What UK Small Businesses Need to Know This Week
Two items from the last 24 hours of vulnerability intelligence deserve your attention this week. One involves email infrastructure that a significant portion of UK businesses either use directly or have in their supply chain. The other involves consumer-grade routers that appear in small offices, server rooms, and back offices across the country. Neither is speculative. Both have confirmed exploitation activity or public exploit code.
This is the 15 September 2026 threat briefing.
Story One: Cisco Secure Email Gateway Is Being Actively Exploited Right Now
CISA added CVE-2026-76461 to its Known Exploited Vulnerabilities catalogue on 14 September 2026. That designation is not given lightly. It means CISA has confirmed evidence of active exploitation in the wild, not just a theoretical risk.
The vulnerability is a SQL injection flaw in Cisco AsyncOS, the operating system that runs Cisco Secure Email Gateway (SEG). SQL injection, in plain English, means an attacker can send carefully crafted data to the software and manipulate what the database does with it. In this case, the result is arbitrary command execution with root privileges on the underlying operating system.
No authentication is required. An unauthenticated remote attacker can send a malicious request to a vulnerable Cisco SEG and obtain full control of the system. Root privileges means they own it: they can read every email, modify configurations, install persistent software, and use the gateway as a pivot point into your wider network.
The CISA required action is to apply vendor mitigations immediately, in accordance with Cisco’s published guidance and CISA’s BOD 26-04 patching guidelines. If mitigations are unavailable, discontinue use of the product.
Two additional Cisco SEG vulnerabilities were published to the NVD on the same day: CVE-2026-20353 (CVSS 9.8, improper control of a resource through its lifetime) and CVE-2026-76441 (CVSS 9.8, improper access control). These emerged from Cisco’s own internal security review. The cluster of Cisco SEG flaws landing simultaneously is worth noting.
The Sandworm Connection
This is where it becomes harder to dismiss as an enterprise problem.
Dark Reading reported on 14 September 2026 that a likely Russian threat actor, tracked as Sandworm, is chaining Cisco vulnerabilities to deploy Cyclops Blink: a sophisticated malware implant capable of harvesting credentials, scanning internal networks, and maintaining persistent access. Cyclops Blink has previously been attributed to Sandworm and was the subject of a joint advisory from the NCSC, CISA, NSA, and FBI in 2022.
Sandworm does not exclusively target large enterprises. They target network infrastructure precisely because it is shared: an email gateway, a router, a firewall used by hundreds of organisations routes through one vulnerable point. Small businesses are not the primary target. They are the collateral, or worse, the entry point into a larger supply chain.
If your email filtering is managed by your MSP and routes through Cisco SEG, the question you need to ask today is straightforward: has CVE-2026-76461 been patched on our email infrastructure, and when?
If your MSP cannot answer that question by end of business, that is information worth having.
Story Two: D-Link Routers With CVSS 9.9 Flaws and Public Exploits
D-Link published a cluster of critical vulnerabilities on 14 September 2026. Three models are affected: DIR-823G, DIR-878, and DWR-M921. The CVSSv3 scores range from 9.1 to 9.9.
The specific flaws:
CVE-2026-90680 and CVE-2026-90692 and CVE-2026-90693 affect the DIR-823G and DIR-878 respectively, with CVSS 9.9 scores. These are stack-based buffer overflows: an attacker sends data that exceeds the memory buffer allocated for it, overwrites adjacent memory, and can execute arbitrary code. All are remotely exploitable.
CVE-2026-90702 and CVE-2026-90703 affect the DWR-M921, with CVSS 9.1. These are OS command injection vulnerabilities. An attacker can send crafted input through the web management interface that the device passes directly to the operating system as a command. The exploits for these have been publicly disclosed.
Publicly disclosed exploits are significant. It removes the technical barrier for lower-skilled attackers. You no longer need a sophisticated threat actor to exploit a CVSS 9.9 buffer overflow in a D-Link router when the exploit code is already published.
D-Link routers appear regularly in small business environments. They are inexpensive, widely available, and frequently unmanaged. If you have a DIR-823G, DIR-878, or DWR-M921 on your network and have not checked for firmware updates, do it now.
If firmware updates are not available for your model, the immediate mitigation is to ensure the web management interface is not exposed to the internet. Management access should be restricted to the local network only. If you are unsure whether this is the case, ask whoever manages your network.
Why This Matters If You Think You’re Too Small
Two patterns are worth naming directly.
First, the Cisco SEG situation illustrates supply chain risk. Most small businesses do not run their own email filtering infrastructure. They rely on their MSP, or on a cloud email security product. The question is not whether you personally run Cisco SEG. The question is whether anyone in your supply chain does, and whether they have patched it.
Second, the D-Link situation illustrates what happens when cheap network hardware is deployed and forgotten. Routers do not advertise when they need patching. They sit quietly in a corner, routing traffic, until an attacker finds the CVE on NVD and points a script at your IP address.
The NCSC’s Cyber Essentials framework requires that all software, including firmware on network devices, be kept up to date and that unnecessary services be disabled. The D-Link vulnerabilities are a precise illustration of why that control exists.
How This Gives You an Edge
Organisations that respond to active exploitation intelligence faster than their peers reduce their window of exposure. That is not a marketing claim. It is the logical consequence of patching before an attacker arrives versus patching after.
If you are an SMB that can say to a prospective client or partner: we have a process for monitoring CISA’s Known Exploited Vulnerabilities catalogue and we act on critical items within 24 to 48 hours, that is a verifiable, differentiated position. Most organisations of your size cannot say that.
Cyber Essentials Plus certification requires evidence of timely patching. Using CISA KEV additions as a trigger for urgent patching action is a defensible, auditable process.
Making the Business Case
Three points worth raising with whoever controls your IT budget:
Active exploitation is not a future risk. CVE-2026-76461 is on CISA’s Known Exploited Vulnerabilities list. That means attackers are using it now, against real targets. The patching window is not months. It is days.
The cost of inaction is asymmetric. A ransomware incident originating from an unpatched email gateway or a compromised router will cost significantly more in recovery, regulatory notification, and reputational damage than the cost of an emergency patching exercise or a router replacement.
Your supply chain is your risk surface. If your MSP or email provider runs Cisco SEG, their patch status is your problem. Ask the question. Document the answer. If the answer is unsatisfactory, it is relevant to your vendor risk assessment.
What to Do Before Friday
-
Check your email security stack. Ask your MSP or IT provider whether your email filtering routes through Cisco Secure Email Gateway. If it does, ask for written confirmation that CVE-2026-76461 has been patched and when the patch was applied.
-
Audit your router inventory. Check whether you have any D-Link DIR-823G, DIR-878, or DWR-M921 devices on your network. If you do, check the manufacturer’s website for available firmware updates and apply them. If you do not know what routers you have, that is the first problem to solve.
-
Confirm management interfaces are not internet-exposed. For any network device, the web management interface should not be reachable from the public internet. Your ISP or IT provider can confirm this. If it is exposed, restrict it to local network access immediately.
-
Subscribe to CISA’s KEV feed. CISA publishes its Known Exploited Vulnerabilities catalogue publicly at cisa.gov. New additions represent confirmed active exploitation. Monitoring this feed is free and takes minutes to set up.
-
Ask your MSP what their patch SLA is for CISA KEV items. If they do not have a defined response time for actively exploited vulnerabilities, that gap needs to be addressed in your service agreement.
Before you go: follow the show wherever you listen, and if it is useful, leave a rating or review. It genuinely helps. Drop a comment with your thoughts, and share this episode with someone who should probably know about the Cisco situation before their weekend.