This week's zero-days: Cisco Secure Email Gateway, Chrome and Windows — what to patch today in your Mexico operation
Two advisories came out today, September 15, 2026, and both reach the average office in Mexico. Cisco patched a zero-day in its Secure Email Gateway (the appliance that filters mail before it reaches Outlook) that was already being exploited, as BleepingComputer reported. A zero-day is a flaw attackers use before a fix exists.
The same day, The Hacker News reported that a China-linked group is chaining a Chrome flaw with a Windows flaw to install malware called GRIMWEDGE. A normal PC, a normal browser, one web page.
If headquarters is abroad and the Mexico site runs with a small IT team or none, here is what to check, in what order, and what to look for if you suspect someone already got in.
Which devices are exposed
Cisco email gateways (ESA, or IronPort if you have been around a while) are common in corporate offices, maquiladoras and plants that inherited the setup from headquarters. Nobody looks at them: they sit in a rack in Monterrey or Tijuana and filter spam quietly. That is exactly why nobody remembers when they were last updated.
The flaw allows running commands as root, meaning full control of the appliance, according to The Hacker News. And that appliance sees every email going in and out of your Mexico operation.
The second front is wider. Chrome and Edge share the same engine, so the chain applies to both. Anyone at the Mexico office on Windows with a browser open is on the list: the accountant, the receptionist, the plant manager.
How to verify in five minutes
| Device | Where to see the version | What to look for |
|---|---|---|
| Cisco ESA / IronPort | Web console, Monitor › System Status, or the version command over SSH | It matches the fixed release in the Cisco advisory |
| Chrome | chrome://settings/help | It says up to date and does not ask for a relaunch |
| Edge | edge://settings/help | Same |
| Windows | Settings › Windows Update | September updates already installed |
If a local vendor manages the gateway, today is the day to call and ask, in writing, for the version and the patch date. In our experience that call tends to reveal appliances nobody has touched in a long time. It also helps to find out who at headquarters actually owns that box.
Patch order
- Email gateway first. It faces the internet and it is already under attack. Back up the configuration, apply the Cisco patch and confirm mail keeps flowing.
- Browsers by policy. Do not rely on each person clicking update. Push the version with Group Policy, Intune or whatever you use, and force a browser relaunch. This works fine from abroad; nobody needs to be on site.
- Windows last, with a window. Agree a maintenance slot with the plant, outside production hours, and have local hands on call in case a server does not come back.
What to check if you were already hit
Patching closes the door, but it does not remove whoever is already inside. Spend one hour on these three things:
- New accounts. On the gateway, in the domain and in Microsoft 365 or Google Workspace. A user nobody remembers creating is a clear sign.
- Forwarding rules. Check whether any mailbox sends a copy of everything to an external address. It is the favorite trick for reading the country manager’s email unnoticed.
- Odd outbound traffic. Connections from the gateway or from a PC to addresses you do not recognize, especially at night. Your firewall should have the log.
If you find something, do not delete it: change passwords, isolate the device and get help. Deleting evidence makes it harder to know what was taken.
Who handles this every week
This week it was Cisco, Chrome and Windows. Next week it will be another vendor. The real question is who reads the advisories for your Mexico site, decides what is urgent and applies the patch without breaking anything.
An IT support plan with SLA includes exactly that: patch management, a maintenance window agreed with you and a backup before every change. Remote work from anywhere, in English or Spanish, plus local hands in Mexico when the gateway needs a physical reboot.
And in your Mexico operation?
If you cannot say for certain which version your email gateway runs, or how many PCs in Mexico still have an old Chrome, that is today’s to-do.
We run a free perimeter exposure review: we tell you which devices face the internet, which ones are missing patches and in what order to fix them.
Request your exposure review — we reply the same business day.
Your path
Running IT in Mexico from abroad
12 of 32- Smart hands ✓ Read You are here 2 min
- Remote support ✓ Read You are here 3 min
- Nearshoring checklist ✓ Read You are here 2 min
- Retail rollouts ✓ Read You are here 2 min
- Fake IT support ✓ Read You are here 3 min
- Backups that restore ✓ Read You are here 3 min
- Secure M365 ✓ Read You are here 3 min
- Windows 10 deadline ✓ Read You are here 4 min
- Audit app access ✓ Read You are here 3 min
- CEO fraud ✓ Read You are here 4 min
- Office 2016 cutoff ✓ Read You are here 3 min
- Patch today ✓ Read You are here 4 min
- Patch VMware ✓ Read You are here 4 min
- Office 2021 EOL ✓ Read You are here 3 min
- Starlink for sites ✓ Read You are here 3 min
- Cardless access ✓ Read You are here 4 min
- Control AI on PCs ✓ Read You are here 4 min
- ScreenConnect flaw ✓ Read You are here 4 min
- Server 2022 EOL ✓ Read You are here 3 min
- Exposed cameras ✓ Read You are here 3 min
- Domain trust fix ✓ Read You are here 4 min
- Patch Cisco ISE ✓ Read You are here 3 min
- Protect the plant ✓ Read You are here 3 min
- Move to 25H2 ✓ Read You are here 4 min
- Outages and UPS ✓ Read You are here 3 min
- IT maintenance ✓ Read You are here 4 min
- Third-party scripts ✓ Read You are here 3 min
- License audit ✓ Read You are here 4 min
- Bajío fiber corridor ✓ Read You are here 3 min
- Check Point flaw ✓ Read You are here 4 min
- Cashless payments ✓ Read You are here 3 min
- AI that hacks alone ✓ Read You are here 3 min
- Field services →