Handler on Duty: Guy Bruneau
Threat Level: green
Podcast Detail
SANS Stormcast Friday, September 4th, 2026: AV Exploits; Plex Update; Cisco Patches; Sangoma Switchvox Exploited
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10082.mp3
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
Nightmare Eclipse Discloses Several Anti-Malware Privilege Escalation Exploits
https://github.com/MSNightmare
Plex Update
https://forums.plex.tv/t/important-security-update-for-plex-media-server-v1-43-2-and-earlier/942319
Cisco Update
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-smime-disc-dzw4rEdY
Sangoma Switchvox Exploit
https://horizon3.ai/attack-research/disclosures/cve-2026-9586-sangoma-switchvox-rce/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
| Application Security: Securing Web Applications, APIs, and Microservices | Las Vegas | Sep 21st - Sep 25th 2026 |
| Network Monitoring and Threat Detection In-Depth | Amsterdam | Oct 12th - Oct 17th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | India Standard Time | Mar 15th - Mar 19th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Orlando | Apr 12th - Apr 16th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Mountain | Apr 21st - Apr 25th 2027 |
Podcast Transcript
Hello and welcome to the Friday, September 4th, 2026 edition of the SANS Internet Storm Center's Stormcast. My name is Johannes Ullrich and today I am recording from Jacksonville, Florida. And this episode is brought to you by the SANS.edu Graduate Certificate Program in Penetration Testing and Ethical Hacking. Nightmare Eclipse is added again, this time not targeting Microsoft but still sticking to the theme of targeting anti -malware products. There are three new vulnerabilities and exploits released by Nightmare Eclipse. The first one Falcon Flank is targeting CrowdStrike and the second one Hard Breacher is targeting Kaspersky's Antivirus and then we also have a third one, Pretty Prague, that one is targeting Avast Antivirus. Antivirus products have this hard task of parsing complex structures as they're trying to make sense of files whether or not they're malicious or not. And at the same time of course in order to not be affected by malware themselves, they usually run with very high and elevated privileges. So any vulnerability in an anti -malware product immediately with that becomes a severe privilege escalation vulnerability. And we have seen this with the Microsoft exploits of course from Nightmare Eclipse in the past but overall this is not a new problem. In the past it has often been ignored. So if anything let's hope that these sort of more public and more newsworthy kind of exploits are actually changing a little bit that people are taking some of these privilege escalation vulnerabilities in anti-malware products more serious and that they get the attention they deserve. And Plex released an advisory stating that users should immediately update the latest and greatest version of Plex that was released earlier this week. Sadly we don't really have any details as to what the vulnerabilities are. They haven't been able to get CVE numbers for them yet but apparently they consider them critical enough where they are releasing this advisory. Luckily Plex does a decent job in updating itself so there's nothing really that you may need to do. You may still want to verify that all worked and that you actually got the latest version 143.3 and for desktop it's 1.115. The problem cases here with Plex particularly on the server side are often sort of various NAS devices and such that come with Plex installed. That's usually installed as a package from the vendor and as Plex points out the vendor may not have released an updated package for it yet. They recommend that you should then manually update. They don't have one of those devices so not sure how difficult that is and if that later may then break additional updates that are released by the vendor in the form of a package in case they sort of customized anything there. And Cisco released a couple of interesting advisories. One for iOS XR. This fixes a total of seven vulnerabilities. One of them has a CVSS score of 9 .8. This one and then at least two more do have some of the standard memory management flaws so they do have remote code execution potential. There is also an update for the secure email appliances from Cisco. That particular vulnerability is only rated as a medium and it's a denial of service vulnerability in the S MIME feature. So if you're sending encrypted email with S MIME there are some denial of service conditions here that may be triggered. And Horizon 3 is reporting that they're seeing active exploitation against Switchvox vulnerability. Switchvox is an enterprise voice over IP management system. It comes from Sangoma. Sangoma is also known for free PBX and as Horizon 3 said well after a few critical vulnerabilities in free PBX they took a closer look at Switchvox and found some issues there as well. And then also saw at least one of these vulnerabilities already being exploited. So certainly make sure that you keep this product up to date and properly configured. Well and that's it for today. So thanks for listening. Thanks for liking. Thanks for subscribing. And we'll talk to you again on Tuesday, not on Monday, because Monday is a holiday here in the US. So you you you you





