Last verified: Sep 16, 2026.
At a glance
- CVE-2026-76461 (Cisco): Critical 9.8 SQL injection; CISA KEV Sep 14, due Sep 17; UAT-9686 China-nexus attribution
- Veradigm breach: 3.5M patient records claimed (The Gentlemen); 8-K filed Sep 9
- Boston Scientific: Ongoing cyberattack; distribution network reset; Sep 9 update
- Healthcare breach wave: Aesto (9.5M), DaVita (2.4M, $15M settlement), MCNA (8.9M, $6.4M fees)
- Interim HealthCare: Two ransomware groups listing same target (GENESIS + another)
- Common vector: Third-party / vendor compromise in all three major events
The Cisco story in one paragraph
CVE-2026-76461 is a true zero-day SQL injection (CVSS 9.8) in Cisco AsyncOS for Secure Email Gateway. Cisco PSIRT identified the bug on September 1, 2026 while resolving a customer support case, confirmed active in-the-wild exploitation in September 2026, and published advisory cisco-sa-esa-inj-2bLVGmhX on September 14, 2026. CISA added the CVE to the Known Exploited Vulnerabilities catalog the same day with a federal remediation due date of September 17, 2026. Talos assesses with moderate confidence that the actor is UAT-9686, a China-nexus group that has been exploiting Cisco appliance trust relationships since November 2025 (Talos threat assessment, September 14, 2026).
Fixed releases are AsyncOS 15.5.5-0141, 16.0.4-3021, and 16.5.0-780. Cisco recommends migrating to 16.5.0-780 (the long-term branch). There are no workarounds. The actor deploys AquaShell (Python backdoor), AquaTunnel (ReverseSSH-based tunnel), and AquaPurge (log cleaner) after exploitation.
The Veradigm story in one paragraph
Veradigm disclosed a patient data breach on September 9, 2026 after The Gentlemen ransomware group claimed 3.5 million patient records. An attacker obtained credentials from a third-party vendor's environment for a Veradigm API reserved for customer services, then used those credentials to copy patient data. Exposed data includes names, Social Security numbers for some patients, addresses, phone numbers, and guarantor PII. Clinical data was not accessed. Veradigm filed an 8-K with the SEC the same day. The Gentlemen threatened to publish the dataset on September 11, 2026 (Veradigm 8-K filing, BleepingComputer, September 9, 2026).
The vendor compromise is the defining characteristic. Veradigm said access was limited to a specific interface and did not impact the company's broader environment. The credential theft pattern has become the dominant healthcare-cyber incident of 2026: compromise a third party, harvest valid API credentials, pull data through an interface that was never designed to be exposed.
The Boston Scientific story in one paragraph
Boston Scientific disclosed on September 9, 2026 that its previously announced cyberattack has continued to cause operational issues. The medical device giant had to undergo a substantial portion of its distribution network reset. Boston Scientific is a Fortune 500 medical device company with global operations; the cyberattack has disrupted its commercial operations for several weeks. The company has been working to recover some systems, though full remediation is ongoing (The Record, September 9, 2026).
Boston Scientific's situation illustrates the difference between data-breach incidents (Veradigm) and operational-impact incidents. The economic damage from operational disruption — lost shipments, halted manufacturing, delayed procedures — can dwarf the cost of a pure data breach.
The healthcare breach wave in September 2026
Veradigm is the third major healthcare breach of September 2026. Aesto Health confirmed 9.5 million records. DaVita confirmed 2.4 million records (with a $15 million settlement). MCNA Dental confirmed 8.9 million records (with $6.4 million in fees). The Gentlemen ransomware gang has also listed Interim HealthCare (a home health and hospice provider operating in roughly 40 U.S. states) and Nutex/AnMed on its leak site (HIPAA Journal, September 9, 2026).
Interim HealthCare of Oklahoma City reported a cybersecurity incident to HHS on July 31, 2026, a filing that HIPAA's breach notification rule requires whenever protected health information belonging to 500 or more people is compromised. Two separate ransomware groups — GENESIS and an unidentified second group — have listed Interim HealthCare. The Oklahoma City breach notice lists names, addresses, Social Security numbers, dates of birth, medical information, and insurance information among the data types potentially exposed.
What the September pattern tells us
Third-party compromise is the dominant initial-access vector in 2026. In each of the three major September events — Cisco, Veradigm, Boston Scientific — the headline breach is at a large enterprise, but the actual entry point is at a smaller, less-defended upstream entity. UAT-9686 exploits Cisco appliance trust relationships; Veradigm is compromised via a vendor's API credentials; Boston Scientific's disruption stems from its distribution network's exposure to upstream suppliers.
For security leaders, the pattern has clear implications: vendor risk management has overtaken perimeter security as the highest-impact control. Every API credential issued to a vendor is a trust decision that should be reviewed quarterly. Behavioral anomaly detection on vendor API traffic catches the credential-stuffing pattern earlier than rate-based detection.
What to watch next
Three near-term datapoints. First, the September 17 federal remediation deadline for CVE-2026-76461 will produce the first wave of agency breach disclosures if any agency misses the deadline. Second, the HHS Office for Civil Rights breach portal will confirm or deny the Veradigm 3.5M record count within the 60-day HIPAA notification window. Third, any Boston Scientific operational impact update will surface in the next quarterly earnings call or 8-K filing.






