AI Stories on SHORT INFO are generated & curated with AI
2 linked sources 15 Sept, 18:53

Cisco Secure Email Gateway zero-day under active exploitation

Cisco $CSCO warns that a critical zero-day in its Secure Email Gateway is being actively exploited, letting unauthenticated attackers gain root access with a single crafted email. CISA has ordered federal agencies to patch by September 17.

Cisco $CSCO confirms attackers are actively exploiting CVE-2026-76461, a 9.8-severity flaw in the email parsing logic of its AsyncOS software for Secure Email Gateway appliances. A crafted email containing malicious SQL statements lets an unauthenticated attacker execute commands with root privileges on the underlying system, no login required. Cisco has contacted customers whose Secure Email Cloud devices showed signs of compromise but has not disclosed the scale. CISA added the flaw to its Known Exploited Vulnerabilities catalog, giving federal agencies until September 17, 2026 to patch. Security researchers at Shadowserver count more than 400 of these gateways still reachable from the open internet. Cisco has released fixed software for all affected release branches.

#cyber
Published on