Find notable cyber news and cases, enriched with sources, timelines, and signals.

Cisco Secure Email Gateway insufficient validation flaw (CVE-2026-76461)

Vulnerability
First reported
Last updated
Happening score
H score 45
2 unique sources, 2 articles

Summary

Hide ▲

Cisco Secure Email Gateway devices are exposed to CVE-2026-76461, an actively exploited email-parsing flaw that can let an unauthenticated remote attacker execute commands with root privileges. Cisco says the weakness affects both physical and virtual appliances and released fixes for 15.5 and earlier, 16.0, and 16.5. There are no workarounds beyond upgrading, and Cisco warned that exploitation can hide evidence on the device. CISA added the CVE to KEV and set a September 17, 2026 deadline for FCEB patching.

Timeline

  1. 15.09.2026 09:11 3 articles · 2h ago

    Cisco warns CVE-2026-76461 is under active exploitation

    Initial Disclosure

    Cisco warned that CVE-2026-76461 in AsyncOS Software for Cisco Secure Email Gateway is under active exploitation and that a crafted email carrying malicious SQL can let an unauthenticated remote attacker execute arbitrary SQL statements and reach root-level command execution on Cisco Secure Email Gateway devices. Cisco listed fixed builds for 15.5 and earlier, 16.0, and 16.5, said there are no workarounds other than updating to the latest supported version, and advised reviewing mail_logs and running grep -i "COPY.*TO PROGRAM" against IronPort Text Mail Logs for suspicious activity.

    Show sources
  2. 15.09.2026 09:11 1 articles · 2h ago

    CISA adds CVE-2026-76461 to KEV catalog and sets September 17, 2026 deadline

    Legal Policy Action Update

    CISA added CVE-2026-76461 to the Known Exploited Vulnerabilities catalog and required Federal Civilian Executive Branch agencies to apply the available patches by September 17, 2026. Cisco warned that successful exploitation can yield command execution with root privileges and that evidence of exploitation may be removed or hidden on the impacted device.

    Show sources