SPOJENO AI KEV ✓ EPSS 0.02
Kritische Sicherheitslücke in Cisco Secure Email Gateway - aktiv ausgenutzt - Updates verfügbar
15. September 2026 Beschreibung In Cisco Secure Email Gateway existiert eine kritische Sicherheitslücke. Bei erfolgreicher Ausnutzung könnte diese Sicherheitslücke es nicht authentifizierten Angreifer:innen aus der Ferne ermöglichen Befehle mit Root-Rechten auf dem zugrunde liegenden Betriebssystem auszuführen. Laut Cisco wurde eine Ausnutzung der Sicherheitslücke bereits beobachtet. CVE-Nummer(n): CVE-2026-76461 CVSS Base Score: 9.8 Auswirkungen Ein Angreifer könnte diese Sicherheitslücke…
Cisco veřejná správa AT RO SE US FI GB FR CA NL IT
CVE v události 1
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2026-76461 | 9.8 3.1 · cisco | KEV ✓ | 0.02 |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.8.
Dalších 5 CVE zmiňuje jen text zpravodajského článku (CVE-2025-20393, CVE-2026-20353, CVE-2026-76440, CVE-2026-76441, CVE-2026-76443). Nejsou to identifikátory téhle události, proto nejsou v tabulce ani v odznacích.
Jak se o tom psalo 14
-
· CERT.at AT nadpis události
Kritische Sicherheitslücke in Cisco Secure Email Gateway - aktiv ausgenutzt - Updates verfügbar
15. September 2026 Beschreibung In Cisco Secure Email Gateway existiert eine kritische Sicherheitslücke. Bei erfolgreicher Ausnutzung könnte diese Sicherheitslücke es nicht authentifizierten Angreifer:innen aus der Ferne ermöglichen Befehle mit Root-Rechten auf dem zugrunde liegenden Betriebssystem auszuführen. Laut Cisco wurde eine Ausnutzung der Sicherheitslücke bereits beobachtet. CVE-Nummer(n): CVE-2026-76461 CVSS Base Score: 9.8 Auswirkungen Ein Angreifer könnte diese Sicherheitslücke…
-
· DNSC Rumunsko RO
ALERTĂ: Vulnerabilitate exploatată activ în Cisco AsyncOS
DESCRIERE Experții în securitate cibernetică au descoperit o vulnerabilitate critică, CVE-...
-
· CERT-SE SE
Kritisk sårbarhet i Cisco Secure Email Gateway utnyttjas aktivt
Cisco har publicerat information om en kritisk SQL injection-sårbarhet i Cisco Secure Email Gateway som utnyttjas aktivt. Sårbarheten (CVE-2026-76461) har fått CVSS-klassificering 9.8 (CVSS v.3.1). [1] CISA har lagt till sårbarheten i KEV-katalogen (Known Exploited Vulnerabilities catalog). [2]
-
· Rapid7 US
CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
OverviewOn September 14, 2026, Cisco published a security advisory for CVE-2026-76461, a critical SQL injection vulnerability affecting Cisco AsyncOS Software for Cisco Secure Email Gateway. The vulnerability has a reported CVSS v3.1 base score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on an affected appliance.Cisco Secure Email Gateway, formerly known as IronPort Email Security Appliance, is an enterprise email security…
-
· BleepingComputer US
Cisco patches Secure Email Gateway zero-day exploited in attacks
Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks. [...]
-
· NCSC-FI FI
Cisco Secure Email Gateway SQL Injection Vulnerability
Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: 9.8, CVEs: CVE-2026-76461, Summary: A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted…
-
· Sophos Threat Research GB
Cisco Secure Email Gateway vulnerability (CVE-2026-76461) in active exploitation
Categories: Threat ResearchTags: advisory, vulnerability, Cisco
-
· CERT-FR – avis FR
Multiples vulnérabilités dans les produits Cisco (15 septembre 2026)
De multiples vulnérabilités ont été découvertes dans les produits Cisco. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une injection SQL (SQLi). Cisco indique que la vulnérabilité CVE-2026-76461 est...
-
· Cyber Centre Kanada CA
Cisco security advisory (AV26-921)
Serial Number: AV26-921Date: September 14, 2026 As of September 14, 2026, Cisco is affected by vulnerabilities in the following products: Cisco AsyncOS for Cisco Secure Email Gateway Prior to 15.5.5-014 Prior to 16.0.4-302 Prior to 16.5.0-780 Cisco Secure Email Gateway Prior to 15.5.5-014 Prior to 16.5.0-780 Cisco Secure Email and Web Manager Prior to 15.5.5-006 Prior to 16.5.0-429 On September 14, 2026, Cisco stated that CVE-2026-76461 is being actively exploited. On September 14, 2026,…
-
· NCSC-NL NL
NCSC-2026-0368 [1.00] [H/H] Kwetsbaarheid verholpen in Cisco Secure Email Gateway
Cisco heeft een kwetsbaarheid verholpen in Cisco Secure Email Gateway. De kwetsbaarheid bevindt zich in de verwerking van e-mailberichten binnen Cisco AsyncOS Software voor Cisco Secure Email Gateway en wordt veroorzaakt door onvoldoende validatie van inkomende e-mailberichten. Een niet-geauthenticeerde kwaadwillende kan een speciaal vervaardigd e-mailbericht met kwaadaardige SQL-instructies naar een kwetsbaar systeem versturen. Succesvol misbruik kan leiden tot het uitvoeren van willekeurige…
-
· CSIRT Itálie (ACN) IT
Cisco: sfuttamento in rete della CVE-2026-76461 relativa a Secure Email Gateway
Cisco ha rilasciato aggiornamenti di sicurezza per sanare 6 vulnerabilità, di cui 5 con gravità "critica" e una con gravità "alta", che interessano Cisco Secure Email Gateway, soluzione per la protezione e la gestione della posta elettronica, e Cisco Secure Email and Web Manager, piattaforma per la gestione centralizzata dei relativi servizi di sicurezza.
-
· Cisco PSIRT US
Cisco Secure Email Gateway SQL Injection Vulnerability
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the…
-
· CISA Advisories US
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian…
-
· CISA KEV US
Cisco Secure Email Gateway SQL Injection Vulnerability (CVE-2026-76461)
CISA added CVE-2026-76461 to the Known Exploited Vulnerabilities catalog. Affected product: Cisco Secure Email Gateway. Remediation due date: 2026-09-17.