[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fGf56T5bTvnAWwfvzqIx4WySTV4PqNQ882NFw6KTp_VM":3},{"article":4,"iocs":45},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":27,"category":28,"article_tags":32},"6ec43bc1-2059-4e7a-9c41-e5d9871cdd3f","Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution","cisco-secure-email-gateway-flaw-exploited-in-the-wild-enables-root-command-execu-afc835","Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing logic that could allow an unauthenticated, remote attacker","Cisco has issued a critical warning about CVE-2026-76461, a vulnerability in its Secure Email Gateway software that allows unauthenticated remote attackers to execute arbitrary commands with root privileges. The flaw, stemming from insufficient validation in email parsing logic, is actively being exploited in the wild. Cisco has released patches for affected versions and advises customers to update immediately, as there are no workarounds.","Cisco Secure Email Gateway flaw exploited in the wild, enabling root command execution.","Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution Ravie LakshmananSep 15, 2026Vulnerability \u002F Network Security Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing logic that could allow an unauthenticated, remote attacker to run arbitrary commands with root privileges on the underlying operating system. \"An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device,\" Cisco said in a Monday advisory. \"A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.\" The shortcoming affects Cisco Secure Email Gateway, both physical and virtual, regardless of device configuration. However, the networking equipment maker said other products like Secure Email and Web Manager and Secure Web Appliance are not impacted. Fixes are available for the following versions of Cisco AsyncOS for Cisco Secure Email Gateway Software Release - 15.5 and earlier (Fixed in 15.5.5-0141) 16.0 (Fixed in 16.0.4-302) 16.5 (Fixed in 16.5.0-780) There are no workarounds other than updating to the latest supported version. Cisco said it became aware of active exploitation of this vulnerability this month, sharing the following indicators of compromise (IoCs) - Review mail_logs and look for suspicious SQL statements. If the device is part of a cluster, review the logs of each cluster device. To detect potentially malicious SQL statements, it's advised to run the command: cisco-esa> grep -i \"COPY.*TO PROGRAM\" [IronPort Text Mail Logs Log name - Default: mail_logs] The presence of any entry in the output may indicate malicious activity. Cisco also said it has directly contacted customers who own Cisco Secure Email Cloud devices on which malicious activity was detected. It did not disclose the scale of the attacks. \"Upon successful exploitation of this vulnerability, threat actors may obtain command execution with root privileges,\" the company warned. \"Because of this level of access, evidence of exploitation and indicators of compromise may be removed or hidden by the threat actors.\" As a result, administrators are recommended to cross-check the network logs and the firewall logs outside of the impacted device to identify any potential anomalous activity, including unexpected uploads that were initiated from the affected device to external IP addresses or downloads from malicious IP addresses. The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add CVE-2026-76461 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 17, 2026. Large-Scale Credential Attacks Target Fortinet VPNs The disclosure comes days after Arctic Wolf said it detected large-scale credential attacks targeting internet-facing Fortinet VPN appliances in late August 2026. The high-volume activity took place over two sustained waves across multiple U.S. customer environments from August 26 through August 28, 2026, generating tens of millions of authentication failures. \"The actor used organization-specific usernames, corporate email addresses, affiliate accounts, and common administrative identities, indicating access to previously collected or enumerated identity information,\" security researcher Kyle Siddall said. \"The attempted usernames included employee names, corporate email addresses, affiliate identities, and common administrative accounts associated with the targeted organizations. This targeted identity selection, rather than generic username spraying, indicates access to previously collected or enumerated identity information.\" In one observed case, a successful Fortinet VPN authentication originating from the IP address \"158.94.211[.]14\" was followed by malicious activity in the affected environment. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  cisco, Credential Attack, email security, network security, remote code execution, Vulnerability ⚡ Top Stories This Week OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure Claude Used to Automate Exploitation and Data Theft Across Multiple Victims Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6 Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks When the Whole Company Adopts AI: What It Does to Your SOC Your Critical Vulnerabilities Might Not Be Your Biggest Risk What It Took to Reach 1 Billion Build Manifests US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries Why Are So Many Security Professionals Keeping Breaches Quiet? The Economics of Dwell Time and Why AI Native SIEM Changes the Equation ⭐ Featured Resources Get the eBook: Map Enterprise AI Risk Across the Full Lifecycle Give SOC Analysts Visibility Into 90% of Attacks Within 60 Seconds Benchmark Your SOC's AI Adoption With the 2026 Security Operations Report Register for LDR516: Strategic Vulnerability and Threat Management at SANS DC Metro","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fcisco-secure-email-gateway-flaw.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEhu8z5yuk0NLq0i2IvKx9dibCdw5at8BanYNBhjn665PLV0EanY_s0UV0D4D0wcPijyd5r8sS4eCMDwKdsVQ9GktnqcPRympe7ZqI7Bh8ZSBukLsxFSQ3-SFRb10ylKsDPl7tU2-M3w_E0eNSe_ytrRE-JZ62fvAExuQCawQJZFjYwArFC550Ri8mOQ1q1s\u002Fs1600\u002Fcisco-email.jpg","2026-09-15T06:11:11+00:00","2026-09-15T08:00:19.457663+00:00",9,[18,21,24],{"name":19,"type":20},"Cisco Secure Email Gateway","product",{"name":22,"type":23},"Cisco","vendor",{"name":25,"type":26},"AsyncOS Software","technology","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":27,"icon":29,"name":30,"slug":31},null,"Vulnerabilities","vulnerabilities",[33,38,40],{"category":34},{"id":35,"icon":29,"name":36,"slug":37},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":39},{"id":27,"icon":29,"name":30,"slug":31},{"category":41},{"id":42,"icon":29,"name":43,"slug":44},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[46,50,54],{"type":47,"value":48,"context":49},"cve","CVE-2026-76461","Critical vulnerability in Cisco Secure Email Gateway",{"type":51,"value":52,"context":53},"malware","SQL statements","Crafted email messages containing malicious SQL statements used to exploit the vulnerability",{"type":55,"value":56,"context":57},"mitre_attack","T1059.004","SQL Query execution for command execution"]