CVE Tools
Back to feed
Exploited in the wild Cisco Secure Email Gateway rce Cisco zero-day

Шлюзы Cisco Secure Email Gateway можно взломать с помощью вредоносного письма

Хакер (xakep.ru)·By Мария Нефёдова··2 min read
CVE Tools coverage

Cisco has patched CVE-2026-76461, a CVSS 9.8 vulnerability in Cisco Secure Email Gateway appliances and virtual deployments running AsyncOS. Attackers are actively exploiting the flaw by sending crafted email containing SQL commands, which can lead to arbitrary SQL execution and root-level command execution.

Cisco Secure Email Cloud has been updated to AsyncOS 16.5.0-780. Organizations should update to AsyncOS 15.5.5-014, 16.0.4-302, or 16.5.0-780, preferably the latest release, and investigate mail, network, and firewall logs because attackers with root access may remove local evidence.