Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Cisco Secure Email Gateway Flaw Exploited in the Wild: A Critical Vulnerability Affects AsyncOS Software




A critical vulnerability has been discovered in Cisco Secure Email Gateway, which could allow an unauthenticated, remote attacker to run arbitrary commands with root privileges on the underlying operating system. The vulnerability, tracked as CVE-2026-76461, has already been identified as a case of insufficient validation in the email parsing logic. Fixes are available for the affected versions of Cisco AsyncOS, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. Stay up-to-date with the latest security patches and best practices to protect your organization from this and other emerging threats.

  • Send a crafted email message with malicious SQL statements to exploit the vulnerability (CVE-2026-76461) in Cisco Secure Email Gateway.
  • The vulnerability affects both physical and virtual devices, regardless of configuration.
  • Fixes are available for Cisco AsyncOS versions 15.5 and earlier, as well as 16.0 and 16.5.
  • Cisco has contacted affected customers and shared indicators of compromise (IoCs) with the public.
  • Run the command "cisco-esa> grep -i \"COPY.*TO PROGRAM\"" to detect potentially malicious SQL statements.
  • Check network logs, firewall logs, and review mail_logs for suspicious activity.
  • CISA has added CVE-2026-76461 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply patches by September 17, 2026.
  • Recent cybersecurity incidents include large-scale credential attacks, ChatGPT flaws, WeChat Zero-Click Worms, and Fake IT Calls.



  • The cybersecurity landscape has been rocked by the recent discovery of a critical vulnerability in Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution. The vulnerability, tracked as CVE-2026-76461, has already been identified as a case of insufficient validation in the email parsing logic that could allow an unauthenticated, remote attacker to run arbitrary commands with root privileges on the underlying operating system.

    According to Cisco, the vulnerability could be exploited by sending a crafted email message that contains malicious SQL statements through an affected device. This could potentially lead to the execution of arbitrary SQL statements, resulting in command execution with root privileges on the underlying operating system. The shortcoming affects Cisco Secure Email Gateway, both physical and virtual, regardless of device configuration.

    However, it's worth noting that other products like Secure Email and Web Manager and Secure Web Appliance are not impacted. Fixes are available for the following versions of Cisco AsyncOS for Cisco Secure Email Gateway Software Release 15.5 and earlier, as well as versions 16.0 and 16.5.

    Cisco has directly contacted customers who own Cisco Secure Email Cloud devices on which malicious activity was detected. It has also shared indicators of compromise (IoCs) with the public, including the need to review mail_logs and look for suspicious SQL statements. If the device is part of a cluster, reviewing the logs of each cluster device is also recommended. To detect potentially malicious SQL statements, it's advised to run the command: cisco-esa> grep -i "COPY.*TO PROGRAM" [IronPort Text Mail Logs Log name - Default: mail_logs].

    The presence of any entry in the output may indicate malicious activity. Furthermore, administrators are recommended to cross-check the network logs and the firewall logs outside of the impacted device to identify any potential anomalous activity, including unexpected uploads that were initiated from the affected device to external IP addresses or downloads from malicious IP addresses.

    This vulnerability has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add CVE-2026-76461 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 17, 2026.

    In addition to this vulnerability, there are several other cybersecurity incidents that have been reported recently, including large-scale credential attacks targeting internet-facing Fortinet VPN appliances in late August 2026. The high-volume activity took place over two sustained waves across multiple U.S. customer environments, generating tens of millions of authentication failures.

    Furthermore, ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account, while WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls. Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks have also been reported.

    These incidents highlight the importance of staying vigilant and up-to-date with the latest security patches and best practices. As the threat landscape continues to evolve, it's essential to be proactive in identifying and addressing vulnerabilities before they can be exploited.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Cisco-Secure-Email-Gateway-Flaw-Exploited-in-the-Wild-A-Critical-Vulnerability-Affects-AsyncOS-Software-ehn.shtml

  • https://thehackernews.com/2026/09/cisco-secure-email-gateway-flaw.html

  • https://cybersecuritynews.com/cisco-secure-email-gateway-flaw-exploited/


  • Published: Tue Sep 15 02:15:05 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us