Security news
Latest security news
Yesterday · Tue, 15 Sept 2026
- Cisco email security boxes can be rooted by... an email
Attackers already exploiting the critical flaw, and Cisco warns they may be able to cover their tracks once they're in
The RegisterCisco - Cisco warns customers of actively exploited zero-day in email gateways
The company confirmed the defect was exploited before it was disclosed and patched, but it did not describe the nature of the attacks or the scope of impact across its customer base.
CyberScoopCisco - CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
Overview On September 14, 2026, Cisco published a security advisory for CVE-2026-76461 , a critical SQL injection vulnerability affecting Cisco AsyncOS Software for Cisco Secure Email Gateway. The vulnerability has a reported CVSS v3.1 base score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on an affected appliance. Cisco Secure Email Gateway, formerly known as IronPort Email Security Appliance, is an enterprise email security product that inspects inbound and outbound email for threats including phishing, malware, spam, and business email compromise. Because affected gateways process externally delivered email as part of their normal operation, exploitation does not require access to an administrative interface or authentication. An attacker can reportedly trigger the vulnerability by sending a specially crafted email through a vulnerable gateway. CVE-2026-76461 was added to CISA's Known Exploited Vulnerabilities ( KEV ) catalog on the same day as the vendor disclosed the vulnerability, indicating that CVE-2026-76461 was exploited as a zero-day prior to disclosure. Cisco noted that their PSIRT became aware of active
CriticalUsed in attacksRapid7 BlogCisco - Cisco patches Secure Email Gateway zero-day exploited in attacks
Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks.
BleepingComputerCisco - Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing logic that could allow an unauthenticated, remote attacker
CriticalUsed in attacksThe Hacker NewsCisco - Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation
An unauthenticated attacker can exploit CVE-2026-76461 to execute arbitrary commands on the underlying OS with root privileges.
CriticalUsed in attacksSecurityWeekCisco
Mon, 14 Sept 2026
- 'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink
The notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022.
Dark ReadingCisco - Cisco security advisory (AV26-921)
Serial Number: AV26-921 Date: September 14, 2026 As of September 14, 2026, Cisco is affected by vulnerabilities in the following products: Cisco AsyncOS for Cisco Secure Email Gateway Prior to 15.5.5-014 Prior to 16.0.4-302 Prior to 16.5.0-780 Cisco Secure Email Gateway Prior to 15.5.5-014 Prior to 16.5.0-780 Cisco Secure Email and Web Manager Prior to 15.5.5-006 Prior to 16.5.0-429 On September 14, 2026, Cisco stated that CVE-2026-76461 is being actively exploited. On September 14, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76461 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Cisco Secure Email Gateway SQL Injection Vulnerability Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 Cisco Security Advisories CISA KEV: CVE-2026-76461
CriticalUsed in attacksCanadian Centre for Cyber SecurityCisco
Fri, 11 Sept 2026
- Metasploit Wrap Up: This One Goes to Sixteen!
This One Goes to Sixteen! Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have a Metasploit scanner to watch the watchers! New module content (16) Elasticsearch ingest-attachment Apache Tika XFA XXE Local File Read Authors: Bourbon Offensive Security Services and Jean-Marie Bourbon Type: Auxiliary Pull request: #21739 contributed by kmkz Path: scanner/http/elasticsearch_tika_xfa_xxe CVE reference: CVE-2025-66516 Description: Adds an auxiliary scanner module for CVE-2025-54988/CVE-2025-66516. The module validates an XML External Entity (XXE) vulnerability in Apache Tika's XFA parser exposed through the Elasticsearch attachment ingest processor. SPIP Unauthenticated Blind SQLi via Date Field Escaping Bypass Authors: Benoit Hua, Franck Chevalier, Julien Voisin, and ka3n1x Type: Auxiliary Pull request: #21791 contributed by jvoisin Path: scanner/http/spip_annee_sqli Description: Adds modules/auxiliary/scanner/http/spip_annee_sqli.rb which exploits a blind SQL injection in SPIP's date column escaping logic. M
Rapid7 BlogPaperCut, SonicWall, Cisco - Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass
CriticalUsed in attacksThe Hacker NewsCisco
About this news
- 1,256
- Stories
- 41
- Added in the last 24 hours
- 19
- Critical in the last 7 days
- 4
- Reported by several outlets