CVE Tools

Шлюзы Cisco Secure Email Gateway можно взломать с помощью вредоносного письма

Хакер (xakep.ru)By Мария Нефёдова

Reported exploitedCisco Secure Email Gateway

Our summary

Cisco has patched CVE-2026-76461, a CVSS 9.8 vulnerability in Cisco Secure Email Gateway appliances and virtual deployments running AsyncOS. Attackers are actively exploiting the flaw by sending crafted email containing SQL commands, which can lead to arbitrary SQL execution and root-level command execution.

Cisco Secure Email Cloud has been updated to AsyncOS 16.5.0-780. Organizations should update to AsyncOS 15.5.5-014, 16.0.4-302, or 16.5.0-780, preferably the latest release, and investigate mail, network, and firewall logs because attackers with root access may remove local evidence.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store