UNDERCOVERED IN US

Cisco patches critical zero-day in email gateway under active exploit

Between September 14–16, 2026, Cisco disclosed and patched CVE-2026-76461, a critical SQL-injection vulnerability in AsyncOS software for Cisco Secure Email Gateway that allows unauthenticated remote attackers to execute arbitrary commands. Attackers were actively exploiting the flaw before the patch was released.

42 reports · 40 independentother · primary

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

CVE-2026-76461: Cisco Secure Email Gateway — Cisco Secure Email Gateway SQL Injection Vulnerability

json:cisa-kevprimary15d ago wire ×2 kagi ↗

Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL

ayy lmao Cisco CVE-2026-76461 A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary command

mastodon:infosec-exchangeother15d ago kagi ↗

ayy lmao Cisco CVE-2026-76461 A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability. https:// sec.cloudapps.cisco.com/securi ty/cent

Welcome to Monday and two new advisories from Cisco. CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Releas

mastodon:infosec-exchangeother15d ago kagi ↗

Welcome to Monday and two new advisories from Cisco. CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 https:// sec.cloudapps.cisco.com/securi ty/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm CRITICAL: CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vul

🚨 [CISA-2026:0914] CISA Adds One Known Exploited Vulnerability to Catalog ( https:// secdb.nttzen.cloud/security-ad visory/detail/CISA-2026:0914 ) CISA has added one new vulnerability to its Known Ex

mastodon:infosec-exchangeother15d ago kagi ↗

🚨 [CISA-2026:0914] CISA Adds One Known Exploited Vulnerability to Catalog ( https:// secdb.nttzen.cloud/security-ad visory/detail/CISA-2026:0914 ) CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the feder

Since no one seems to have noticed the Cisco exploited zero-day: CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CV

mastodon:infosec-exchangeother15d ago kagi ↗

Since no one seems to have noticed the Cisco exploited zero-day: CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability https://www. cisa.gov/news-events/alerts/20 26/09/14/cisa-adds-one-known-exploited-vulnerability-catalog # CISA # KEV # Cisco # zero

CVE-2026-76461 (CVSS 9.8) is a Cisco Secure Email Gateway vulnerability exploited in the wild. SQL injection grants root command execution. Patch now. # Cisco # EmailSecurity # CVE202676461 # SQLInjec

mastodon:infosec-exchangeother15d ago kagi ↗

CVE-2026-76461 (CVSS 9.8) is a Cisco Secure Email Gateway vulnerability exploited in the wild. SQL injection grants root command execution. Patch now. # Cisco # EmailSecurity # CVE202676461 # SQLInjection # RCE # ExploitedInTheWild # AsyncOS # InfoSec # PatchNow # RootAccess https:// securityonline.info/cve-2026-7 6461-cisco-email-gateway-rce/?utm_source=mastodon&utm_medium=jetpack_social

CRITICAL (CVSS 9.8): CVE-2026-76461 in Cisco AsyncOS for Secure Email Gateway lets unauthenticated attackers execute commands as root via crafted emails. Patch status unknown — monitor Cisco’s updates

mastodon:infosec-exchangeother15d ago kagi ↗

CRITICAL (CVSS 9.8): CVE-2026-76461 in Cisco AsyncOS for Secure Email Gateway lets unauthenticated attackers execute commands as root via crafted emails. Patch status unknown — monitor Cisco’s updates. https:// radar.offseq.com/threat/a-vuln erability-in-the-email-parsing-of-cisco-asyncos-software-for-cisco-secure-email-gateway-could-a5a1b3247d786df4 # OffSeq # Cisco # Vulnerability # EmailSecurit

Cisco warns of actively exploited Secure Email Gateway zero-day

kite:cybersecurityother14d ago kagi ↗

Cisco has warned that attackers are exploiting CVE-2026-76461, a critical zero-day in AsyncOS software used by Cisco Secure Email Gateway appliances. The flaw allows unauthenticated remote attackers to send a specially crafted email containing malicious SQL statements and execute arbitrary commands with root privileges on the underlying operating system. It affects physical and virtual gateways in

Everyone's talking about how fragile everything is this week. Look at the root RCE in Cisco Secure Email Gateway (CVE-2026-76461), those authentication bypasses in JFrog Artifactory, or the urgent war

mastodon:infosec-exchangeother14d ago kagi ↗

Everyone's talking about how fragile everything is this week. Look at the root RCE in Cisco Secure Email Gateway (CVE-2026-76461), those authentication bypasses in JFrog Artifactory, or the urgent warnings CISA put out… https:// theperimetersite.com/report/262 # vulnerability # databreach # infosec

🤖 CVE-2026-76461 (CVSS 9.8): critical flaw in Cisco Secure Email Gateway (AsyncOS) under active exploitation in the wild. Insufficient validation in email parsing lets an unauthenticated remote attac

mastodon:infosec-exchangeother14d ago kagi ↗

🤖 CVE-2026-76461 (CVSS 9.8): critical flaw in Cisco Secure Email Gateway (AsyncOS) under active exploitation in the wild. Insufficient validation in email parsing lets an unauthenticated remote attacker execute commands as root. Patch now. 🔗 https:// thehackernews.com/2026/09/cisc o-secure-email-gateway-flaw.html # CVE # Exploit # CyberSec

Cisco Secure Email Gateway faces a CRITICAL zero-day vulnerability, actively exploited in the wild. No CVE or version info yet. Patch available — apply ASAP to protect email infrastructure. https:// r

mastodon:infosec-exchangeother14d ago kagi ↗

Cisco Secure Email Gateway faces a CRITICAL zero-day vulnerability, actively exploited in the wild. No CVE or version info yet. Patch available — apply ASAP to protect email infrastructure. https:// radar.offseq.com/threat/cisco- patches-secure-email-gateway-zero-day-exploited-in-attacks-76a43690673247c4 # OffSeq # Cisco # ZeroDay # BlueTeam # EmailSecurity

Reward: You've been granted the Undead Inbox title. It comes with no privileges you still control. https:// undercodenews.com/cisco-secure -email-gateway-zero-day-under-active-attack-critical-flaw-giv

mastodon:infosec-exchangeother14d ago kagi ↗

Reward: You've been granted the Undead Inbox title. It comes with no privileges you still control. https:// undercodenews.com/cisco-secure -email-gateway-zero-day-under-active-attack-critical-flaw-gives-hackers-root-level-control-video/?utm_source=mastodon&utm_medium=jetpack_social # CyberSecurity # ZeroDay # Cisco # EmailSecurity # Ransomware # AchievementUnlocked (3/3)

Cisco confirms active exploitation of zero-day in Secure Email Gateway (CVE-2026-76461) giving unauthenticated root RCE. CISA mandates 3-day patch for federal agencies. https:// deafnews.it/en/article

mastodon:infosec-exchangeother14d ago kagi ↗

Cisco confirms active exploitation of zero-day in Secure Email Gateway (CVE-2026-76461) giving unauthenticated root RCE. CISA mandates 3-day patch for federal agencies. https:// deafnews.it/en/article/cisco-s eg-zero-day-root-rce-appliance-compromise-erases-its-own-forensic-trail

🔴 New security advisory: CVE-2026-76461 affects multiple systems. • Impact: Remote code execution or complete system compromise possible • Risk: Attackers can gain full control of affected systems •

mastodon:infosec-exchangeother14d ago kagi ↗

🔴 New security advisory: CVE-2026-76461 affects multiple systems. • Impact: Remote code execution or complete system compromise possible • Risk: Attackers can gain full control of affected systems • Mitigation: Patch immediately or isolate affected systems Full breakdown: https://www. yazoul.net/advisory/cve/cve-20 26-76461-cisco-secure-email-gateway-rce-exploited-poc by Yazoul AI # CVE # PatchNo

⚠️ Threat Notice: Cisco Secure Email Gateway Vulnerability ⚠️ Cisco has disclosed a critical, actively exploited, SQL injection vulnerability in Cisco Secure Email Gateway. The vulnerability affects a

mastodon:infosec-exchangeother14d ago kagi ↗

⚠️ Threat Notice: Cisco Secure Email Gateway Vulnerability ⚠️ Cisco has disclosed a critical, actively exploited, SQL injection vulnerability in Cisco Secure Email Gateway. The vulnerability affects all physical and virtual Secure Email Gateway appliances regardless of configuration, and no workarounds are available. Cisco has confirmed active exploitation of this vulnerability, which has been add

CVE-2026-76461 | 9.8 Critical | SQL Injection Vulnerability → An unauthenticated remote attacker can send a crafted email containing malicious SQL statements to execute arbitrary SQL commands, resulti

mastodon:infosec-exchangeother14d ago kagi ↗

CVE-2026-76461 | 9.8 Critical | SQL Injection Vulnerability → An unauthenticated remote attacker can send a crafted email containing malicious SQL statements to execute arbitrary SQL commands, resulting in command execution with root privileges on the underlying operating system.

Cisco patches exploited email gateway zero-day enabling root access

kite:cybersecurityother14d ago kagi ↗

Cisco disclosed and patched CVE-2026-76461, a critical SQL-injection vulnerability in AsyncOS Software for Cisco Secure Email Gateway, after confirming that attackers were exploiting it in the wild during September 2026 [bleepingcomputer.com#1][thehackernews.com#1][rapid7.com#1]. The flaw affects both physical and virtual appliances regardless of configuration and could allow an unauthenticated re

🔵 THREAT INTELLIGENCE Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution Vulnerability | CRITICAL CVEs: CVE-2026-76461 Cisco warned customers to patch a critical Se

mastodon:infosec-exchangeother14d ago kagi ↗

🔵 THREAT INTELLIGENCE Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution Vulnerability | CRITICAL CVEs: CVE-2026-76461 Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks. [...] Full analysis: https://www. yazoul.net/news/article/cisco- secure-email-gateway-flaw-exploited-in-th

U.S. # CISA adds # Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog https:// securityaffairs.com/199156/sec urity/u-s-cisa-adds-cisco-secure-email-gateway-flaw-to-its-kno

mastodon:infosec-exchangeother14d ago kagi ↗

U.S. # CISA adds # Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog https:// securityaffairs.com/199156/sec urity/u-s-cisa-adds-cisco-secure-email-gateway-flaw-to-its-known-exploited-vulnerabilities-catalog.html # securityaffairs # hacking

🚨 SIGINT // Cybersecurity Watch — 2026-09-16 Root RCE zero-day in Cisco Secure Email Gateway actively exploited in the wild — unauthenticated attackers can gain full system control. Patch now. https:

mastodon:fosstodonother14d ago kagi ↗

🚨 SIGINT // Cybersecurity Watch — 2026-09-16 Root RCE zero-day in Cisco Secure Email Gateway actively exploited in the wild — unauthenticated attackers can gain full system control. Patch now. https://www. securityweek.com/root-rce-zero -day-in-cisco-secure-email-gateway-under-active-exploitation/ # CVE # Cisco # InfoSec # Cybersecurity

⚠️ CRITICAL: Cisco patches Secure Email Gateway zero-day exploited in attacks Cisco Secure Email Gateway has a critical zero-day (CVE-2026-76461) that allows unauthenticated attackers to execute arbit

mastodon:infosec-exchangeother14d ago kagi ↗

⚠️ CRITICAL: Cisco patches Secure Email Gateway zero-day exploited in attacks Cisco Secure Email Gateway has a critical zero-day (CVE-2026-76461) that allows unauthenticated attackers to execute arbitrary commands as root via malicious SQL in crafted emails. This is actively exploited in the wild. Any organization running SEG is at immediate risk of full compromise. https:// threatnoir.com/focus #

⚠️ CRITICAL: Cisco warns customers of actively exploited zero-day in email gateways Cisco Secure Email Gateway contains a critical unauthenticated root privilege escalation vulnerability (CVE-2026-764

mastodon:infosec-exchangeother14d ago kagi ↗

⚠️ CRITICAL: Cisco warns customers of actively exploited zero-day in email gateways Cisco Secure Email Gateway contains a critical unauthenticated root privilege escalation vulnerability (CVE-2026-76461) that was actively exploited in the wild before patches were available. Multiple customers are likely already compromised. This is now tracked in CISA's Known Exploited Vulnerabili… https:// threat

A critical Cisco Secure Email Gateway vulnerability allows unauthenticated attackers to gain root access via a single email. Learn about CVE-2026-76461. # Cisco # EmailGateway # CyberSecurity # ZeroDa

mastodon:infosec-exchangeother13d ago kagi ↗

A critical Cisco Secure Email Gateway vulnerability allows unauthenticated attackers to gain root access via a single email. Learn about CVE-2026-76461. # Cisco # EmailGateway # CyberSecurity # ZeroDay # Vulnerability https:// meterpreter.org/cisco-secure-e mail-gateway-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social

CVE-2026-87886: Acronis Backup — Acronis Backup Incorrect Default Permissions Vulnerability

json:cisa-kevprimary13d ago kagi ↗

Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Not

🚨 [CISA-2026:0916] CISA Adds One Known Exploited Vulnerability to Catalog ( https:// secdb.nttzen.cloud/security-ad visory/detail/CISA-2026:0916 ) CISA has added one new vulnerability to its Known Ex

mastodon:infosec-exchangeother13d ago kagi ↗

🚨 [CISA-2026:0916] CISA Adds One Known Exploited Vulnerability to Catalog ( https:// secdb.nttzen.cloud/security-ad visory/detail/CISA-2026:0916 ) CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the feder

Cisco patches exploited zero-days in email, identity products

kite:cybersecurityother13d ago kagi ↗

Cisco is urging customers to install emergency updates after attackers exploited two critical, unauthenticated vulnerabilities in its Secure Email Gateway and Identity Services Engine products. The email-gateway flaw, CVE-2026-76461, affects email parsing in Cisco AsyncOS and allows an attacker to send a crafted message containing malicious SQL statements that execute arbitrary commands with root

🏆 New Achievement! Root Access? We'll Get That Escalated for You! Your ticket has been received. We see you're experiencing an issue where an unauthenticated attacker is executing arbitrary commands

mastodon:infosec-exchangeother13d ago kagi ↗

🏆 New Achievement! Root Access? We'll Get That Escalated for You! Your ticket has been received. We see you're experiencing an issue where an unauthenticated attacker is executing arbitrary commands with root privileges on your Cisco Secure Email Gateway via CVE-2026-76461. Great news: we've reproduced the bug! It's the email parsing in Cisco AsyncOS — sending a specially crafted email with malic

CVE-2026-20341: CRITICAL flaw in Cisco Secure FMC Software sftunnel protocol. Admin remote attackers can gain root via insecure deserialization. Limit admin access, monitor for abuse, and check for pa

mastodon:infosec-exchangeother13d ago kagi ↗

CVE-2026-20341: CRITICAL flaw in Cisco Secure FMC Software sftunnel protocol. Admin remote attackers can gain root via insecure deserialization. Limit admin access, monitor for abuse, and check for patch updates. https:// radar.offseq.com/threat/a-vuln erability-in-the-sftunnel-inter-device-communication-protocol-of-cisco-secure-fmc-software-could-c3ce1a1e4096035e # OffSeq # Cisco # Infosec # Vuln

Cisco patches CVE-2026-76460, a CVSS 10.0 authentication bypass in ISE under active exploitation that enables root command execution. Organizations should apply emergency https:// deafnews.it/en/artic

mastodon:infosec-exchangeother12d ago kagi ↗

Cisco patches CVE-2026-76460, a CVSS 10.0 authentication bypass in ISE under active exploitation that enables root command execution. Organizations should apply emergency https:// deafnews.it/en/article/cisco-i se-emergency-patch-for-actively-exploited-zero-day-with-cvss-10

CRITICAL auth bypass (CVE-2026-76460) in Cisco ISE & ISE-PIC is being actively exploited. Remote attackers gain root on management interface via crafted API calls. Patch ASAP — no workarounds except A

mastodon:infosec-exchangeother12d ago kagi ↗

CRITICAL auth bypass (CVE-2026-76460) in Cisco ISE & ISE-PIC is being actively exploited. Remote attackers gain root on management interface via crafted API calls. Patch ASAP — no workarounds except ACLs. Details: https:// radar.offseq.com/threat/active -exploitation-triggers-emergency-patch-for-cisco-ise-zero-day-d5bd452a61e0a8f8 # OffSeq # Cisco # ZeroDay

Cisco Patches 18 Critical and High-Severity Firewall Vulnerabilities, One Actively Exploited Cisco released a massive security hardening update fixing 18 vulnerabilities in its Secure Firewall suite,

mastodon:infosec-exchangeother12d ago kagi ↗

Cisco Patches 18 Critical and High-Severity Firewall Vulnerabilities, One Actively Exploited Cisco released a massive security hardening update fixing 18 vulnerabilities in its Secure Firewall suite, including an actively exploited authentication bypass (CVE-2026-20332) and multiple critical remote code execution flaws. **If you use Cisco Secure Firewall (ASA, FTD, or FMC), this is urgent. Patch n

Cisco's Back-to-Back Zero-Days: CVE-2026-76461 (Secure Email Gateway) and CVE-2026-76460 (ISE Auth Bypass) If your organization runs Cisco networking or security appliances, and most mid-size and larg

mastodon:infosec-exchangeother12d ago kagi ↗

Cisco's Back-to-Back Zero-Days: CVE-2026-76461 (Secure Email Gateway) and CVE-2026-76460 (ISE Auth Bypass) If your organization runs Cisco networking or security appliances, and most mid-size and large organizations run at least some, this week deserves your attention. Cisco disclosed two separate, maximum-severity vulnerabilities within roughly 48 hours of each other, and confirmed that both are

Cisco Secure Email Gateway zero-day confirmed: Experts advise immediate patching

stream:bsky-jetstreamother11d ago kagi ↗

Cisco confirmed a zero-day vulnerability that lets unauthenticated remote attackers execute arbitrary commands with root privileges. ⚠️ Experts advise immediate patching. We break down the risk with insights from Gunter Ollmann and Josh Picolet: #Cybersecurity #InfoSec Cisco has confirmed a vulnerability that could allow a remote attacker to run arbitrary commands with root privileges on the OS

CVE-2026-53266: Linux Kernel — Linux Kernel Out-of-Bounds Write Vulnerability

json:cisa-kevprimary11d ago kagi ↗

Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. Actio

Cisco FMC CVE-2026-20324 is a critical sftunnel vulnerability with a CVSS score of 9.9. The flaw involves missing authorization (CWE-862) and can allow an attacker controlling or hijacking a registere

mastodon:infosec-exchangeother11d ago kagi ↗

Cisco FMC CVE-2026-20324 is a critical sftunnel vulnerability with a CVSS score of 9.9. The flaw involves missing authorization (CWE-862) and can allow an attacker controlling or hijacking a registered sftunnel peer to write arbitrary files and execute commands as root on Secure Firewall Management Center. The important part: this isn't a typical unauthenticated internet-facing RCE. Exploitation r

🚨 [CISA-2026:0918] CISA Adds 2 Known Exploited Vulnerabilities to Catalog ( https:// secdb.nttzen.cloud/security-ad visory/detail/CISA-2026:0918 ) CISA has added 2 new vulnerabilities to its Known Ex

mastodon:infosec-exchangeother11d ago kagi ↗

🚨 [CISA-2026:0918] CISA Adds 2 Known Exploited Vulnerabilities to Catalog ( https:// secdb.nttzen.cloud/security-ad visory/detail/CISA-2026:0918 ) CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the feder

⚪️ Cisco Secure Email Gateway Appliances Can Be Hacked with a Malicious Email 🗨️ Cisco researchers have fixed a critical vulnerability in Secure Email Gateway, a gateway designed to protect email fro

mastodon:infosec-exchangeother11d ago kagi ↗

⚪️ Cisco Secure Email Gateway Appliances Can Be Hacked with a Malicious Email 🗨️ Cisco researchers have fixed a critical vulnerability in Secure Email Gateway, a gateway designed to protect email from malicious messages. Ironically, to compromise the gateway itself, an attacker only had to send a specially crafted email through it. The vulnerability… 🔗 https:// hackmag.com/news/cve-2026-7646 1?u