Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

High · The Hacker News ·

Exploited

What happened

Cisco Secure Email Gateway (AsyncOS) flaw CVE-2026-76461, CVSS 9.8, is actively exploited; unauthenticated remote attackers can run commands as root via email parsing. Patch now.

What to do now

Apply Cisco's AsyncOS update for CVE-2026-76461 immediately; verify fixed version with the Cisco advisory. If patching is delayed, restrict gateway access to trusted IPs, monitor logs, and isolate the appliance.

CVE references

  • CVE-2026-76461

Original source

The Hacker News

AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.

← All cyber news