Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
High · The Hacker News ·
Exploited
What happened
Cisco Secure Email Gateway (AsyncOS) flaw CVE-2026-76461, CVSS 9.8, is actively exploited; unauthenticated remote attackers can run commands as root via email parsing. Patch now.
What to do now
Apply Cisco's AsyncOS update for CVE-2026-76461 immediately; verify fixed version with the Cisco advisory. If patching is delayed, restrict gateway access to trusted IPs, monitor logs, and isolate the appliance.
CVE references
- CVE-2026-76461
Original source
AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.