chiprook
← Security
SecuritySeptember 15, 2026, 18:09

Cisco Patches Actively Exploited Email Gateway Zero-Day (CVE-2026-76461)

Cisco confirmed active exploitation of a zero-day SQL injection, CVE-2026-76461, in Cisco Secure Email Gateway on AsyncOS 16.5, 16.0, and 15.5 and earlier. An unauthenticated attacker can execute arbitrary SQL code via an email and gain root access to the OS. CISA added the flaw to its exploited catalog and requires US federal agencies to fix it by September 17.

Cisco Patches Actively Exploited Email Gateway Zero-Day (CVE-2026-76461)
#Cisco#CISA
Read next
Security

U.S. jails expand continuous biometric monitoring as data rules lag

Security

WordPress Click2Shell flaw lets hackers run PHP on the server

Security

ZoomEye: Over 239,000 Citrix NetScaler Gateways Exposed Amid SAML Bypass

Security

Microsoft and Google take down $66 million RedVDS cybercrime marketplace