ZoomEye finds 5,950 Cisco Secure Email gateways exposed amid CVE-2026-76461
A ZoomEye scan on September 30, 2026 found 5,950 internet-facing Cisco Secure Email Gateway (IronPort) appliances. CVE-2026-76461, rated 9.8, allows SQL injection in mail parsing leading to root command execution; it has been exploited in the wild and added to the KEV catalog on September 14.
- CVE-2026-76461 in AsyncOS: SQL injection in mail parsing and root command execution, rated 9.8
- Fixed builds: 15.5.5-014, 16.0.4-302 and 16.5.0-780
- ZoomEye found 5,950 Cisco IronPort gateways reachable from the internet
- The flaw is exploited in the wild and was added to KEV on September 14, 2026
Read next
Security