logo

Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)

ID: 9857ea95-9379-5892-b519-25302771350c

STIX ID: report--9857ea95-9379-5892-b519-25302771350c

Feed Name: Help Net Security

Threat Score
90/100

Date Published: 2026-09-15

Date Updated: 2026-09-15

Author: Zeljka Zorz

...
...

Cisco confirmed active exploitation of a critical zero-day SQL injection (CVE-2026-76461) in AsyncOS-powered Secure Email Gateway appliances and the cloud service that can allow unauthenticated attackers to execute arbitrary SQL and gain root-level command execution. Cisco published IOCs and guidance to check mail_logs and network/firewall logs, released fixes (15.5.5-014, 16.0.4-302, 16.5.0-780), and CISA added the flaw to its Known Exploited Vulnerabilities catalog with an urgent remediation deadline.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.