Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

The Hacker News by The Hacker News
September 15, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananSep 15, 2026Vulnerability / Network Security

Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild.

The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing logic that could allow an unauthenticated, remote attacker to run arbitrary commands with root privileges on the underlying operating system.

“An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device,” Cisco said in a Monday advisory. “A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.”

The shortcoming affects Cisco Secure Email Gateway, both physical and virtual, regardless of device configuration. However, the networking equipment maker said other products like Secure Email and Web Manager and Secure Web Appliance are not impacted.

Fixes are available for the following versions of Cisco AsyncOS for Cisco Secure Email Gateway Software Release –

  • 15.5 and earlier (Fixed in 15.5.5-0141)
  • 16.0 (Fixed in 16.0.4-302)
  • 16.5 (Fixed in 16.5.0-780)

There are no workarounds other than updating to the latest supported version. Cisco said it became aware of active exploitation of this vulnerability this month, sharing the following indicators of compromise (IoCs) –

  • Review mail_logs and look for suspicious SQL statements.
  • If the device is part of a cluster, review the logs of each cluster device.
  • To detect potentially malicious SQL statements, it’s advised to run the command: cisco-esa> grep -i “COPY.*TO PROGRAM” [IronPort Text Mail Logs Log name – Default: mail_logs]
  • The presence of any entry in the output may indicate malicious activity.

Cisco also said it has directly contacted customers who own Cisco Secure Email Cloud devices on which malicious activity was detected. It did not disclose the scale of the attacks.

“Upon successful exploitation of this vulnerability, threat actors may obtain command execution with root privileges,” the company warned. “Because of this level of access, evidence of exploitation and indicators of compromise may be removed or hidden by the threat actors.”

As a result, administrators are recommended to cross-check the network logs and the firewall logs outside of the impacted device to identify any potential anomalous activity, including unexpected uploads that were initiated from the affected device to external IP addresses or downloads from malicious IP addresses.

The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add CVE-2026-76461 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 17, 2026.

Large-Scale Credential Attacks Target Fortinet VPNs

The disclosure comes days after Arctic Wolf said it detected large-scale credential attacks targeting internet-facing Fortinet VPN appliances in late August 2026. The high-volume activity took place over two sustained waves across multiple U.S. customer environments from August 26 through August 28, 2026, generating tens of millions of authentication failures.

“The actor used organization-specific usernames, corporate email addresses, affiliate accounts, and common administrative identities, indicating access to previously collected or enumerated identity information,” security researcher Kyle Siddall said.

“The attempted usernames included employee names, corporate email addresses, affiliate identities, and common administrative accounts associated with the targeted organizations. This targeted identity selection, rather than generic username spraying, indicates access to previously collected or enumerated identity information.”

In one observed case, a successful Fortinet VPN authentication originating from the IP address “158.94.211[.]14” was followed by malicious activity in the affected environment.



Source link

The Hacker News

The Hacker News

Next Post

LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server

Recommended.

DNA Expands Collaboration with Google Cloud to Drive Innovation and Deliver Dynamic Services to its Customers

DNA Expands Collaboration with Google Cloud to Drive Innovation and Deliver Dynamic Services to its Customers

February 26, 2025
UAE launches national cryptography discovery platform to accelerate post-quantum security transition | Computer Weekly

UAE launches national cryptography discovery platform to accelerate post-quantum security transition | Computer Weekly

June 5, 2026

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026

Goldman Sachs picks China stocks poised to benefit from a new wave of AI-related hardware exports

August 16, 2026
AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

July 31, 2026
Apple Expands iOS 18.7.7 Update to More Devices to Block DarkSword Exploit

Apple Expands iOS 18.7.7 Update to More Devices to Block DarkSword Exploit

April 2, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio