Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Cisco users urged to patch email gateway flaw | Computer Weekly

By Computer Weekly by By Computer Weekly
September 15, 2026
Home Uncategorized
Share on FacebookShare on Twitter


Cisco is urging defenders to get out in front of a highly-dangerous flaw in its Secure Email Gateway (SEG) appliance, CVE-2026-76461 that could enable an unauthenticated, remote attacker to gain the ability to execute arbitrary commands with root privileges.

Listed on the US’ Cybersecurity and Infrastructure Security Agency’s (Cisa’s) Known Exploited Vulnerabilities (Kev) catalogue as of Monday 14 September, CVE-2026-76461 arises in SEG’s underlying AsyncOS software and occurs due to insufficient validation in the email parsing logic.

In simple terms, an attacker could exploit this by sending an email containing malicious Structured Query Language (SQL) statements via an affected device, Cisco explained. It was uncovered during a routine customer service interaction with its support team.

“Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability,” the supplier said in a statement.

Cisco warned that both physical and virtual versions of SEG – regardless of how they are configured – are affected.

Besides applying Cisco’s patch, most defenders can quickly confirm any attempted exploit by combing their SEG mail_logs for suspicious SQL statements. The presence of entries in the output may serve as an indicator of compromise (IoC), but according to Cisco, all users should additionally note that given CVE-2026-76461 opens up root privileges, an opsec-conscious threat actor could delete these.

“A root shell from a crafted email is about as bad as it gets, and the CVSS [base 9.8] score almost undersells it,” said Gunter Ollmann, chief technology officer at Cobalt, a supplier of penetration testing services.

“Email gateways have to read untrusted content from anyone on the internet by design, then make trust decisions about it. That’s exactly the kind of position attackers look for.”

Ollman said the rather more worrying aspect was the fact that attackers could wipe their IoCs. “If your detection strategy leans on matching known IoCs after the fact, you may have already missed the intrusion,” he said. “This is a good argument for putting more weight on behavioral and network-level detection around these devices, not just signature checks.”

Perimeter products targeted

The disclosure of CVE-2026-76461 comes hot on the heels of the discovery of other vulnerabilities discovered in Cisco perimeter products, in this case its Secure Firewall Management Center (FMC) software.

The first of these, CVE-2026-20079 enables an unauthenticated, remote attacker to bypass authentication and execute script files on the affected system to gain root access. The second, CVE-2026-20316, enables an unauthenticated, remote attacker to log in to an affected device with a low-privileged account and potentially to access sensitive data.

According to an investigation conducted by Cisco’s Talos threat research unit, two distinct exploitation clusters have been detected. One of these clusters, attributed to a group Cisco tracks as UAT-11823, ultimately led to the deployment of a variant of the Cyclops Blink malware.

Cyclops Blink has been extensively used by the Russian state APT most commonly known as Sandworm – once described by Mandiant as one of the “most brazen” nation-state threats around.

“Perimeter security appliances need the same ongoing scrutiny as any other internet-facing application, not a patch cycle tied to change windows…. Assume active probing against unpatched, reachable instances is already happening,” noted Ollman.



Source link

By Computer Weekly

By Computer Weekly

Next Post

NinjaOne Extends Browser Management To Give MSPs More Visibility, Control

Recommended.

China’s property slump is far from bottoming. But Beijing is prioritizing tech growth

China’s property slump is far from bottoming. But Beijing is prioritizing tech growth

October 23, 2025
Chicago Fed President Goolsbee says officials have to be careful not to get too aggressive with rate cuts

Chicago Fed President Goolsbee says officials have to be careful not to get too aggressive with rate cuts

September 23, 2025

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
Apple Expands iOS 18.7.7 Update to More Devices to Block DarkSword Exploit

Apple Expands iOS 18.7.7 Update to More Devices to Block DarkSword Exploit

April 2, 2026

Goldman Sachs picks China stocks poised to benefit from a new wave of AI-related hardware exports

August 16, 2026
Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

July 31, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio