Search/Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)
Story

Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)

Criminals are exploiting a critical Cisco Secure Email Gateway flaw that can turn a malicious email into root access. The vulnerability, tracked as CVE-2026-76461, carries a 9.8 CVSS score and affects physical and virtual Secure Email Gateway appliances regardless of their configuration. Cisco says there are no workarounds, so patching is the only fix. The bug lies in how Cisco's AsyncOS software handles incoming email. An attacker doesn't need to log in: they can send a booby-trapped message through a vulnerable gateway and, if the exploit works, run commands as root. Which is not exactly what you want from the box tasked with keeping nasty emails out. Cisco's Product Security Incident Response Team said it became aware of active exploitation in September, although the networking giant…

CVEs
17
Highest CVSS
10
In KEV
7
Sources
16
Key vulnerabilities
top 3 of 17 by CVSS
CVE-2026-76460CVSS 10● KEV

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

CVE-2026-76423CVSS 10

A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain administrative access to an affected device. This vulnerability is due to the REST API web service being exposed with insufficient authorization checks. An attacker could exploit this vulnerability by sending a crafted HTTP request to the exposed REST API port. A successful exploit could allow the attacker to read and modify ISE configuration and identity data with administrative privileges.

CVE-2026-20192CVSS 10

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20192 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.

Connections
52 relationships
Cisco drops another exploited zero-day, this time a perfect 10
Cisco admins who have spent their week patching email gateways now face a perfect-10 Identity Services Engine flaw under active attack. Cisco disclosed CVE-2026-76460 on Wednesday, describing it as an authentication bypass affecting Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). Successful exploitation can give an unauthenticated remote attacker command execution with root privileges. Product Security Incident Response Team said it was aware of active exploitation and urged customers to install the fixes immediately. CISA has also added the vulnerability to its Known Exploited Vulnerabilities catalog. The warning follows another actively exploited critical vulnerability disclosed days earlier, CVE-2026-76461, affecting its Secure Email Gateway and Secure Email and Web Manager appliances. That 9.8-rated bug could also lead to root access, prompting Cisco to warn admins that attackers may be able to cover their tracks after getting in. The latest problem lies in an API within Cisco ISE, the company's network access control platform. Cisco says insufficient authentication controls on an API endpoint mean an attacker can send a crafted request to bypass the product's web-based management interface. No credentials or user interaction are required, and Cisco says vulnerable versions of ISE and ISE-PIC are affected regardless of configuration. The flaw received the maximum CVSS score of 10.0. Cisco warned that root access could allow attackers to remove or conceal traces of an intrusion, complicating efforts to determine whether an appliance had been breached. Cisco advised admins to review ISE access logs for suspicious usernames on every node in a distributed deployment and to check network and firewall logs held outside the affected device for signs of unexpected uploads or downloads. If admins find evidence of possible exploitation, Cisco "strongly recommends" reimaging affected nodes and restoring their configurations from backup if necessary. No workaround exists, although Cisco said infrastructure access control lists can be used as a temporary mitigation to restrict management and control-plane traffic reaching affected systems. Permanent fixes are available in ISE and ISE-PIC 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4. ISE 3.0 has reached the end of software maintenance, so customers running it must migrate to a supported release. Cisco discovered CVE-2026-76460 while resolving a Technical Assistance Center support case, but has not disclosed who is exploiting it, how long the attacks have been underway, or what the intruders have done after gaining access. The advisory accompanied a substantial batch of other ISE vulnerabilities published Wednesday. Two other Cisco advisories carried maximum CVSS scores of 10.0, while a separate trio of remote code execution flaws scored as high as 9.9. For admins responsible for Cisco kit, September is shaping up to be quite the patching month. ®
theregister.comSep 17, 2026extracted
NCSC-2026-0382 [1.00] [H/H] Kwetsbaarheden verholpen in Cisco Identity Services Engine (ISE)
Cisco heeft 21 kwetsbaarheden verholpen in Cisco Identity Services Engine (ISE) en Cisco ISE Passive Identity Connector (ISE-PIC). De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Cisco ISE en ISE-PIC, waaronder mogelijkheden voor niet-geauthenticeerde en laaggeprivilegieerde kwaadwillenden om via netwerktoegang ongeautoriseerde acties uit te voeren. De kwetsbaarheden hebben CVSS-scores variërend van middel tot kritiek. Van de in totaal 21 kwetsbaarheden zijn 13 als kritiek aangemerkt. Op basis van de door Cisco gepubliceerde CVSS-scores kunnen vier kwetsbaarheden zonder authenticatie op afstand worden misbruikt. Succesvol misbruik kan onder meer leiden tot het omzeilen van authenticatie- en autorisatiecontroles, het verkrijgen en wijzigen van gevoelige configuratie- en identiteitsgegevens, het uitvoeren van willekeurige code of commando's met rootrechten, SQL-injectie, het uitlezen van bestanden en het verstoren van de beschikbaarheid van getroffen systemen. Sommige kwetsbaarheden vereisen voorafgaande administratieve toegangsrechten of een specifieke configuratie, terwijl andere volledig op afstand en zonder authenticatie kunnen worden misbruikt. Van de 13 kwetsbaarheden die als kritiek zijn aangemerkt, hebben meerdere een CVSS-score van 9,8 of hoger. Vier kwetsbaarheden, CVE-2026-20130, CVE-2026-20192, CVE-2026-76423 en CVE-2026-76460, hebben een CVSS-score van 10,0. De kwetsbaarheid met kenmerk CVE-2026-76423 betreft een kwetsbaarheid in de REST API waarmee een niet-geauthenticeerde kwaadwillende administratieve toegang kan verkrijgen tot Cisco ISE en ISE-PIC. De kwetsbaarheid met kenmerk CVE-2026-76460 betreft een authenticatieomzeiling in een API van Cisco ISE en ISE-PIC waarmee een niet-geauthenticeerde kwaadwillende toegang tot het getroffen systeem kan verkrijgen. Cisco meldt dat deze kwetsbaarheid actief wordt misbruikt. Na succesvolle exploitatie kunnen kwaadwillenden volgens Cisco commando's met rootrechten uitvoeren. De kwetsbaarheden met kenmerk CVE-2026-20130 en CVE-2026-20192 betreffen door Cisco gegroepeerde kwetsbaarheden op het gebied van respectievelijk onvoldoende neutralisatie van invoer en onjuiste toegangscontrole. Cisco heeft voor deze hardening-release meerdere onderliggende kwetsbaarheden per CWE-klasse onder één CVE-ID samengebracht. De CVSS-score vertegenwoordigt daarbij de hoogst scorende onderliggende kwetsbaarheid. Het NCSC adviseert om de beveiligingsupdates voor de kritieke kwetsbaarheden met voorrang toe te passen.
advisories.ncsc.nlSep 17, 2026extracted
Cisco email security boxes can be rooted by... an email
Criminals are exploiting a critical Cisco Secure Email Gateway flaw that can turn a malicious email into root access. The vulnerability, tracked as CVE-2026-76461, carries a 9.8 CVSS score and affects physical and virtual Secure Email Gateway appliances regardless of their configuration. Cisco says there are no workarounds, so patching is the only fix. The bug lies in how Cisco's AsyncOS software handles incoming email. An attacker doesn't need to log in: they can send a booby-trapped message through a vulnerable gateway and, if the exploit works, run commands as root. Which is not exactly what you want from the box tasked with keeping nasty emails out. Cisco's Product Security Incident Response Team said it became aware of active exploitation in September, although the networking giant hasn't said who is behind the attacks, how long they have been going on, or how many organizations have been compromised. Cisco uncovered the bug while resolving a Technical Assistance Center support case. Signs suggest at least some Cisco cloud customers were caught up in the attacks. Cisco said it investigated devices belonging to its Secure Email Cloud service and directly contacted customers whose appliances showed indicators of possible compromise. It is now carrying out remediation and recovery work and says all of its Secure Email Cloud devices have been upgraded to AsyncOS 16.5.0-780. Admins running their own appliances have a little more work to do. Cisco recommends checking logs for signs of suspicious activity, but warns that finding nothing doesn't necessarily mean the system is clean. Once attackers have root access, Cisco says they could tamper with the logs and cover their tracks. Admins are also being told to check network and firewall logs for anything unusual, rather than relying on the gateway itself for answers. For virtual appliances suspected of being compromised, Cisco's recovery advice is fairly drastic: preserve the forensic evidence, deploy a fresh VM running fixed software, rebuild the configuration, and rotate credentials and cryptographic material. Cisco has fixed the bug in AsyncOS releases 15.5.5-014, 16.0.4-302 and 16.5.0-780, with customers strongly encouraged to move to the latter. There's still a decent-sized target pool out there. The Shadowserver Foundation was tracking more than 400 Cisco Secure Email Gateway appliances exposed to the internet as of Monday The flaw has also landed in CISA's Known Exploited Vulnerabilities catalog, with US federal civilian agencies ordered to remediate it by September 17. CVE-2026-76461 comes less than a year after attackers exploited another critical AsyncOS flaw, CVE-2025-20393, to break into Cisco Secure Email Gateway appliances and install persistence mechanisms. That bug eventually scored a perfect 10. For anyone still running an affected gateway, the message is fairly simple: the box designed to inspect hostile email can itself be pwned by one; attackers are already doing it, and there is no workaround to hide behind. ®
theregister.comSep 15, 2026extracted
Cisco: sfuttamento in rete della CVE-2026-76461 relativa a Secure Email Gateway
Cisco: sfuttamento in rete della CVE-2026-76461 relativa a Secure Email Gateway Alert AL06/260914/CSIRT-ITA Sintesi Cisco ha rilasciato aggiornamenti di sicurezza per sanare 6 vulnerabilità, di cui 5 con gravità "critica" e una con gravità "alta", che interessano Cisco Secure Email Gateway, soluzione per la protezione e la gestione della posta elettronica, e Cisco Secure Email and Web Manager, piattaforma per la gestione centralizzata dei relativi servizi di sicurezza. Tra queste, si evidenzia la CVE-2026-76461 che risulta sfruttata attivamente in rete e che potrebbe permettere l'esecuzione di codice arbitrario remoto con privilegi elevati sui sistemi interessati. Tipologia Remote Code Execution Security Restrictions Bypass Authentication Bypass Denial of Service Data Manipulation Descrizione e potenziali impatti La vulnerabilità identificata tramite la CVE-2026-76461, di tipo "Remote Code Execution", e con CVSS 3.1 pari a 9.8, interessa il software Cisco AsyncOS per Cisco Secure Email Gateway. Tale vulnerabilità è dovuta a un'errata convalida di parametri di input nella logica di gestione del parsing dei messaggi di posta elettronica. Un attaccante remoto non autenticato potrebbe sfruttare tale vulnerabilità per inviare messaggi di posta elettronica opportunamente predisposti al dispositivo interessato al fine di eseguire istruzioni SQL arbitrarie e ottenere l'esecuzione di comandi con privilegi di root sul sistema operativo sottostante. Prodotti e/o versioni affette Cisco AsyncOS per Cisco Secure Email Gateway versioni precedenti alla 15.5.5-014 16.x, versioni precedenti alla 16.0.4-302 16.5.x, versioni precedenti alla 16.5.0-780 Secure Email Gateway versioni precedenti alla 15.5.5-014 16.x, versioni precedenti alla 16.5.0-780 Secure Email e Web Manager versioni precedenti alla 15.5.5-006 16.x, versioni precedenti alla 16.5.0-429 Azioni di mitigazione Ove non provveduto e in linea con le dichiarazioni del vendor, si raccomanda di aggiornare tempestivamente i prodotti vulnerabili seguendo le indicazioni dei relativi bollettini di sicurezza riportati nella sezione Riferimenti.
acn.gov.itSep 14, 2026extracted
NCSC-2026-0076 [1.03] [H/H] Kwetsbaarheden verholpen in Cisco Secure Firewall Management Center
Cisco heeft kwetsbaarheden verholpen in Cisco Secure Firewall Management Center. De kwetsbaarheid met kenmerk CVE-2026-20079 bevindt zich in de webinterface van Cisco Secure Firewall Management Center. Een ongeauthenticeerde externe kwaadwillende kan de authenticatiecontroles omzeilen door een onjuist systeemproces dat bij het opstarten is aangemaakt te misbruiken. De kwaadwillende kan deze kwetsbaarheid misbruiken door speciaal geprepareerde HTTP-verzoeken naar een getroffen apparaat te sturen. Een succesvolle exploit kan de aanvaller in staat stellen verschillende scripts en commando’s uit te voeren die root-toegang tot het apparaat mogelijk maken. De kwetsbaarheid met kenmerk CVE-2026-20131 bevindt zich in de webinterface van Cisco Secure Firewall Management Center. Deze kwetsbaarheid stelt ongeauthenticeerde externe kwaadwillende in staat om willekeurige Java-code uit te voeren met root-rechten. De kwetsbaarheid wordt veroorzaakt door de onveilige deserialisatie van door de gebruiker aangeleverde Java-byte-stromen. Een kwaadwillende kan deze kwetsbaarheid misbruiken door een speciaal geprepareerd, geserialiseerd Java-object naar de webgebaseerde beheerinterface van een getroffen apparaat te sturen. Een succesvolle exploit kan de aanvaller in staat stellen om willekeurige code op het apparaat uit te voeren en de rechten te verhogen tot root-niveau. Als de beheerinterface van Cisco Secure Firewall Management Center geen publieke internettoegang heeft, wordt het aanvalsoppervlak verkleind. Het is niet gebruikelijk om een managementinterface direct publiekelijk aan het internet bloot te stellen. Indien jouw organisatie gebruikmaakt van Cisco Security Cloud Control Firewall Management, dan betreft dit een SaaS-dienst (Software-as-a-Service) die door Cisco Systems automatisch wordt bijgewerkt als onderdeel van regulier onderhoud. Er is in dat geval geen actie van de gebruiker vereist. Het NCSC verwacht op korte termijn een publieke PoC en grootschalige pogingen tot misbruik. Het NCSC adviseert met klem de update zo spoedig mogelijk te installeren. Update 19-03-26: Uit onderzoek van Amazon threat intelligence blijkt dat CVE-2026-20131 vermoedelijk al sinds 26 januari actief is misbruikt voor het uitrollen van Interlock ransomware. Daarnaast is er inmiddels een publieke PoC verschenen voor kwetsbaarheid CVE-2026-20079. Het is daarom van groot belang om - indien dit nog niet gedaan is - te updaten naar de nieuwste versie van Cisco Secure Firewall Management Center. UPDATE 11-09-26: Cisco meldt dat succesvolle exploitatie van de kwetsbaarheid met kenmerk CVE-2026-20079 is waargenomen. Organisaties wordt geadviseerd de updates van Cisco direct toe te passen en kwetsbare systemen te controleren op aanwijzingen van misbruik. Raadpleeg de Talos blog voor aanvullende aanbevelingen. EINDE UPDATE
advisories.ncsc.nlSep 12, 2026extracted
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. The second flaw under exploitation is CVE-2026-20316 (CVSS score: 5.3), which could allow an unauthenticated, remote attacker to log in to an affected device using a low-privilege account to access sensitive data within susceptible systems. It can be paired with other Cisco Secure FMC vulnerabilities to elevate privileges. Cisco Talos said it identified three clusters of post-compromise activity of FMC instances associated with state-sponsored and crimeware threat actors. These include - UAT-12197, which has exploited CVE-2026-20079 to deploy JSP-based web shells and a Java Archive (JAR)-based command executor to query internal databases and obtain user authentication data and credentials UAT-11823, which has exploited both CVE-2026-20079 and CVE-2026-20316 to deliver a Netcat-based reverse shell, two bash scripts to harvest managed-device configurations, and a variant of Cyclops Blink, a modular ELF implant previously attributed to the Russian state-sponsored hacking group Sandworm UAT-11988, a ransomware operation that has exploited CVE-2026-20316 for initial access and then used legitimate built-in FMC tooling as part of a living-off-the-land (LotL) attack to conduct extensive reconnaissance of the victim's environment, drop tunneling tools to maintain network access, collect credentials, build a target list of endpoints to encrypt, terminate security tools, and deploy Qilin ransomware on selected systems. "Customers are strongly advised to apply hotfixes for affected software versions already released by Cisco for CVE-2026-20079 and CVE-2026-20316," Cisco said, adding it intends to ship a comprehensive hardening release for various internally discovered vulnerabilities next week. The development comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The second vulnerability, CVE-2026-20316, was added to the KEV catalog in late July 2026.
thehackernews.comSep 11, 2026extracted
Related Stories
1
Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)
Criminals are exploiting a critical Cisco Secure Email Gateway flaw that can turn a malicious email into root access. The vulnerability, tracked as CVE-2026-76461, carries a 9.8 CVSS score and affects physical and virtual Secure Email Gateway appliances regardless of their configuration. Cisco says there are no workarounds, so patching is the only fix. The bug lies in how Cisco's AsyncOS software handles incoming email. An attacker doesn't need to log in: they can send a booby-trapped message through a vulnerable gateway and, if the exploit works, run commands as root. Which is not exactly what you want from the box tasked with keeping nasty emails out. Cisco's Product Security Incident Response Team said it became aware of active exploitation in September, although the networking giant hasn't said who is behind the attacks, how long they have been going on, or how many organizations have been compromised. Cisco uncovered the bug while resolving a Technical Assistance Center support case. Signs suggest at least some Cisco cloud customers were caught up in the attacks. Cisco said it investigated devices belonging to its Secure Email Cloud service and directly contacted customers whose appliances showed indicators of possible compromise. It is now carrying out remediation and recovery work and says all of its Secure Email Cloud devices have been upgraded to AsyncOS 16.5.0-780. Admins running their own appliances have a little more work to do. Cisco recommends checking logs for signs of suspicious activity, but warns that finding nothing doesn't necessarily mean the system is clean. Once attackers have root access, Cisco says they could tamper with the logs and cover their tracks. Admins are also being told to check network and firewall logs for anything unusual, rather than relying on the gateway itself for answers. For virtual appliances suspected of being compromised, Cisco's recovery advice is fairly drastic: preserve the forensic evidence, deploy a fresh VM running fixed software, rebuild the configuration, and rotate credentials and cryptographic material. Cisco has fixed the bug in AsyncOS releases 15.5.5-014, 16.0.4-302 and 16.5.0-780, with customers strongly encouraged to move to the latter. There's still a decent-sized target pool out there. The Shadowserver Foundation was tracking more than 400 Cisco Secure Email Gateway appliances exposed to the internet as of Monday The flaw has also landed in CISA's Known Exploited Vulnerabilities catalog, with US federal civilian agencies ordered to remediate it by September 17. CVE-2026-76461 comes less than a year after attackers exploited another critical AsyncOS flaw, CVE-2025-20393, to break into Cisco Secure Email Gateway appliances and install persistence mechanisms. That bug eventually scored a perfect 10. For anyone still running an affected gateway, the message is fairly simple: the box designed to inspect hostile email can itself be pwned by one; attackers are already doing it, and there is no workaround to hide behind. ®
14 shared
Sep 15, 2026