【Security Vulnerability Alert】Cisco Secure Email Gateway contains a critical security vulnerability (CVE-2026-76461)

 
2026/9/22 ~ 2027/3/22
View Count:36

Forwarded from Taiwan Computer Emergency Response Team / Coordination Center Security Information Alert TWCERTCC-200-202609-00000017

[Content Description]
Cisco has issued a critical security vulnerability advisory for its Secure Email Gateway (CVE-2026-76461, CVSS:9.8). This vulnerability allows an unauthenticated remote attacker to remotely execute arbitrary code (RCE) on the underlying operating system with root privileges by sending a specially crafted email containing malicious SQL commands. Note: Cisco has currently observed attackers exploiting this vulnerability. It is recommended to take temporary mitigation measures as soon as possible to prevent possible attacks targeting this vulnerability.

[Affected Platforms]
Cisco AsyncOS for Cisco Secure Email Gateway versions 15.5 (inclusive) and earlier
Cisco AsyncOS for Cisco Secure Email Gateway version 16.0
Cisco AsyncOS for Cisco Secure Email Gateway version 16.5

[Recommended Measures]
Please update to the following versions: Cisco AsyncOS for Cisco Secure Email Gateway 15.5.5-014 (inclusive) and later versions, Cisco AsyncOS for Cisco Secure Email Gateway 16.0.4-302 (inclusive) and later versions, Cisco AsyncOS for Cisco Secure Email Gateway 16.5.0-780 (inclusive) and later versions

[References]
1. https://www.twcert.org.tw/tw/cp-169-11206-b668b-1.html

Files
system_update_alt參考資料
Top↑