Cybersecurity · September 16, 2026
Cisco has confirmed that attackers are actively exploiting a critical flaw in AsyncOS software for its Secure Email Gateway, tracked as CVE-2026-76461 with a near-maximum CVSS score of 9.8. The bug stems from how the gateway's email-parsing logic handles incoming messages, letting an unauthenticated remote attacker run commands with root privileges on affected appliances. Organizations running Secure Email Gateway should apply Cisco's patch as soon as possible given the confirmed in-the-wild attacks.
// source: thehackernews.com ↗