Cisco customers urged to patch e mail gateway flaw
Cisco is urging defenders to get out in entrance of a highly-dangerous flaw in its Safe E-mail Gateway (SEG) equipment, CVE-2026-76461 that might allow an unauthenticated, distant attacker to achieve the flexibility to execute arbitrary instructions with root privileges.
Listed on the US’ Cybersecurity and Infrastructure Safety Company’s (Cisa’s) Recognized Exploited Vulnerabilities (Kev) catalogue as of Monday 14 September, CVE-2026-76461 arises in SEG’s underlying AsyncOS software program and happens attributable to inadequate validation within the e mail parsing logic.
In easy phrases, an attacker might exploit this by sending an e mail containing malicious Structured Question Language (SQL) statements through an affected machine, Cisco defined. It was uncovered throughout a routine customer support interplay with its assist group.
“Cisco has launched software program updates that tackle this vulnerability. There aren’t any workarounds that tackle this vulnerability,” the provider mentioned in an announcement.
Cisco warned that each bodily and digital variations of SEG – no matter how they’re configured – are affected.
In addition to making use of Cisco’s patch, most defenders can shortly verify any tried exploit by combing their SEG mail_logs for suspicious SQL statements. The presence of entries within the output might function an indicator of compromise (IoC), however based on Cisco, all customers ought to moreover be aware that given CVE-2026-76461 opens up root privileges, an opsec-conscious risk actor might delete these.
“A root shell from a crafted e mail is about as unhealthy because it will get, and the CVSS [base 9.8] rating virtually undersells it,” mentioned Gunter Ollmann, chief know-how officer at Cobalt, a provider of penetration testing companies.
“E-mail gateways should learn untrusted content material from anybody on the web by design, then make belief choices about it. That is precisely the sort of place attackers search for.”
Ollman mentioned the relatively extra worrying side was the truth that attackers might wipe their IoCs. “In case your detection technique leans on matching recognized IoCs after the very fact, you could have already missed the intrusion,” he mentioned. “It is a good argument for placing extra weight on behavioral and network-level detection round these units, not simply signature checks.”
Perimeter merchandise focused
The disclosure of CVE-2026-76461 comes scorching on the heels of the invention of different vulnerabilities found in Cisco perimeter merchandise, on this case its Safe Firewall Administration Middle (FMC) software program.
The primary of those, CVE-2026-20079 permits an unauthenticated, distant attacker to bypass authentication and execute script recordsdata on the affected system to achieve root entry. The second, CVE-2026-20316, permits an unauthenticated, distant attacker to log in to an affected machine with a low-privileged account and probably to entry delicate information.
Based on an investigation performed by Cisco’s Talos risk analysis unit, two distinct exploitation clusters have been detected. Considered one of these clusters, attributed to a gaggle Cisco tracks as UAT-11823, finally led to the deployment of a variant of the Cyclops Blink malware.
Cyclops Blink has been extensively utilized by the Russian state APT mostly often called Sandworm – as soon as described by Mandiant as one of many “most brazen” nation-state threats round.
“Perimeter safety home equipment want the identical ongoing scrutiny as every other internet-facing software, not a patch cycle tied to vary home windows…. Assume energetic probing towards unpatched, reachable cases is already taking place,” famous Ollman.

