Tuesday , September 15 2026
Secure Email Gateway

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers are using this flaw in real attacks. The flaw, known as CVE-2026-76461, impacts Cisco AsyncOS software on Cisco Secure Email Gateway devices. CVE-2026-76461 is a type of SQL injection flaw, listed as CWE-89.

It might let a remote attacker send special requests to a weak Cisco Secure Email Gateway device and run any commands on the system. Successful exploitation can give root-level access, allowing an attacker full control of the affected device. Cisco Secure Email Gateway is often used at the edge of business networks to check email traffic and stop harmful messages, spam, phishing, and malware.

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

VPN flaw exposed 246,000 personnel records in japan

Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
VPN flaw exposed 246,000 personnel records in japan

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
Hackers deploy Casbaneiro Trojan that activates on bank websites

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Palo Alto Networks has revealed a serious flaw in PAN-OS. It may let a remote attacker without a password run...
Read More
Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Critical Check Point VPN flaws allow remote code execution attacks

Check Point Software has revealed and fixed two major VPN flaws, CVE-2026-85102 and CVE-2026-85103. Both have a top CVSS score...
Read More
Critical Check Point VPN flaws allow remote code execution attacks

Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being used...
Read More
Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

A Russian-speaking hacker has used artificial intelligence like never before. They sent out hundreds of AI agents to find and...
Read More
Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Six Chinese AI companies ran large-scale attacks on American AI models since late 2024, according to U.S. cybersecurity and intelligence...
Read More
CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Compromising this system could lead to big security flaws because it handles a lot of incoming and outgoing emails, including ones with important business information.

An attacker with root access could change email security rules, look at saved messages, make ways to stay hidden, stop security logs, or use the broken gateway to get into the bigger network.

Cisco Secure Email Gateway 0-Day Vulnerability Exploited

Security teams need to check if the appliance has communicated to unknown external systems or done surprising admin actions. CISA added the weakness to the KEV list on September 14, 2026, and told affected federal agencies to use vendor fixes by September 17, 2026.

The agency also labeled the issue as needing forensic assessment under Binding Operational Directive 26-04, showing the high risk tied to confirmed exploitation.

The listing does not say if the flaw has been used in ransomware attacks. But, weaknesses that allow remote command execution without authentication and with root access are very useful to attackers, especially if the product is on the internet.

Organizations using Cisco Secure Email Gateway need to find all open AsyncOS instances, check their software versions, and follow Cisco’s advice for fixes quickly.

Where mitigations are unavailable, CISA advises organizations to follow applicable BOD 26-04 guidance for cloud services or discontinue use of the affected product. Security teams should prioritize incident-response checks alongside remediation.

Check Also

Secure Email Gateway

Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center …