Cisco Warns of Active Exploitation of Critical Secure Email Gateway Zero-Day (CVE-2026-76461)

AI-generated NewsSnap summary based on source reporting.
Published: 2026-09-15
Category: technology
Source: The Hacker News

Cisco has issued a warning regarding a new critical vulnerability (CVE-2026-76461) in AsyncOS Software for Cisco Secure Email Gateway, which is under active exploitation. The flaw, carrying a CVSS score of 9.8, stems from insufficient validation in the email parsing logic, enabling unauthenticated, remote attackers to execute arbitrary commands with root privileges by sending a specially crafted email. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to apply patches by September 17, 2026.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai