Kritisk sårbarhet i Cisco Secure Email Gateway utnyttjas aktivt
Cybersecurity Classified by Officially
Cisco har publicerat information om en kritisk SQL injection-sårbarhet i Cisco Secure Email Gateway som utnyttjas aktivt. Sårbarheten (CVE-2026-76461) har fått CVSS-klassificering 9.8 (CVSS v.3.1). [1] CISA har lagt till sårbarheten i KEV-katalogen (Known Exploited Vulnerabilities catalog). [2]
Framgångsrikt utnyttjande av sårbarheten innebär att en hotaktör kan fjärrexekvera kod på underliggande system med höga privilegier.
Påverkade produkter
- Cisco Secure Email Gateway i fysisk och virtuell installation, version 16.5, 16.0 samt 15.5 och tidigare.
- Cisco AsyncOS (samtliga versioner)
Cisco rekommenderar användare att uppgradera till version 16.5.0-780.
Rekommendationer
CERT-SE rekommenderar att uppgradera till säker version så snart som möjligt, undersöka egna system samt att följa leverantörens anvisningar i övrigt.
Källor
This is an extract. The publication continues at the source.
Source: CERT-SE.
Read the original at the source: https://www.cert.se/2026/09/kritisk-sarbarhet-i-cisco-secure-email-gateway-utnyttjas-aktivt.html
Officially imported this from CERT-SE’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- CERT-SE — imported from official source
- Official source
- https://www.cert.se/feed/atom.xml ATOM
- Imported
- October 03, 2026 20:38
- Versions
- 1 recorded
- Identity
-
https://www.cert.se/2026/09/kritisk-sarbarhet-i-cisco-secure-email-gateway-utnyttjas-ak...