Kritisk sårbarhet i Cisco Secure Email Gateway utnyttjas aktivt

Imported from official source

Announcement

Cybersecurity Classified by Officially

Cisco har publicerat information om en kritisk SQL injection-sårbarhet i Cisco Secure Email Gateway som utnyttjas aktivt. Sårbarheten (CVE-2026-76461) har fått CVSS-klassificering 9.8 (CVSS v.3.1). [1] CISA har lagt till sårbarheten i KEV-katalogen (Known Exploited Vulnerabilities catalog). [2]

Framgångsrikt utnyttjande av sårbarheten innebär att en hotaktör kan fjärrexekvera kod på underliggande system med höga privilegier.

Påverkade produkter

  • Cisco Secure Email Gateway i fysisk och virtuell installation, version 16.5, 16.0 samt 15.5 och tidigare.
  • Cisco AsyncOS (samtliga versioner)

Cisco rekommenderar användare att uppgradera till version 16.5.0-780.

Rekommendationer

CERT-SE rekommenderar att uppgradera till säker version så snart som möjligt, undersöka egna system samt att följa leverantörens anvisningar i övrigt.

Källor

This is an extract. The publication continues at the source.

Source: CERT-SE.

Read the original at the source: https://www.cert.se/2026/09/kritisk-sarbarhet-i-cisco-secure-email-gateway-utnyttjas-aktivt.html

Officially imported this from CERT-SE’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
CERT-SE — imported from official source
Official source
https://www.cert.se/feed/atom.xml ATOM
Imported
October 03, 2026 20:38
Versions
1 recorded
Identity
https://www.cert.se/2026/09/kritisk-sarbarhet-i-cisco-secure-email-gateway-utnyttjas-ak...

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.