Cisco users urged to patch email gateway flaw


Cisco is urging defenders to get out in front of a highly-dangerous flaw in its Secure Email Gateway (SEG) appliance, CVE-2026-76461 that could enable an unauthenticated, remote attacker to gain the ability to execute arbitrary commands with root privileges.

Listed on the US’ Cybersecurity and Infrastructure Security Agency’s (Cisa’s) Known Exploited Vulnerabilities (Kev) catalogue as of Monday 14 September, CVE-2026-76461 arises in SEG’s underlying AsyncOS software and occurs due to insufficient validation in the email parsing logic.

In simple terms, an attacker could exploit this by sending an email containing malicious Structured Query Language (SQL) statements via an affected device, Cisco explained. It was uncovered during a routine customer service interaction with its support team.

“Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability,” the supplier said in a statement.

Cisco warned that both physical and virtual versions of SEG – regardless of how they are configured – are affected.

Besides applying Cisco’s patch, most defenders can quickly confirm any attempted exploit by combing their SEG mail_logs for suspicious SQL statements. The presence of entries in the output may serve as an indicator of compromise (IoC), but according to Cisco, all users should additionally note that given CVE-2026-76461 opens up root privileges, an opsec-conscious threat actor could delete these.

“A root shell from a crafted email is about as bad as it gets, and the CVSS [base 9.8] score almost undersells it,” said Gunter Ollmann, chief technology officer at Cobalt, a supplier of penetration testing services.

“Email gateways have to read untrusted content from anyone on the internet by design, then make trust decisions about it. That’s exactly the kind of position attackers look for.”

Ollman said the rather more worrying aspect was the fact that attackers could wipe their IoCs. “If your detection strategy leans on matching known IoCs after the fact, you may have already missed the intrusion,” he said. “This is a good argument for putting more weight on behavioral and network-level detection around these devices, not just signature checks.”

Perimeter products targeted

The disclosure of CVE-2026-76461 comes hot on the heels of the discovery of other vulnerabilities discovered in Cisco perimeter products, in this case its Secure Firewall Management Center (FMC) software.

The first of these, CVE-2026-20079 enables an unauthenticated, remote attacker to bypass authentication and execute script files on the affected system to gain root access. The second, CVE-2026-20316, enables an unauthenticated, remote attacker to log in to an affected device with a low-privileged account and potentially to access sensitive data.

According to an investigation conducted by Cisco’s Talos threat research unit, two distinct exploitation clusters have been detected. One of these clusters, attributed to a group Cisco tracks as UAT-11823, ultimately led to the deployment of a variant of the Cyclops Blink malware.

Cyclops Blink has been extensively used by the Russian state APT most commonly known as Sandworm – once described by Mandiant as one of the “most brazen” nation-state threats around.

“Perimeter security appliances need the same ongoing scrutiny as any other internet-facing application, not a patch cycle tied to change windows…. Assume active probing against unpatched, reachable instances is already happening,” noted Ollman.



Source link

Recent Articles

spot_img

Related Stories