Security News

Cybersecurity news aggregator

🔓
CRITICAL Vulnerabilities Help Net Security

Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)

Cisco has released a patch for CVE-2026-76461, a critical (CVSS 9.8) SQL injection vulnerability in its Secure Email Gateway appliances that is being actively exploited. The vulnerability affects Cisco AsyncOS Software versions 16.5, 16.0, and 15.5 and earlier.
Read Full Article →

Attackers have leveraged a zero-day SQL injection vulnerability (CVE-2026-76461) to compromise Cisco Secure Email Gateway appliances, Cisco confirmed on Monday. The vendor’s Product Security Incident Response Team became aware of active exploitation of this vulnerability in September 2025, and has shared indicators of compromise that organizations can look for to check whether they’ve been hit. About CVE-2026-76461 The vulnerability affects versions 16.5, 16.0, and 15.5 and earlier of Cisco AsyncOS Software, running on on-premises physical … More → The post Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) appeared first on Help Net Security .

Share this article