Skip to main content
Security

Cisco says email-gateway zero-day was exploited before patch

Cisco says email-gateway zero-day was exploited before patch Image: Primary
Cisco disclosed and patched CVE-2026-76461, a critical zero-day in Cisco Secure Email Gateway that it says was exploited before disclosure. The flaw affects Cisco AsyncOS Software and lets unauthenticated remote attackers execute commands with root privileges on vulnerable systems. Cisco said it contacted Cisco Secure Email Cloud customers where it identified possible compromise indicators and deployed mitigations within its managed environment. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog. Cisco released indicators of compromise, though attackers may be able to hide or remove traces.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from CyberScoop and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI Capital
AI Capital

Profound raises $180 million at $1.8 billion valuation

AI marketing startup Profound has raised $180 million in a Series D round at a $1.8 billion valuation, according to a company announcement planned for Tuesday. Sequoia Capital and Kleiner Perkins co-led the financing. The supplied...

Security Infrastructure
Security Infrastructure

CISA flags ransomware use of VMware vCenter flaw

CISA updated its Known Exploited Vulnerabilities catalog to say ransomware gangs are actively abusing CVE-2026-59310, a critical VMware vCenter directory-traversal flaw patched by Broadcom in July, BleepingComputer reported. Broad...

Capital Products
Capital Products

Crane Venture Partners raises €419 million across four vehicles

Crane Venture Partners announced €419 million in committed capital across four investment vehicles and plans to build an inception-to-seed platform with MassMutual Ventures. The vehicles include Crane III at €146 million, a €129 m...

Security Infrastructure
Security Infrastructure

Sysdig details rapid Marimo exploit path to AWS-backed SSH access

Sysdig reported that a threat actor exploited CVE-2026-39987, a pre-authenticated remote-code-execution flaw in Marimo, then reached an SSH bastion host in eight seconds. The reported chain used credentials harvested from the comp...

Security
Security

Cisco patches exploited Secure Email Gateway flaw

Cisco warned customers to patch CVE-2026-76461, a critical Secure Email Gateway vulnerability it says is being actively exploited. Cisco said an unauthenticated remote attacker could send a crafted email containing malicious SQL s...

Products Capital
Products Capital

Thatch raises $108 million at $1 billion valuation

Health-benefits platform Thatch raised $108 million from existing investors at a $1 billion valuation, TechCrunch reported. The company was valued at $410 million when it raised a $40 million Series B 17 months earlier. Thatch off...