Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026091708090303 | Publication Time | 2026-09-17 08:42:04 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-09-17 08:42:04 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】Cisco Secure Email Gateway Contains a Critical Cybersecurity Vulnerability (CVE-2026-76461) |
|||
| [Content]
Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202609-00000017 Cisco issued an advisory regarding a critical cybersecurity vulnerability affecting its Secure Email Gateway (CVE-2026-76461, CVSS: 9.8). This vulnerability allows an unauthenticated remote attacker to send a specially crafted email containing malicious SQL commands and remotely execute arbitrary code (RCE) with root privileges on the underlying operating system. Note: Cisco has currently observed attackers exploiting this vulnerability. It is recommended to implement temporary mitigation measures as soon as possible to prevent potential attacks targeting this vulnerability. Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
Cisco AsyncOS for Cisco Secure Email Gateway version 15.5 and earlier |
|||
|
[Recommended Actions] Please update to the following versions: Cisco AsyncOS for Cisco Secure Email Gateway version 15.5.5-014 or later |
|||
|
[Reference] |
|||