Cisco email security system can be hacked using email

Cisco email security system can be hacked using email

Attackers are actively exploiting critical vulnerabilities in virtual and physical Cisco Secure Email Gateway appliances designed to protect email services. This “vulnerability” allows you to use a malicious email to gain root access to a device. Report Register. The vulnerability was discovered while handling a technical support request from the Technical Support Center.








loopholes CVE-2026-76461 The CVSS rating is 9.8 and applies to both virtual and physical devices regardless of their configuration. go through data Cisco, the only way to resolve this issue is to install a security update. The problem lies with the incoming message handling mechanism in Cisco AsyncOS. An attacker does not need to compromise the system itself; sending a specially crafted letter through a vulnerable gateway is enough. If everything works “as expected”, he will be able to issue commands with administrator privileges.

Cisco experts reported that they only received information about the active exploit in September. Meanwhile, the company has remained mum on who is behind the attacks, when they occurred and how many organizations were compromised. There are indications that at least some Cisco cloud customers were affected. The company conducted an investigation and directly contacted customers with signs of exploitation. The cloud client has received an updated version of AsyncOS 16.5.0-780.

    Photo credit: Andy Makely/unsplash.com

Photo credit: Andy Makely/unsplash.com

Those managing equipment operations independently will have to work extra hard. Cisco recommends checking logs for signs of suspicious activity, but even the absence of such signs doesn’t mean the system hasn’t been compromised. Once attackers gain root access, they can rewrite logs and hide their traces. Therefore, administrators should also check network and firewall logs rather than rely solely on gateway data.

For virtual appliances suspected of being compromised, the company recommends saving state, logs, disk images and other data for further investigation, then deploying a new virtual machine with a corrected software version, restoring the configuration and replacing credentials and encryption data.

Cisco has fixed the vulnerability in AsyncOS versions 15.5.5-014, 16.0.4-302, and 16.5.0-780, but customers are strongly encouraged to use the latest versions. However, there are still many potential attack targets – on Monday, the Shadowserver Foundation reported that more than 400 Cisco Secure Email Gateway devices could be used for attacks originating from the Internet. The vulnerability has been included in the US federal agency CISA’s registry of known exploitable vulnerabilities, and US federal civilian agencies (not related to military agencies and intelligence agencies) have been ordered to eliminate the vulnerability by September 17.

CVE-2026-76461 comes less than a year after attackers compromised Cisco Secure Email Gateway devices by exploiting another AsyncOS security vulnerability, CVE-2025-20393. As a result, the maximum score for this vulnerability is 10 points. However, that’s a small thing compared to Barracuda’s recommendation to discard damaged products. ESG Gateway (Email Security Gateway).

If you find an error, select it with your mouse and press CTRL+ENTER. |Can you write better? We always welcome new authors.

source:

Exit mobile version