CISA Warns of Cisco Secure Email Gateway 0-Day Vulnerability Actively Exploited in Attacks
2026/09/15 CyberSecurityNews — 米国の Cybersecurity and Infrastructure Security Agency (CISA) は、Cisco Secure Email Gateway に影響する高深刻度の脆弱性 CVE-2026-76461 を Known Exploited Vulnerabilities (KEV) カタログに追加したと発表するとともに、この脆弱性が実環境の攻撃で積極的に悪用されていると警告している。脆弱性 CVE-2026-76461 は、Cisco Secure Email Gateway アプライアンスで使用される Cisco AsyncOS Software に影響を及ぼす SQL インジェクションの欠陥であり、CWE-89 に分類されている。
Tag: CVE-2026-76461
Cisco Secure Email Gateway の脆弱性 CVE-2026-76461 が FIX:root 権限でのコマンド実行の可能性
Hackers Exploit Critical Cisco Secure Email Gateway Flaw to Execute Commands as Root
2026/09/15 gbhackers — Cisco が公表したのは、Cisco Secure Email Gateway の深刻度が Critical の SQL インジェクション脆弱性 CVE-2026-76461 (CVSS:9.8) と、セキュリティ・アップデートのリリースに関する情報である。この脆弱性は物理/仮想の Cisco Secure Email Gateway デバイス上で動作する Cisco AsyncOS Software に影響を及ぼす。CVE-2026-76461 を悪用する未認証のリモート攻撃者は、影響を受けるデバイス上で root 権限で任意のコマンドを実行する可能性がある。この問題を 9月14日に公表した Cisco は、設定内容にかかわらず、すべての脆弱なゲートウェイ導入環境がリスクにさらされていると警告している。