ZeroHour

Search: “Cisco Secure Email”

9 stories in the last 3d

Critical Cisco Secure Email Gateway zero-day gives attackers root access

Actively exploited Cisco Secure Email Gateway zero-day CVE-2026-76461 lets crafted emails trigger SQL injection and root command execution; CISA added it to KEV.

Cisco released emergency patches for CVE-2026-76461, a critical SQL injection in Secure Email Gateway (physical and virtual) caused by insufficient validation in email parsing. Sending a crafted email with malicious SQL statements can yield arbitrary command execution with root privileges. Cisco was aware of active exploitation before the fixes, and CISA added the flaw to its KEV catalog; patched AsyncOS releases are 15.5.5-0141, 16.0.4-3021, and 16.5.0-780. Because successful exploits grant root, Cisco warns logs may be tampered with and advises checking external firewall/network logs and rebuilding virtual appliances with rotated credentials.

CSO Onlineupdated · 2d agofirst · 2d agoExploit / PoC in the wild 17 sourcesCVE-2026-76461CVE-2025-203932

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Cisco warns CVE-2026-76460 (CVSS 10.0), an unauthenticated ISE auth bypass leading to root command execution, is under active exploitation and was added to CISA's KEV.

Cisco warned that CVE-2026-76460 (CVSS 10.0), an insufficient-authentication flaw in an Identity Services Engine (ISE) API endpoint, is being actively exploited by unauthenticated remote attackers and can yield root-privilege command execution on ISE and ISE-PIC regardless of configuration. Fixes shipped across ISE 3.1 through 3.5 patch branches; Cisco advised reviewing access.log for unexpected usernames (e.g., "dummyuser"), re-imaging affected nodes, and using iACLs, since no workarounds exist. CISA added the flaw to its KEV catalog on September 16, 2026, requiring FCEB agencies to patch by September 19. Cisco simultaneously issued 77 new CVEs, 41 affecting ISE and 28 affecting Secure Firewall products, days after confirming active exploitation of CVE-2026-76461 in Secure Email Gateway.

The Hacker News · 1d agoExploit / PoC in the wildCVE-2026-76460CVE-2026-76461CVE-2026-20176+27 CVEs2

Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard

Cisco patches dozens of critical flaws in FMC, ISE and Nexus Dashboard, including ISE bugs and an authentication bypass already exploited in the wild.

Cisco released patches for dozens of critical-severity CVEs in Secure Firewall Management Center, Identity Services Engine and Nexus Dashboard. ISE updates cover 20 CVEs including 12 critical ones; three publicly disclosed flaws (CVE-2026-20282, CVE-2026-20283, CVE-2026-20284) enable SQL injection, data tampering and command execution but require administrative access. FMC patches fix 18 CVEs, eight critical, several shared with ASA and FTD, where CVE-2026-20079 and CVE-2026-20316 have been exploited since August. Cisco also warned of a critical-severity ISE authentication bypass exploited in the wild as a zero-day.

Acronis Patches Exploited Vulnerability in cPanel Backup Plugin

Acronis urgently patched CVE-2026-87886 (CVSS 7.8), insecure file permissions enabling privilege escalation, exploited in targeted attacks on cPanel & WHM backups.

Acronis released urgent patches for CVE-2026-87886 (CVSS 7.8), insecure file permissions in the Backup plugin for cPanel & WHM and the Backup extension for Plesk that allow attackers to gain elevated privileges. Exploitation has been detected in the wild in limited, targeted attacks against the cPanel & WHM plugin, but not against the Plesk extension. All Linux versions of the plugin before build 1.9.3.1021 and the Plesk extension before build 1.8.11.638 are affected; Acronis urges immediate updates and has not shared technical details.

SecurityWeekupdated · 1d agofirst · 2d agoExploit / PoC in the wild 7 sourcesCVE-2026-87886

Enterprises Warned of Attacks Exploiting WSO2 Vulnerability

Attackers are actively exploiting CVE-2026-5430 (CVSS 10), a WSO2 JWT authentication bypass, to access enterprise API credentials and sensitive data.

WatchTowr's honeypot network recorded the first exploitation attempt of CVE-2026-5430 on September 13, roughly two months after the CVE record was published in early August. The flaw, patched by WSO2 in April with an advisory in May, carries a maximum CVSS score of 10 and allows JWT authentication bypass via tokens signed with unsupported algorithms, enabling unauthorized access and full account takeover. A forged JWT observed in the wild granted access to API backend endpoints, credentials, and consumer keys and secrets for every registered application. WSO2's API Manager, API Control Plane, Traffic Manager, and Universal Gateway are affected, and the platform serves nearly 1,000 enterprise customers in banking, government, telecom, and logistics.

SecurityWeekupdated · 1d agofirst · 2d agoExploit / PoC in the wild 3 sourcesCVE-2026-54302· 1 read

Cisco patches max-severity ISE flaw, the second critical zero-day this week

Cisco emergency-patched actively exploited CVE-2026-76460 (CVSS 10.0), an unauthenticated API flaw granting root on ISE appliances; CISA added it to KEV.

Cisco patched CVE-2026-76460, a CVSS 10.0 authentication bypass in a Cisco Identity Services Engine management API that lets unauthenticated attackers gain root privileges. It affects ISE and ISE-PIC in all configurations and is fixed in 3.1 Patch 12 through 3.5 Patch 4. CISA added the flaw to its Known Exploited Vulnerabilities catalog after confirmed in-the-wild exploitation. A broader review fixed 21 critical ISE flaws plus high- and medium-severity issues, following earlier exploited firewall flaws CVE-2026-20079 and CVE-2026-20131.

CSO Online · 17h agoExploit / PoC in the wildCVE-2026-76460CVE-2026-20079CVE-2026-201312· 2 reads

Cisco drops another exploited zero-day, this time a perfect 10

Cisco's CVSS 10.0 CVE-2026-76460 authentication bypass in Identity Services Engine is actively exploited, granting unauthenticated attackers root command execution.

Cisco disclosed CVE-2026-76460 (CVSS 10.0), an authentication bypass in Identity Services Engine (ISE) and ISE-PIC APIs that gives unauthenticated remote attackers command execution with root privileges; CISA added it to the KEV catalog. It follows CVE-2026-76461 (CVSS 9.8), an actively exploited flaw in Cisco Secure Email Gateway and Secure Email and Web Manager disclosed days earlier. Permanent fixes ship in ISE 3.1 Patch 12 through 3.5 Patch 4; ISE 3.0 is end-of-maintenance and ISE 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4 are available. No workaround exists, though ACLs restricting management traffic can serve as temporary mitigation.

The Register · Securityupdated · 17h agofirst · 1d agoExploit / PoC in the wild 26 sourcesCVE-2026-76460CVE-2026-764615· 1 read

The AI hacking apocalypse is not inevitable

Security experts, including former CISA and NCSC leaders, argue AI agent apocalypse claims are overblown and manageable with established cybersecurity controls.

Cybersecurity and national security experts, including SentinelOne's Juan Andres Guerrero-Saade, former CISA executive Matt Hartman, and ex-NCSC head Ciaran Martin, push back on claims that frontier AI agents could take over the internet. Martin called Anthropic CEO Dario Amodei's warning of a HuggingFace-style agent botnet capable of taking over the entire internet within 6-12 months "not a credible warning." Former GCHQ specialist Matt Tait noted frontier models require datacenter-scale supercomputers, making model self-extraction implausible. Experts argue monitoring, permission constraints, and network segmentation can manage agentic AI risk, while questioning the absence of federal oversight and independent third-party review.

CyberScoop · 18h agoAI safety & security in the wild

ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories

Unit 42 exposed CL-CRI-1171, a pay-per-install operation spreading OfferLoader and Insomnia RAT via YouTube and SEO poisoning to corporate and government targets.

The ThreatsDay bulletin leads with Unit 42's disclosure of CL-CRI-1171, a pay-per-install marketplace using YouTube channels and SEO-poisoning funnels to push trojanized software and the OfferLoader loader, which delivered Docro Hijacker, ARKTunnel and the cross-platform Insomnia RAT between July 2025 and April 2026. Oasis Security reported that 230 of 243 unauthenticated LocalAI instances were exploitable, with root command execution confirmed on 23 servers, theft of 127 AWS credential records, and exfiltration from a Thai military workstation. The roundup also covers Irregular's research on agentic self-modification, an AEPD-notified breach executed with an AI agent, CISA's warning that ransomware gangs exploit VMware vCenter CVE-2026-59310, and Oracle's September 2026 CPU fixing over 800 flaws.

The Hacker News · 20h agoThreat actor in the wildCVE-2026-59310