安全客•September 16, 2026•🇨🇳Translated from Chinese

Cisco Secure Email Gateway CVE-2026-76461 Critical SQL Injection Flaw Exploited in the Wild for Root Access

Cisco Secure Email Gateway is affected by CVE-2026-76461, a CVSS 9.8 critical vulnerability that is already being exploited in the wild. Attackers can obtain root privileges on the gateway simply by sending one specially crafted email, with no authentication, user interaction, or bypass required.

Attack Mechanics

The flaw is an SQL injection located in the mail parsing logic of AsyncOS. When the gateway processes incoming messages, insufficient input validation allows embedded malicious SQL statements to be executed as legitimate commands on the underlying operating system. The entire attack occurs during automated mail inspection, before any recipient opens the message.

Why the Impact Is Severe

Secure Email Gateway functions as the enterprise email boundary device, scanning all inbound and outbound traffic for malware and phishing. Once compromised with root access, an attacker can install persistent backdoors, monitor every message, intercept or alter business-critical emails, use the gateway as a pivot into the internal network, and send highly trusted internal phishing messages.

Affected Versions and Remediation

Impacted releases are 15.5 and earlier, 16.0, and 16.5. Cisco provides no mitigation steps and urges immediate upgrade to 16.5.0-780 (or the corresponding fixed builds 15.5.5-014 and 16.0.4-302). Cloud customers have been contacted directly by Cisco where malicious activity was detected, but should still verify their deployments.

Detection Guidance

Administrators should search mail_logs for suspicious SQL patterns such as COPY.*TO PROGRAM. Because root-level access allows log tampering, organizations must also review firewall and network device logs for unexpected outbound connections originating from the gateway and inspect any underlying virtualization platform for signs of further compromise.

Broader Context

This incident highlights the recurring risk posed by internet-facing security appliances that receive untrusted data yet run with elevated privileges. Security teams are advised to audit all perimeter devices for current firmware, unnecessary exposed services, and centralized logging to reduce similar exposure.

Related articles

Habr•Vulnerabilities & Exploits

New Spectre-v2 Variant Uses JIT Compiler Branch Target Reuse for Cross-Process Data Extraction

Researchers from the Netherlands and Italy have published a paper detailing a fresh Spectre-v2 attack that reuses branch predictor state instead of injecting new instructions. The technique leverages the JIT compiler cBPF inside the Linux kernel to train the branch target predictor, enabling speculative execution that leaks sensitive data such as hashed root passwords. Practical demonstrations extracted credentials from the su process in an average of three to five minutes on AMD, Intel, and ARM processors. Partial success was shown with SpiderMonkey in Firefox and GraalVM, although realistic end-to-end attacks were not achieved with those engines. The work also covers additional topics including forensic detection of attacks against 1C servers, a record Debian Linux kernel patch set, zero-day fixes in TeamViewer and Apple Core Graphics, and critical flaws in Dell Container Storage Modules.

Security NEXT•Vulnerabilities & Exploits

Critical CVE-2026-21589 Affects Eight Atlassian Products with CVSS 9.3 Score

Atlassian has disclosed a critical vulnerability tracked as CVE-2026-21589 that impacts eight of its products. The flaw allows unauthenticated access to specific files located in the web application's root directory when an attacker already knows the file name and path. Products affected include Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian rates the issue Critical with a CVSSv4.0 base score of 9.3 and warns that Data Center editions face elevated risk due to potential exposure of sensitive files. The company released patches for all affected products and urges immediate updates, while also providing mitigation steps and indicators of compromise for organizations unable to patch right away.

Security NEXT•Vulnerabilities & Exploits

Fortinet Releases FortiMail Updates to Patch Zero-Day CVE-2026-104286

Fortinet has begun distributing updates for its FortiMail email security product to address the zero-day vulnerability CVE-2026-104286. The flaw allows unauthenticated attackers to write arbitrary files to the system by sending specially crafted HTTP requests. The company first published a security advisory on October 1, 2026, confirming active exploitation and providing Indicators of Compromise while preparing fixes. On October 5, 2026, Fortinet updated the advisory and released patched versions including FortiMail 8.0.2, 7.6.7, and 7.4.9. Organizations still running the 7.2 branch are advised to migrate to the 7.4 branch or later to obtain protection. The advisory reference is FG-IR-26-175.

Hispasec•Vulnerabilities & Exploits

Critical CVE-2026-61500 in Rejetto HFS Allows Admin Session Forgery Leading to Remote Code Execution

A critical vulnerability tracked as CVE-2026-61500 is being actively exploited in Rejetto HTTP File Server (HFS), enabling unauthenticated attackers to forge administrator sessions and achieve remote code execution. The flaw impacts versions 3.0.0 through 3.2.0 and was addressed in release 3.2.1, making immediate updates essential for any internet-exposed instances. The root cause lies in the use of JavaScript Math.random() to generate the session cookie signing key instead of a cryptographically secure random number generator. Attackers can reconstruct the internal state of this weak PRNG from login responses, allowing them to create valid admin cookies. Once authenticated as an administrator, the attacker can abuse the server_code functionality to execute arbitrary JavaScript on the server. Exploitation activity was first observed on October 1, 2026, targeting U.S. systems and attributed to an unidentified actor based in China, following the public release of a Python proof-of-concept in late September.