BoletimSec•September 17, 2026•🇵🇹Translated from Portuguese

Cisco Confirms Active Exploitation of Critical Secure Email Gateway Flaw Allowing Root Command Execution

Cisco has confirmed active exploitation of a critical vulnerability in the Secure Email Gateway that permits attackers to run commands with root privileges on affected appliances.

The issue, identified as CVE-2026-76461 and rated CVSS 9.8, resides in the AsyncOS software used by both physical and virtual versions of the product. Insufficient validation of message analysis logic allows an attacker to send a specially crafted email containing malicious SQL instructions. Successful exploitation results in arbitrary SQL command execution that ultimately grants root-level access.

The attack surface is particularly concerning because email gateways are designed to accept messages from any sender, meaning the vector is exposed by default to anyone who can craft the correct payload. Impacted versions include 15.5 and earlier, 16.0, and 16.5. Fixed releases are 15.5.5-0141, 16.0.4-302, and 16.5.0-780.

The Secure Email and Web Manager and Secure Web Appliance are not affected. No workaround exists, so administrators must apply the available patches. CISA added the identifier to its Known Exploited Vulnerabilities catalog on September 14 and set September 17 as the deadline for federal agencies to remediate.

Cisco verified the attacks occurred in September but did not disclose the scale of compromise. Organizations are advised to review email and cluster logs for suspicious SQL activity and to examine network and firewall logs for anomalous data transfers.

Related articles

BoletimSec•Vulnerabilities & Exploits

Atlassian Fixes Critical Path Traversal Flaw CVE-2026-21589 Exposing Files in Jira and Confluence

Atlassian has patched CVE-2026-21589, a CVSS 9.3 path traversal vulnerability that allows unauthenticated attackers to read files across eight products including Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye in Data Center editions. The flaw accepts manipulated paths where traversal sequences appear adjacent to forward slashes, backslashes or double colons, including URL-encoded variants. Attackers must know the exact file name and path because the vulnerability does not permit directory listing and is restricted to the web application root directory of each product. Configuration files located in predictable locations remain accessible to attackers familiar with the products. Patches have been released in specific versions such as Bitbucket 10.5.1, Confluence 10.2.19, Jira Software and Jira Service Management 11.3.12, Bamboo 12.1.12, Crowd 7.2.4 and Crucible and Fisheye 4.9.15. Atlassian found no evidence of exploitation in its cloud products, though the advisory does not address on-premises customer installations.

BoletimSec•Vulnerabilities & Exploits

Apache Struts CVE-2026-104711 Enables Remote Code Execution via Legacy RESTful Mapper

Apache Struts has patched four vulnerabilities, one of which permits unauthenticated remote code execution through an OGNL injection flaw. The issue, tracked as CVE-2026-104711, only affects applications that still rely on the legacy RESTful mapper; modern configurations using the default mapper, restful2, or the official Struts REST plugin remain unaffected. Exploitation occurs when the legacy mapper extracts action names and parameters directly from the URL, allowing attackers to inject malicious OGNL expressions. Vulnerable releases span 2.0.0–2.3.37, 2.5.0–2.5.33, 6.0.0–6.11.0, and 7.0.0–7.3.0, with fixes available in 6.12.0 and 7.4.0. The remaining three flaws impact availability or cause cross-request data leakage but do not lead to code execution, and only one received an “important” severity rating.

Habr•Vulnerabilities & Exploits

Automated Pentesting and BAS: How AI Systems Like XBOW Outpace Human Researchers in Vulnerability Discovery

The article explores how automated penetration testing and Breach and Attack Simulation tools have evolved to provide continuous validation of security controls beyond annual manual pentests. It explains the distinction between BAS, which tests individual attack techniques against security tools using frameworks like MITRE ATT&CK, and autopentest solutions that build complete attack paths to critical assets. Russian vendor Positive Technologies released PT Dephaze 3.0 in October 2025, incorporating machine learning for controlled internal pentesting and earning the National Runet Award. Globally, AI-driven systems demonstrated superior performance, with XBOW topping HackerOne rankings by discovering over 1,000 vulnerabilities including 54 critical ones in just 90 days. Google’s Big Sleep project, combining DeepMind and Project Zero, identified and helped patch CVE-2025-6965 in SQLite before widespread exploitation. These developments underscore the need to integrate automated validation into vulnerability management processes under the emerging CTEM framework.

Security NEXT•Vulnerabilities & Exploits

Critical SSRF Vulnerability Affects SonicWall SMA1000 Series Remote Access Appliances

SonicWall has disclosed four vulnerabilities in its SMA1000 series remote access products, with one rated critical. The most severe issue, CVE-2026-102255, is a server-side request forgery flaw in the WorkPlace interface that allows unauthenticated attackers to abuse the appliance as a forward proxy and reach internal functions. The vulnerability received the maximum CVSSv3.0 base score of 10.0. Two additional flaws, CVE-2026-102256 and CVE-2026-102257, enable authenticated OS command injection and unauthenticated path traversal via crafted archives, respectively. No exploitation has been observed in the wild at the time of disclosure. SonicWall has released updates to address all issues.