- RCE
- No patch
- No workaround
- No public IoCs
Recommendation is to reimage to a known-good config. Whatever that is, without indicators.
Good luck I guess??
- RCE
- No patch
- No workaround
- No public IoCs
Recommendation is to reimage to a known-good config. Whatever that is, without indicators.
Good luck I guess??
www.bleepingcomputer.com/news/securit...
www.bleepingcomputer.com/news/securit...
Cisco Alerts on Critical 10.0 CVSS AsyncOS Zero Day Actively Exploited by China Linked APT, No Patch Available
Cisco Alerts on Critical 10.0 CVSS AsyncOS Zero Day Actively Exploited by China Linked APT, No Patch Available
-impacts Cisco Secure Email Gateway And Cisco Secure Email and Web Manager
-CVE-2025-20393
-CVSS score: 10
-APT is UAT-9686
blog.talosintelligence.com/uat-9686/
-impacts Cisco Secure Email Gateway And Cisco Secure Email and Web Manager
-CVE-2025-20393
-CVSS score: 10
-APT is UAT-9686
blog.talosintelligence.com/uat-9686/
www.bleepingcomputer.com/news/securit...
www.bleepingcomputer.com/news/securit...
CVE-2026-76461: A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote…
CVSS 9.8 · exploited
https://beta.vulnsea.com/cve/CVE-2026-76461
#CVE #infosec #cybersecurity #threatintel
CVE-2026-76461: A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote…
CVSS 9.8 · exploited
https://beta.vulnsea.com/cve/CVE-2026-76461
#CVE #infosec #cybersecurity #threatintel
Angreifer nutzen diese, um SQL-Befehle auf verwundbaren Systemen auszuführen und mit Root-Rechten zu operieren. Betreiber sollten unverzüglich aktiv werden. ➡️ https://www.bsi.bund.de/dok/1208172
Angreifer nutzen diese, um SQL-Befehle auf verwundbaren Systemen auszuführen und mit Root-Rechten zu operieren. Betreiber sollten unverzüglich aktiv werden. ➡️ https://www.bsi.bund.de/dok/1208172
blog.talosintelligence.com/uat-9686/
blog.talosintelligence.com/uat-9686/
Cisco has finally shipped security updates for its Email Security Gateway and Secure Email and Web Manager devices, which fix CVE-2025-20393, a vulnerability in the devices’ AsyncOS that has been exp…
#hackernews #news
Cisco has finally shipped security updates for its Email Security Gateway and Secure Email and Web Manager devices, which fix CVE-2025-20393, a vulnerability in the devices’ AsyncOS that has been exp…
#hackernews #news