news.mlab.sh
Back to the feed
vulnerability

Multiples vulnérabilités dans les produits Cisco (15 septembre 2026)

CriticalCVSS 9.8
Summary

A French security advisory from CERT-FR highlights multiple vulnerabilities in Cisco products, including the ability to execute arbitrary code remotely, cause a denial of service, and exploit SQL injection flaws. Cisco has confirmed that CVE-2026-76461 is actively being exploited. Users are advised to apply the provided security patches immediately.

CERT-FR has identified several security vulnerabilities within Cisco products. These vulnerabilities could allow an attacker to execute code remotely, trigger a denial of service, and exploit SQL injection vulnerabilities. Specifically, the advisory details issues within AsyncOS for Secure Email Gateway versions prior to 16.0.4-3021, 16.5.x prior to 16.5.0-780, and versions prior to 15.5.5-0141, as well as Secure Email and Web Manager versions prior to 16.5.0-429 and 15.5.5-006. Cisco has indicated that CVE-2026-76461 is currently being actively exploited. The advisory directs users to consult the linked Cisco security advisories for detailed information and available patches. These advisories include CVE-2026-20353, CVE-2026-76440, CVE-2026-76441, CVE-2026-76442, and CVE-2026-76443.

Read the full article at CERT-FR