Communiqué

Active exploitation of a vulnerability on Cisco Secure Email Gateway

The CSSF has been made aware of the current active exploitation of a vulnerability, CVE-2026-76461, on Cisco Secure Email Gateway. This is a vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.

CIRCL, the Computer Incident Center Luxembourg, keeps tracks on this vulnerability and potential recommendation at this URL: https://vulnerability.circl.lu/vuln/CVE-2026-76461.

The CSSF strongly recommends all supervised entities concerned to duly take note of this report and to take appropriate actions.

In addition, as the unauthenticated remote code execution consists of an unauthorised malicious access, the CSSF reminds all supervised entities that this constitutes a major ICT-related incident that needs to be notified, according to either Circular CSSF 25/893 (DORA) or CSSF 24/847, depending on the type of entity.