BreachFeed
company

Cisco

Tracked by 2 people

Track Cisco

Incident history

CISA Advisories·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu4jscpn8gcxhpu275pfxesf

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-76460 Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability CVE-2026-87886 Acronis Backup Incorrect Default Permissions Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing…

Cyber Security Headlines·3 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp5002bhku2o55vvzgc

Cisco zero-day goes straight to root, BambooToken branches into Linux, CenterPoint breach claim hits 7M+

Cisco zero-day goes straight to root BambooToken branches into Linux CenterPoint breach claim hits 7M+ Get the show notes here: https://cisoseries.com/cybersecurity-news-september-16-2026/ Huge thanks to our episode sponsor, Vanta Risk and regulation are ramping up, and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC…

CSO Online·6 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu33lhpy6urghpu2st0y0cz2

Critical Cisco Secure Email Gateway zero-day gives attackers root access

Cisco released emergency patches for a critical vulnerability in its Secure Email Gateway appliance that could allow attackers to take over the device by simply sending malicious crafted emails to users. The flaw was already being exploited in the wild when the fixes were released. Tracked as CVE-2026-76461, the vulnerability is described by Cisco as an SQL injection caused by insufficient validation in the product’s email parsing code. Parsing incoming email messages for threats is this…

CyberScoop·6 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu2uiuok6krfhpu24nmh1dj6

Cisco warns customers of actively exploited zero-day in email gateways

The company confirmed the defect was exploited before it was disclosed and patched, but it did not describe the nature of the attacks or the scope of impact across its customer base. The post Cisco warns customers of actively exploited zero-day in email gateways appeared first on CyberScoop.

The Hacker News·6 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu2ag43t5yjahpu2rkzh46ou

Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing logic that could allow an unauthenticated, remote attacker