top of page

CSSF Issues Notice on Actively Exploited Cisco Secure Email Gateway Vulnerability

vor 3 Tagen
1 Min. Lesezeit

On September 15, 2026, the Commission de Surveillance du Secteur Financier (CSSF) issued a notice regarding the active exploitation of a critical vulnerability in Cisco Secure Email Gateway. The vulnerability (CVE-2026-76461) affects the email parsing component of Cisco AsyncOS Software and may allow unauthenticated remote attackers to execute arbitrary commands with root privileges, potentially resulting in full system compromise.



The CSSF calls on supervised entities using Cisco Secure Email Gateway, either directly or through an ICT service provider, to assess their exposure, monitor the Computer Incident Response Center Luxembourg (CIRCL)'s dedicated tracking page and implement appropriate remediation measures without delay. The CSSF further highlights that a resulting compromise constitutes an unauthorised malicious access and may qualify as a major ICT-related incident subject to notification requirements under Circular CSSF 25/893 (DORA) or Circular CSSF 24/847, depending on the entity concerned.


CSSF-supervised entities using Cisco Secure Email Gateway may wish to assess whether they are affected and review the applicable remediation and incident-reporting requirements.

 
 
bottom of page