Cisco's email gateway is under attack, and CISA added seven more flaws
Key takeaways
- CVE-2026-76461 in AsyncOS for Cisco Secure Email Gateway is being exploited in the wild and allows unauthenticated command execution as root.
- CISA added seven flaws to its Known Exploited Vulnerabilities catalog covering SonicWall, Artifactory, Switchvox, Starlette, Kestra and LiteLLM.
- Federal agencies had until 16 September to remediate the Starlette issue, with reverse shells and crypto miners already observed.
Cisco has warned that CVE-2026-76461, affecting AsyncOS for Cisco Secure Email Gateway, is being exploited in the wild. An unauthenticated attacker can execute arbitrary commands on the underlying operating system with root privileges. No credentials, full control of the box.
What else landed this week
CISA added seven flaws to its Known Exploited Vulnerabilities catalog, covering SonicWall, Artifactory, Switchvox, Starlette, Kestra and LiteLLM. Federal agencies had until 16 September, today, to remediate the Starlette issue. Attackers have been dropping reverse shells and crypto miners through these, which is the usual signature of opportunistic mass scanning rather than targeted work.
There is also a LiteSpeed flaw affecting cPanel versions before 6.3.7, fixed in a release published on 11 September.
The entry worth pausing on
LiteLLM is the interesting one. That is AI infrastructure sitting on the actively exploited list, which tells you the AI stack is now part of the attack surface rather than adjacent to it. Proxy layers in front of model APIs tend to hold credentials for several providers at once, so the blast radius of a compromise there is wider than the component's profile suggests.
Why the Cisco bug is the priority
An unauthenticated root execution flaw on a mail gateway is close to worst case, because the gateway sees everything before anyone else does. Every inbound message, every attachment, and often the credentials used to relay them. Patching that is not a this-quarter job.
The wider pattern is familiar from the September KEV additions and from the Zimbra flaw exploited earlier this year: mail infrastructure keeps getting picked because it is exposed by definition and patched on a slower cycle than anything customer facing. The same held for Oracle's 943 patch release in August.
What to do
Check whether you run Cisco Secure Email Gateway and patch AsyncOS first. Then work the KEV list rather than the CVSS scores, because a confirmed exploited flaw with a middling score is a worse problem than a critical one nobody has weaponised.