Organizations using Cisco Secure Email Gateway must treat a newly added flaw as an emergency patching priority after U.S. CISA confirmed its active exploitation.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical zero-day vulnerability in Cisco Secure Email Gateway to its Known Exploited Vulnerabilities (KEV) catalog. This action, reported by Security Affairs, transforms the issue from a vendor disclosure into a mandatory compliance deadline for U.S. federal agencies and a definitive alert for enterprises worldwide.
The vulnerability, tracked as CVE-2025-76461, carries a severe CVSS score of 9.8. Its addition to the KEV catalog on or after September 16 signals that CISA has validated evidence of real-world attacks, demanding an immediate response.
For IT security teams, particularly in sectors like finance and critical infrastructure, the primary directive is to apply the official Cisco security update immediately. A compromised email gateway, a privileged network-edge appliance, could grant attackers deep access for data interception and lateral movement.
If patching is temporarily infeasible, two critical interim controls must be executed in parallel. First, restrict access to the device's web management interface from all untrusted networks, as this is the likely attack vector. Second, adopt a post-breach mindset: actively review appliance logs for signs of unauthorized administrative activity and rotate all device credentials. This verification step is crucial due to the confirmed active exploitation.
The listing in the KEV catalog is the strongest possible signal for prioritization. It provides unambiguous urgency for enterprises to verify their Cisco Secure Email Gateway deployments and act decisively to mitigate this severe, actively targeted threat.
使用思科安全電郵網關的機構,必須將此新增漏洞視為緊急修補優先事項,因美國CISA已確認其正遭積極利用。
美國網絡安全及基礎設施安全局已將思科安全電郵網關的一個嚴重零日漏洞,納入其「已知遭利用漏洞目錄」。此舉將事件從供應商披露轉化為美國聯邦機構的強制合規期限,亦為全球企業發出明確警報。
該漏洞編號為CVE-2025-76461,CVSS評分高達9.8。其於9月16日或之後納入KEV目錄,顯示CISA已核實現實攻擊證據,要求立即採取行動。
對資訊安全團隊而言,尤其在金融及關鍵基礎設施等領域,首要指令是立即套用思科官方安全更新。遭入侵的電郵網關作為具特權的網絡邊緣設備,可能使攻擊者獲得深度訪問權限以攔截數據及進行橫向移動。
若暫時無法進行修補,必須同步執行兩項關鍵過渡措施:首先,限制所有不受信任網絡對設備網絡管理介面的訪問,因這很可能是攻擊向量。其次,採取事後補救思維:主動審查設備日誌以偵測未授權管理活動跡象,並重設所有設備憑證。鑑於已確認存在積極利用情況,此驗證步驟至關重要。
納入KEV目錄是優先處理的最強烈信號,為企業提供明確的緊迫性指標,須核實其思科安全電郵網關部署情況,並果斷採取行動以應對此嚴重且正遭定向攻擊的威脅。
