Cisco Secure Email Gateway vulnerability (CVE-2026-76461) in active exploitation

2026-09-15T20:51:32Z•f6879e1e56ce80891f0dbffc69073a8f0a2bf43abd07f1470c39230c32973c62
CVE-2026-76461CVE-2026-83548CVE-2026-83549Cisco Firewall Management CenterCisco Secure Email GatewayCyclops BlinkGOLD SHERWOODMITRE ATT&CKPHP malwareSonicWall SMA1000active exploitationcybercrime-as-a-servicedefense impairmenteducation sectormanaged service providersransomwareunderground AIweb server rootkit

What happened

Sophos news feed highlights multiple active exploitation campaigns, including a Cisco Secure Email Gateway vulnerability (CVE-2026-76461) and SonicWall SMA1000 vulnerabilities (CVE-2026-83548 and CVE-2026-83549). It also covers the return of Cyclops Blink targeting Cisco FMC devices, a PHP web-server rootkit, ransomware operations, underground AI services, and evolving defensive and MSP cybersecurity practices.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sophos_news
Record identifier
f6879e1e56ce80891f0dbffc69073a8f0a2bf43abd07f1470c39230c32973c62
Enrichment time
2026-09-15T20:51:32Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.