Cisco Secure Email Gateway vulnerability (CVE-2026-76461) in active exploitation
2026-09-15T20:51:32Z•f6879e1e56ce80891f0dbffc69073a8f0a2bf43abd07f1470c39230c32973c62
CVE-2026-76461CVE-2026-83548CVE-2026-83549Cisco Firewall Management CenterCisco Secure Email GatewayCyclops BlinkGOLD SHERWOODMITRE ATT&CKPHP malwareSonicWall SMA1000active exploitationcybercrime-as-a-servicedefense impairmenteducation sectormanaged service providersransomwareunderground AIweb server rootkit
What happened
Sophos news feed highlights multiple active exploitation campaigns, including a Cisco Secure Email Gateway vulnerability (CVE-2026-76461) and SonicWall SMA1000 vulnerabilities (CVE-2026-83548 and CVE-2026-83549). It also covers the return of Cyclops Blink targeting Cisco FMC devices, a PHP web-server rootkit, ransomware operations, underground AI services, and evolving defensive and MSP cybersecurity practices.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sophos_news
- Record identifier
- f6879e1e56ce80891f0dbffc69073a8f0a2bf43abd07f1470c39230c32973c62
- Enrichment time
- 2026-09-15T20:51:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.