CSSF has alerted supervised financial entities to active exploitation of a critical vulnerability in Cisco Secure Email Gateway that permits unauthenticated remote attackers to execute arbitrary commands with root privileges. The vulnerability, tracked as CVE-2026-76461, affects the email parsing functionality of Cisco AsyncOS Software and poses a significant risk to institutional infrastructure across the financial sector.
- Vulnerability ID: CVE-2026-76461
- Affected Software: Cisco AsyncOS Software for Cisco Secure Email Gateway
- Attack Vector: Unauthenticated remote code execution with root privileges
- Regulatory Framework: Circular CSSF 25/893 (DORA) or CSSF 24/847
The Commission de Surveillance du Secteur Financier, Luxembourg’s financial services regulator, strongly recommends that all regulated entities assess their email infrastructure and implement immediate remediation measures. The vulnerability’s exploitation constitutes an unauthorized malicious access incident, triggering mandatory notification requirements under Luxembourg’s Digital Operational Resilience Act framework.
Regulated institutions must evaluate their exposure to this vulnerability and determine applicable notification obligations based on their entity classification. The regulator emphasizes that active exploitation campaigns underscore the severity of the threat and the urgency of patching affected systems. Organizations should prioritize vulnerability remediation within their critical infrastructure assets and document mitigation efforts for regulatory compliance purposes.
