---
title: Cisco תיקנה פגיעות אבטחה מסוג יום אפס ב-Secure Email Gateway שנוצלה בתקיפות
url: https://www.dataloco.com/he/cisco-secure-email-gateway
published: 2026-09-18T06:25:22+00:00
language: he
section: אבטחה
source: https://www.bleepingcomputer.com/news/security/new-cisco-secure-email-zero-day-exploited-to-execute-commands-as-root/
organizations: Cisco, CISA, Shadowserver
publisher: Dataloco
---

# Cisco תיקנה פגיעות אבטחה מסוג יום אפס ב-Secure Email Gateway שנוצלה בתקיפות

חברת Cisco הזהירה את לקוחותיה לעדכן גרסה כדי לתקן פגיעות אבטחה קריטית מסוג יום אפס ב-Secure Email Gateway, אשר נוצלה על ידי תוקפים בתקיפות פעילות.

הפגיעות, המזוהה כ-CVE-2026-76461, נמצאה בלוגיקת ניתוח הדואר האלקטרוני של תוכנת Cisco AsyncOS עבור Secure Email Gateway. היא משפיעה על מכשירים פיזיים ווירטואליים, ללא קשר להגדרות המכשיר. ניצול מוצלח של הפגיעות מאפשר לתוקפים מרוחקים שאינם מאומתים להריץ פקודות שרירותיות עם הרשאות שורש במערכת ההפעלה הבסיסית. התוקף יכול לנצל את הפגיעות על ידי שליחת הודעת דואר אלקטרוני מתוכננת המכילה הצהרות SQL זדוניות דרך מכשיר פגוע, וזאת בשל אימות לא מספיק בלוגיקת ניתוח הדואר.

צוות התגובה לאירועי אבטחה של Cisco זיהה את הניצול הפעיל של הפגיעות בספטמבר 2026. החברה שיתפה אינדיקטורים לפריצה והמליצה למגני רשת לחפש הצהרות SQL חשודות ביומני הדואר של כל מכשיר באשכול. בנוסף, מנהלי מערכות התבקשו לבדוק יומני רשת וחומת אש כדי לאתר פעילות חשודה, כולל העלאות והורדות מכתובות אינטרנט חיצוניות או זדוניות, מכיוון שתוקפים עשויים להסיר ראיות לניצול הפגיעות.

הסוכנות לאבטחת סייבר ותשתיות, CISA, הוסיפה את הפגיעות לקטלוג הפגיעות הידועות כמי שנוצלו והורתה לסוכנויות פדרליות לתקן את מערכותיהן עד ה-17 בספטמבר. במקביל, ארגון Shadowserver עוקב כעת אחרי יותר מ-400 מכשירי Secure Email Gateway, אך לא סיפק מידע לגבי מספר המכשירים שהם מלכודות דבש או כאלו שכבר אובטחו.

במקביל לטיפול ביום האפס, Cisco תיקנה ביום שני ארבע פגיעות קריטיות נוספות המשפיעות על מכשירי Secure Email Gateway ו-Secure Email and Web Manager, אם כי ציינה כי אין ראיות שהן נוצלו בפועל. החברה תיקנה בעבר פגיעות ב-Cisco AsyncOS בינואר, וחשפה כי קבוצות כופרה וקבוצות נתמכות על ידי מדינות ניצלו פגיעות ב-Secure Firewall Management Center. מאז נובמבר 2021, CISA סימנה 98 פגיעות של Cisco כמי שנוצלו באופן פעיל בתקיפות, כולל שבע שנוצלו על ידי כנופיות כופרה.

## This story in other languages

- [Português (Brasil)](https://www.dataloco.com/pt-br/cisco-corrige-falha-de-dia-zero-no-secure-email-gateway-explorada-em-ataques)
- [日本語](https://www.dataloco.com/ja/ciscosecure-email-gateway)
- [中文](https://www.dataloco.com/zh/ciscosecure-email-gateway)
- [한국어](https://www.dataloco.com/ko/cisco-secure-email-gateway)
- [ไทย](https://www.dataloco.com/th/cisco-secure-email-gateway)
- [हिन्दी](https://www.dataloco.com/hi/cisco-na-hamal-ma-isatamal-hae-secure-email-gateway-ka-shanaya-thavasa-thashha-ka-sathhara)
- [Türkçe](https://www.dataloco.com/tr/cisco-saldirilarda-kullanilan-kritik-guvenlik-acigini-kapatti)
- [Русский](https://www.dataloco.com/ru/cisco-ustranila-uiazvimost-nulevogo-dnia-v-secure-email-gateway-kotoraia-ispolzovalas-v-atakax)
- [العربية](https://www.dataloco.com/ar/shrk-cisco-taaalg-thghr-amny-mn-noaa-alyom-alsfr-fy-boab-albryd-alalktrony-alamn)
- [Deutsch](https://www.dataloco.com/de/kritische-sicherheitslucke-in-cisco-secure-email-gateway-wird-aktiv-ausgenutzt)
- [Español](https://www.dataloco.com/es/cisco-advierte-sobre-falla-critica-en-secure-email-gateway-explotada-en-ataques)
- [Français](https://www.dataloco.com/fr/cisco-corrige-une-faille-de-securite-zero-day-exploitee-dans-ses-passerelles-de-messagerie-securisees)
- [Nederlands](https://www.dataloco.com/nl/cisco-waarschuwt-klanten-voor-nul-dag-beveiligingslek-in-secure-email-gateway)
- [Svenska](https://www.dataloco.com/sv/cisco-atgardar-noll-dag-sarbarhet-i-secure-email-gateway-som-utnyttjats-i-attacker)
- [Norsk](https://www.dataloco.com/no/cisco-tetter-kritisk-sarbarhet-i-secure-email-gateway-som-ble-utnyttet-i-angrep)
- [Polski](https://www.dataloco.com/pl/cisco-naprawia-luke-zero-day-w-secure-email-gateway-wykorzystywana-w-atakach)
