Cisco disclosed a critical vulnerability in Secure Email Gateway appliances running affected AsyncOS versions when inbound mail rules use File Analysis (Cisco AMP) or Content Filter features and the bundled Content Scanner Tools are older than 23.3.0.4823. Successful exploitation can let an attacker overwrite files at the operating-system level, enabling root-level account creation, configuration changes, arbitrary code execution, and denial of service. Cisco released software updates and said no alternative mitigations are available.
Palo Alto Networks also issued fixes for a serious PAN-OS management interface flaw that allows an unauthenticated attacker to execute certain PHP scripts and affect the integrity and confidentiality of the firewall, though the vendor said it does not permit arbitrary remote code execution. Exploitation attempts have already been observed and proof-of-concept code is public, increasing urgency for exposed management interfaces. Palo Alto said Cloud NGFW and Prisma Access are not affected, while PAN-OS 11.0 is out of support and will not receive a patch.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
By the time of disclosure, exploitation attempts against the PAN-OS vulnerability had already been observed and proof-of-concept code had been published. Organizations were urged to update immediately and apply Palo Alto's mitigation guidance.
Palo Alto Networks released security updates for a serious PAN-OS vulnerability affecting firewall management interfaces. The flaw allows an unauthenticated attacker to execute certain PHP scripts and could impact the integrity and confidentiality of PAN-OS; PAN-OS 11.0 is out of support and will not receive a fix.
Cisco released a software update for a critical vulnerability in Cisco Secure Email Gateway affecting vulnerable Cisco AsyncOS deployments with specific email-processing features enabled and outdated Content Scanner Tools. Successful exploitation could allow arbitrary file overwrite, root-level user creation, configuration changes, code execution, or denial of service.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
kyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.