Unpatched Cisco AsyncOS Secure Email Gateway (CVE-2026-76461)
This rule identifies instances of Cisco Secure Email Gateway (AsyncOS) running vulnerable versions that are susceptible to CVE-2026-76461. It parses the software inventory data to identify appliances within branches 15.5, 16.0, and 16.5, comparing the patch and build versions against the known secure release versions (15.5.5-0141, 16.0.4-302, 16.5.0-780).
Microsoft Sentinel (KQL)

