ZeroHour
The Register · Securitypublished ()ingested Carly Page
Part of a story covered by 15 sources: “Cisco Warns of Actively Exploited Zero-Day CVE-2026-76461 in Secure Email Gateway: Crafted Email Yields Unauthenticated Root Command Execution” — merged summary and timeline →

Cisco email security boxes can be rooted by... an email

criticalExploit / PoC exploited in the wildimportance 92CVE-2026-76461CVE-2025-20393
AI summary · glm-5.3

Attackers actively exploit critical Cisco Secure Email Gateway flaw CVE-2026-76461, turning a malicious email into unauthenticated root access.

Cisco Secure Email Gateway appliances are being actively exploited via CVE-2026-76461, a CVSS 9.8 AsyncOS flaw requiring no authentication—a crafted email can yield root command execution with no workarounds. Cisco's PSIRT became aware of active exploitation in September; some Secure Email Cloud customers showed indicators of compromise and all cloud devices were upgraded to AsyncOS 16.5.0-780. The bug is in CISA's KEV catalog with federal agencies ordered to remediate by September 17; Shadowserver counted 400+ exposed appliances. Fixes are available in AsyncOS 15.5.5-014, 16.0.4-302, and 16.5.0-780, and attackers with root may tamper with logs to hide activity.

  • CVE-2026-76461 scores 9.8; unauthenticated root via crafted email, no workarounds
  • Active exploitation confirmed in September; added to CISA KEV with Sept 17 deadline
  • Fixed in AsyncOS 15.5.5-014, 16.0.4-302, and 16.5.0-780
  • Over 400 appliances internet-exposed per Shadowserver
  • Attackers with root can tamper with gateway logs to cover tracks

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-20393
Improper Input Validation in Cisco Secure Email and Web Appliances Allows Root Commands

CVE-2025-20393 is an improper input validation flaw (CWE-20) in Cisco Secure Email Gateway, Secure Email, AsyncOS software, and Web Manager appliances that lets attackers execute arbitrary commands with root privileges on the underlying operating system. The flaw is triggered when an affected appliance processes improperly validated input, though the CISA record does not specify the access vector or whether authentication is required. Successful exploitation yields full compromise of the appliance at the highest OS privilege level, which is significant because these devices sit in the email- and web-security path of enterprise networks. Organizations running these Cisco appliances are affected; CVSS has not yet been published and no public proof-of-concept is known. Exploitation is confirmed in the wild: CISA added the vulnerability to the KEV catalog on 2025-12-17, EPSS estimates a 29.9% chance of exploitation within 30 days (98th percentile), and ransomware use remains undetermined.

Do: Apply the mitigations or updates Cisco specifies in its advisory for CVE-2025-20393 without waiting for a CVSS score; the CISA KEV entry directs users to vendor mitigations, applicable BOD 22-01 cloud-service guidance, or discontinuing use if mitigations are unavailable. Because this record contains no fixed-release details, check the Cisco PSIRT advisory for the exact patched AsyncOS and Web Manager versions before planning the upgrade. In the meantime, review appliance logs and configurations for signs of unexpected command execution or changes, since active exploitation is confirmed and ransomware use is still unknown.

10.030% KEV
  • Cisco Secure Email Gateway / Secure Email
  • Cisco AsyncOS Software
  • Cisco Web Manager appliance
largeroughly tens of thousands of appliance deployments worldwide (exact installed base unpublished)
CVE-2026-76461
Unauthenticated SQL Injection to Root RCE in Cisco Secure Email Gateway

Cisco AsyncOS Software for Cisco Secure Email Gateway contains a SQL injection flaw (CWE-89) in its email parsing logic, caused by insufficient validation of message content. An unauthenticated, remote attacker can trigger it simply by sending a crafted email containing malicious SQL statements through an affected gateway, with no user interaction required. Successful exploitation allows arbitrary SQL execution that escalates to arbitrary operating-system command execution with root privileges, fully compromising the appliance and all mail flowing through it. Any organization running an affected version of Cisco Secure Email Gateway is impacted, and because these appliances sit on the inbound mail path they are inherently reachable over the network. There is no known public proof-of-concept, the flaw is not on the CISA KEV list, and no in-the-wild exploitation has been reported to date, though the CVSS 9.8 rating makes patching urgent.

Do: Upgrade to the fixed AsyncOS release listed in the corresponding Cisco PSIRT advisory as soon as possible, since the flaw is unauthenticated, requires no user interaction, and yields root. Until patched, apply any Cisco-documented workarounds and tightly restrict which hosts can submit mail to the gateway where operationally feasible. Review mail and system logs on these appliances for anomalies such as SQL errors in parsing, unexpected processes, or unexplained outbound connections that could indicate exploitation attempts.

9.82% KEV PoC ×2
  • Cisco Secure Email Gateway (Cisco AsyncOS Software)
large≈ tens of thousands of gateway deployments (order of 10,000–50,000 appliances)
Full article500 words · extracted from theregister.com · click to collapse

security

Attackers already exploiting the critical flaw, and Cisco warns they may be able to cover their tracks once they're in

Criminals are exploiting a critical Cisco Secure Email Gateway flaw that can turn a malicious email into root access.

The vulnerability, tracked as CVE-2026-76461, carries a 9.8 CVSS score and affects physical and virtual Secure Email Gateway appliances regardless of their configuration. Cisco says there are no workarounds, so patching is the only fix.

The bug lies in how Cisco's AsyncOS software handles incoming email. An attacker doesn't need to log in: they can send a booby-trapped message through a vulnerable gateway and, if the exploit works, run commands as root.

REG AD

Which is not exactly what you want from the box tasked with keeping nasty emails out.

REG AD

Cisco's Product Security Incident Response Team said it became aware of active exploitation in September, although the networking giant hasn't said who is behind the attacks, how long they have been going on, or how many organizations have been compromised. Cisco uncovered the bug while resolving a Technical Assistance Center support case.

Signs suggest at least some Cisco cloud customers were caught up in the attacks. Cisco said it investigated devices belonging to its Secure Email Cloud service and directly contacted customers whose appliances showed indicators of possible compromise. It is now carrying out remediation and recovery work and says all of its Secure Email Cloud devices have been upgraded to AsyncOS 16.5.0-780.

Admins running their own appliances have a little more work to do. Cisco recommends checking logs for signs of suspicious activity, but warns that finding nothing doesn't necessarily mean the system is clean.

Once attackers have root access, Cisco says they could tamper with the logs and cover their tracks. Admins are also being told to check network and firewall logs for anything unusual, rather than relying on the gateway itself for answers.

For virtual appliances suspected of being compromised, Cisco's recovery advice is fairly drastic: preserve the forensic evidence, deploy a fresh VM running fixed software, rebuild the configuration, and rotate credentials and cryptographic material. 

Cisco has fixed the bug in AsyncOS releases 15.5.5-014, 16.0.4-302 and 16.5.0-780, with customers strongly encouraged to move to the latter.

There's still a decent-sized target pool out there. The Shadowserver Foundation was tracking more than 400 Cisco Secure Email Gateway appliances exposed to the internet as of Monday

The flaw has also landed in CISA's Known Exploited Vulnerabilities catalog, with US federal civilian agencies ordered to remediate it by September 17.

REG AD

CVE-2026-76461 comes less than a year after attackers exploited another critical AsyncOS flaw, CVE-2025-20393, to break into Cisco Secure Email Gateway appliances and install persistence mechanisms. That bug eventually scored a perfect 10.

For anyone still running an affected gateway, the message is fairly simple: the box designed to inspect hostile email can itself be pwned by one; attackers are already doing it, and there is no workaround to hide behind.  ®

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.theregister.com/security/2026/09/15/cisco-email-security-boxes-can-be-rooted-by-an-email/5296604