Hackers Exploit Critical Cisco Secure Email Gateway Vulnerability in the Wild to Run Malicious Code
Cisco warns attackers actively exploit zero-day CVE-2026-76461 in Secure Email Gateway, gaining unauthenticated root command execution via crafted emails.
Cisco PSIRT confirmed active in-the-wild exploitation of CVE-2026-76461 throughout September 2026, a zero-day in Secure Email Gateway AsyncOS that lets remote, unauthenticated attackers execute arbitrary commands with root privileges by sending maliciously crafted emails containing injected SQL statements. Physical appliances, virtual deployments, and Cisco Secure Email Cloud instances were affected; Cisco deployed server-side remediations for cloud tenants but on-premises admins must patch themselves. Fixes ship in AsyncOS 16.5.0-780 plus branches 16.0.4-3021 and 15.5.5-0141, and no workarounds exist.
- Zero-day CVE-2026-76461 enables unauthenticated root command injection via crafted emails
- Actively exploited throughout September 2026 across cloud and on-premises deployments
- Patch targets AsyncOS 16.5.0-780 plus 16.0.4-3021 and 15.5.5-0141 branches
- No workarounds; Cisco advises mail log review, forensic snapshots, rebuilds, and credential rotation
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-76461 | Unauthenticated SQL Injection to Root RCE in Cisco Secure Email Gateway Cisco AsyncOS Software for Cisco Secure Email Gateway contains a SQL injection flaw (CWE-89) in its email parsing logic, caused by insufficient validation of message content. An unauthenticated, remote attacker can trigger it simply by sending a crafted email containing malicious SQL statements through an affected gateway, with no user interaction required. Successful exploitation allows arbitrary SQL execution that escalates to arbitrary operating-system command execution with root privileges, fully compromising the appliance and all mail flowing through it. Any organization running an affected version of Cisco Secure Email Gateway is impacted, and because these appliances sit on the inbound mail path they are inherently reachable over the network. There is no known public proof-of-concept, the flaw is not on the CISA KEV list, and no in-the-wild exploitation has been reported to date, though the CVSS 9.8 rating makes patching urgent. Do: Upgrade to the fixed AsyncOS release listed in the corresponding Cisco PSIRT advisory as soon as possible, since the flaw is unauthenticated, requires no user interaction, and yields root. Until patched, apply any Cisco-documented workarounds and tightly restrict which hosts can submit mail to the gateway where operationally feasible. Review mail and system logs on these appliances for anomalies such as SQL errors in parsing, unexpected processes, or unexplained outbound connections that could indicate exploitation attempts. | 9.8 | 2% | KEV PoC ×2 |
| large≈ tens of thousands of gateway deployments (order of 10,000–50,000 appliances) |
Full article515 words · extracted from cybersecuritynews.com · click to collapse
Cisco has issued an urgent warning regarding an actively exploited zero-day vulnerability in its Secure Email Gateway appliances that allows remote, unauthenticated attackers to execute arbitrary commands with highest-level root privileges.
Tracked as CVE-2026-76461, the flaw stems from a severe parsing breakdown in Cisco AsyncOS Software, enabling adversaries to compromise both physical and virtual deployments simply by routing a maliciously crafted email message through an exposed gateway.
The security defect lies in AsyncOS’s email parsing logic, where insufficient input sanitization lets threat actors embed malicious SQL statements directly into inbound email payloads. Upon receipt and processing by the appliance, these crafted queries execute unchecked, triggering a command injection vector that escalates directly into full root operating system access.
Because the flaw can be triggered remotely without prior credentials or complex network staging, it presents a substantial risk of enterprise boundary takeover, corporate espionage, and stealthy persistence across downstream infrastructure.
Cisco Secure Email Gateway Vulnerability Exploited
Cisco’s Product Security Incident Response Team confirmed that threat actors have actively weaponized this flaw in the wild throughout September 2026.
The vulnerability emerged during an investigation of an internal support case handled by the Cisco Technical Assistance Center, which subsequently exposed active intrusions across corporate appliances and instances hosted within Cisco Secure Email Cloud.
While Cisco has notified impacted cloud tenants and deployed server-side remediations across its managed cloud environments, on-premises administrators remain solely responsible for applying security patches to protect their organizations.
Investigating suspected intrusions presents distinct operational hurdles due to the extensive privileges acquired during compromise. Cisco advises security teams to inspect their text mail logs for anomalies, specifically hunting for rogue database syntax using commands such as grep -i "COPY.*TO PROGRAM" mail_logs across all clustered nodes.
However, because root-level adversaries can effortlessly delete local logs, tamper with audit trails, and manipulate running processes, internal forensics alone may prove inconclusive.
Incident responders must cross-check perimeter firewall flows and outbound network telemetry to detect unexpected external connections, unusual data exfiltration, or secondary-stage payload downloads.
Because no practical workarounds exist for CVE-2026-76461, immediate patching is imperative. Cisco has remediated the security flaw in AsyncOS updates, designating Release 16.5.0-780 as the primary target build, alongside earlier release branches including versions 16.0.4-3021 and 15.5.5-0141.
For administrators running on-premises virtual gateway instances showing signs of prior exploitation, Cisco strongly recommends preserving volatile forensic snapshots, destroying the suspect virtual machines, and rebuilding clean configurations from scratch, along with rolling all appliance credentials and internal certificates.
Beyond deploying immediate software updates, organizations should reinforce their gateway architecture to minimize future exposure. Administrators must isolate mail routing from management interfaces, restrict administrative portal access to verified internal bastions, and place all email security appliances behind robust, two-layer filtering firewalls to stop unauthenticated command-execution attempts at the perimeter.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/cisco-secure-email-gateway-flaw-exploited/