Attackers have already exploited a critical hole in Cisco’s Secure Email Gateway, and the networking giant wants every admin to update now. The vulnerability is CVE-2026-76461, scored 9.8.
AsyncOS, the operating system behind the gateway, fails to validate what it parses. A remote attacker with no credentials can hide SQL statements inside a crafted message. Once the device processes that mail, the injected statements execute as commands at root level on the host.
Both physical appliances and virtual instances carry the bug, and no particular setting makes a device safe. Cisco’s Secure Email and Web Manager and Secure Web Appliance are unaffected. Patched releases are AsyncOS 15.5.5-0141, 16.0.4-302, and 16.5.0-780. Cisco lists no workaround.
The company learned of real-world exploitation this month and says it has reached out to owners of cloud-hosted devices where malicious activity turned up. How many customers are affected remains undisclosed.
Root access means an intruder can cover their tracks, so Cisco recommends looking beyond the appliance. Admins can search mail logs for the string “COPY.*TO PROGRAM” to flag suspicious SQL, and should review firewall and network logs for odd uploads to outside addresses.
CISA’s Known Exploited Vulnerabilities catalog now lists the flaw, setting a September 17 deadline for federal agencies.
