Cisco Email Gateway Flaw Actively Exploited, Patch Urged Immediately
Cisco has issued an advisory for CVE-2026-76461, a critical SQL injection vulnerability in its AsyncOS for Secure Email Gateway. The flaw allows an unauthenticated remote attacker to execute arbitrary commands with root privileges by sending a specially crafted email through the affected gateway.
The vulnerability was added to the CISA Known Exploited Vulnerabilities catalog on September 14, indicating it was exploited as a zero-day before disclosure. Cisco has not attributed the activity to any threat actor, and no public proof-of-concept exploit code existed at publication.
Rapid7 urges administrators to treat the fix as an emergency rather than waiting for routine patch cycles, and to prioritize upgrades over leaning on monitoring or network controls alone.