Cisco Email Gateway Vulnerability Grants Root Access via Malicious Emails
A critical vulnerability has been discovered in Cisco Secure Email Gateway appliances that allows remote attackers to execute arbitrary commands with root privileges. The vulnerability, identified as CVE-2026-76461, is a SQL injection in the email parsing logic of the appliance's core engine.
Cisco's advisory notes that an unauthenticated attacker can send a specially crafted email containing malicious SQL statements, which will be executed by the gateway's parsing logic and grant the attacker root access to the underlying operating system. The company discovered the vulnerability during the resolution of a support case and disclosed it on September 14.
The attack surface is the email itself, which poses a significant risk as most enterprise environments rely on the email security gateway to validate incoming messages. This includes multi-factor authentication codes, password reset links, and identity verification tokens.
Cisco recommends that administrators deploy a new virtual machine running a fixed release, rebuild the product configuration from scratch, and renew all credentials and cryptographic materials installed on the appliance. This is not a patch, but rather a declaration that the compromised device cannot be trusted.