Cisco Fixes Critical Email Gateway Flaw After Active Exploitation
Cisco has released emergency patches for a critical vulnerability in its Secure Email Gateway appliance that could allow attackers to take over devices by sending malicious crafted emails. The flaw, tracked as CVE-2026-76461, is an SQL injection caused by insufficient validation in the product's email parsing code.
The vulnerability affects both physical and virtual versions of the product and was fixed in AsyncOS firmware releases 15.5.5-0141, 16.0.4-3021, and 16.5.0-780 released on Monday. Cisco became aware of active exploitation earlier this month.
Because the vulnerability has been exploited as a zero-day, simply upgrading to the patched firmware version is not enough. Organizations should also try to determine whether their own appliances have been compromised by reviewing mail logs for suspicious SQL statements or checking network and firewall logs outside the device.
Cisco advises organizations to review logs carefully due to the possibility that attackers could use root access to alter the logs and hide their tracks. For physical devices, Cisco recommends contacting the Cisco Technical Assistance Center if exploitation is suspected.