Cisco Fixes Critical Flaw in Secure Email Gateway
Cisco Systems has released software fixes to address an actively exploited flaw in its Secure Email Gateway. The critical vulnerability, tracked as CVE-2026-76461, allows an unauthenticated remote attacker to gain root-level access to affected systems.
The issue arises from insufficient validation within the product's email-parsing logic, which enables attackers to deliver malicious SQL statements through a crafted email.
Cisco has already upgraded Secure Email Cloud devices and contacted customers whose systems showed signs of possible compromise. Administrators are advised to review mail logs for suspicious SQL statements and external network and firewall logs for unexpected transfers.