Cisco Fixes Critical Vulnerability in Secure Email Gateway Appliance
Cisco has released emergency patches for a critical vulnerability in its Secure Email Gateway appliance that could allow attackers to take over the device by sending malicious emails.
The flaw, tracked as CVE-2026-76461, is described as an SQL injection caused by insufficient validation in the product's email parsing code. This means that an attacker can exploit the vulnerability by sending a crafted email message containing malicious SQL statements through an affected device.
A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system. The flaw affects both physical and virtual versions of the product and was fixed in the AsyncOS firmware releases 15.5.5-0141, 16.0.4-3021, and 16.5.0-780 released Monday.
Cisco became aware of active exploitation of this vulnerability earlier this month, and the US Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities (KEV) catalog. Organizations should not only upgrade to the patched firmware version but also review their mail logs for suspicious SQL statements.