Cisco Patches Critical Vulnerability in Secure Email Gateway
Cisco has released patches to address a critical vulnerability in its Secure Email Gateway after attackers were found exploiting the flaw. The SQL injection bug, tracked as CVE-2026-76461, can grant an unauthenticated remote attacker root-level command execution on an affected appliance.
The vulnerability affects the email parsing component of Cisco AsyncOS Software for Secure Email Gateway and was disclosed in a security advisory on September 14, 2026. Cisco assigned it a CVSS base score of 9.8 out of 10 due to its high severity.
Cisco's Product Security Incident Response Team discovered active exploitation during September 2026, and the company strongly recommends migration to version 16.5.0-780 for affected systems running earlier versions.