Cisco Patches Critical Vulnerability in Secure Email Gateway
Cisco has disclosed and patched a critical vulnerability in its Secure Email Gateway that allowed threat actors to gain root-level access to affected appliances.
The flaw, tracked as CVE-2026-76461, is an SQL injection vulnerability in Cisco AsyncOS email parsing functionality used by Secure Email Gateway. Cisco rated it a CVSS score of 9.8.
Cisco confirmed active exploitation of the vulnerability and released indicators of compromise to support investigations.