Cisco Secure Email Gateway Hit by Critical SQL Injection Flaw
Cisco has confirmed that a critical SQL injection vulnerability in its Secure Email Gateway is being actively exploited. The flaw, identified as CVE-2026-76461, can lead to operating-system command execution with root privileges and allows an attacker to modify appliance configurations or access information stored on the system.
The vulnerability was disclosed by Cisco on September 14, 2026, after its Product Security Incident Response Team became aware of exploitation. The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76461 to its Known Exploited Vulnerabilities catalog the same day.
Cisco strongly recommends migrating to AsyncOS 16.5.0-780, where possible, and has already upgraded Secure Email Cloud devices to that release. The company warns that attackers may remove or hide evidence of exploitation, making it essential for defenders to correlate appliance logs with external firewall and network telemetry.