Cisco Secure Email Vulnerability Exploited, Root Privileges Possible
A critical SQL injection vulnerability has been discovered in Cisco Secure Email, allowing unauthenticated remote attackers to execute commands with root privileges.
The vulnerability, CVE-2026-76461, has a CVSS score of 9.8 and is currently listed as actively exploited on the CISA list.
Cisco describes the issue as a validation flaw in AsyncOS' email parsing logic, which can lead to executing arbitrary SQL commands or taking over the device.