Cisco Warns of Critical Vulnerability in Secure Email Gateway
Cisco has issued an urgent warning to customers to patch a critical vulnerability in its Secure Email Gateway, which has already been exploited by hackers. The zero-day flaw allows an unauthenticated attacker to execute arbitrary commands using root privileges on the underlying operating system.
The vulnerability, tracked as CVE-2026-76461, is related to the email parsing of Cisco AsyncOS software in Secure Email Gateway. An attacker can exploit the flaw by sending a specially crafted email with malicious SQL statements to an affected device, according to Cisco.
Security researchers warn that the vulnerability could be used by state-linked actors for espionage. 'The email gateway's intended purpose is to filter these emails, so it would be easy for an attacker's message to make it into the device,' said Spencer McIntyre, director of exploit development at VulnCheck.