Cisco Warns of Critical Vulnerability in Secure Email Gateway Appliance
Cisco has issued an urgent warning to users of its Secure Email Gateway (SEG) appliance regarding a critical vulnerability that can be exploited by attackers to gain root privileges.
The flaw, identified as CVE-2026-76461, arises in the SEG's underlying AsyncOS software due to insufficient validation in the email parsing logic. This allows an attacker to send an email containing malicious Structured Query Language (SQL) statements via an affected device, potentially leading to arbitrary command execution.
Cisco has released software updates that address this vulnerability, and users are advised to apply the patches as soon as possible. The company warned that both physical and virtual versions of SEG - regardless of configuration - are affected by this flaw.
Gunter Ollmann, chief technology officer at Cobalt, a supplier of penetration testing services, noted that the CVSS base score for this vulnerability is 9.8, indicating its high severity. He also emphasized that attackers could potentially delete indicators of compromise (IoCs), making it challenging to detect and respond to such incidents.