Cisco Warns of Zero-Day Exploit in Secure Email Gateway
Cisco has revealed that attackers are exploiting a previously unknown flaw in its Secure Email Gateway appliances. The vulnerability, identified as CVE-2026-76461, allows attackers to run arbitrary commands as root on the devices with no login required.
The company warned that attackers can inject malicious SQL statements into an email, which the gateway executes without sufficient validation. This enables the attacker to execute arbitrary SQL statements and gain command execution with root privileges on the underlying operating system.
Cisco's product security incident response team became aware of active exploitation in September, and the company has already upgraded its cloud devices to AsyncOS 16.5.0-780. On-premises customers are advised to upgrade to fixed versions, including AsyncOS 15.5.5-014, 16.0.4-302, and 16.5.0-780.
The United States Cybersecurity and Infrastructure Security Agency (CISA) has added the flaw to its list of known exploited vulnerabilities (KEV) catalogue. Cisco also published a hardening advisory covering four more vulnerability classes rated 9.8 and a fifth rated 7.5, affecting both Secure Email Gateway and Secure Email and Web Manager.