Cisco Warns SEG Vulnerability Exposes Systems to Root Access
Cisco has disclosed a critical vulnerability in its Secure Email Gateway (SEG) that allows unauthenticated attackers to gain full root control of the underlying system. The flaw, tracked as CVE-2026-76461, is rated 9.8 on the CVSS scale and affects SEG configurations, including physical appliances and virtual instances.
The vulnerability is caused by a mail-parsing bug in AsyncOS that allows attackers to send crafted email messages containing malicious SQL statements. This can result in arbitrary commands being run with root privileges on the host operating system.
Cisco has published corrected AsyncOS builds, version 15.5.5-014, 16.0.4-302, and 16.5.0-780, which must be installed to patch the vulnerability. There is no manual workaround available.