Critical Cisco Security Flaw Exposes Root Access via Email
Cisco has issued an alert about a critical vulnerability in its Secure Email Gateway software. The flaw, tracked as CVE-2026-76461, allows an unauthenticated attacker to run arbitrary commands with root privileges on the underlying operating system.
The issue is caused by insufficient validation of email parsing logic and can be exploited by sending a crafted email message containing malicious SQL statements. Cisco warned that upon successful exploitation, threat actors may obtain command execution with root privileges.
Cisco has released fixes for affected versions of AsyncOS software, but administrators are advised to update their systems as soon as possible. The company also recommends cross-checking network logs and firewall logs outside the impacted device to identify potential anomalous activity.