Critical Cisco Zero-Day Flaw Allows Root RCE via Email
Cisco has patched CVE-2026-76461, a critical zero-day vulnerability in its Secure Email Gateway appliances that is already being exploited in the wild. The flaw carries a CVSS score of 9.8 and enables an unauthenticated remote attacker to execute arbitrary commands with root privileges on the underlying operating system by sending a specially crafted email through a vulnerable device.
The vulnerability resides in the email parsing logic of Cisco AsyncOS Software, which does not sufficiently validate certain information while parsing email messages. An attacker can exploit it remotely by sending a crafted message containing malicious SQL statements through the affected gateway.
SUCCESSFUL EXPLOITATION ENABLES THE ATTACKER TO EXECUTE ARBITRARY SQL STATEMENTS THAT CAN LEAD DIRECTLY TO COMMAND EXECUTION WITH ROOT PRIVILEGES ON THE UNDERLYING OPERATING SYSTEM. Cisco's CVSS vector, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, highlights the severity of the attack.