Critical Flaw Exploited in Cisco Secure Email Gateway
Cisco has released patches for its Secure Email Gateway to fix an actively exploited vulnerability that allows attackers to gain root-level access. The critical flaw, tracked as CVE-2026-76461, carries a Common Vulnerability Scoring System score of 9.8 out of 10.
The bug allows an unauthenticated remote attacker to deliver malicious SQL statements through a crafted email, enabling arbitrary command execution with root privileges. This vulnerability affects Cisco Secure Email Gateway regardless of device configuration and no workaround is available.
Cisco has already upgraded Secure Email Cloud devices and contacted customers whose systems showed signs of possible compromise. The company recommends migration to the latest AsyncOS release, version 16.5.0-780.