Skip to content
Back to Guavy Wire
Stocks

Critical Flaw in Cisco Secure Email Gateway Exploited by Attackers

Instruments
CSCO
Share

Cisco has disclosed a critical vulnerability in its Secure Email Gateway appliances, allowing attackers to run arbitrary commands as root on the devices. The flaw, rated CVSS 3.1 base score of 9.8 out of 10.0, was discovered when Cisco's product security incident response team became aware of active exploitation in September.

The vulnerability allows attackers to inject malicious SQL statements in an email and have the gateway execute them, without requiring a login or access to the management interface. The company has already upgraded affected cloud devices to AsyncOS 16.5.0-780 and is urging customers to upgrade on-premises appliances to fixed versions.

Cisco also disclosed four more vulnerability classes rated 9.8 and one 7.5, affecting both Secure Email Gateway and Secure Email and Web Manager. The company noted that it was not aware of malicious use of these flaws apart from the exploited SQL injection flaw.

More on Stocks

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc