Malicious Emails Can Root Cisco Email Security Boxes
Cisco's Secure Email Gateway appliances are vulnerable to a critical flaw that can be exploited by an attacker sending a malicious email. The bug, tracked as CVE-2026-76461, carries a 9.8 CVSS score and affects physical and virtual Secure Email Gateway appliances regardless of their configuration.
The vulnerability lies in how Cisco's AsyncOS software handles incoming email. An attacker doesn't need to log in: they can send a booby-trapped message through a vulnerable gateway and gain root access, which is not what you want from the box tasked with keeping nasty emails out.
Cisco became aware of active exploitation in September, but it hasn't said who is behind the attacks or how long they have been going on. The networking giant has fixed the bug in AsyncOS releases 15.5.5-014, 16.0.4-302 and 16.5.0-780, with customers strongly encouraged to move to the latter.
Cisco's Product Security Incident Response Team is now carrying out remediation and recovery work after investigating devices belonging to its Secure Email Cloud service and directly contacting customers whose appliances showed indicators of possible compromise.