Threat Intelligence

Critical Cisco Email Gateway Flaw Under Active Attack: Patch Now

The Hacker News · 15 Sept 2026
Key Takeaway If your business uses Cisco Secure Email Gateway, patch immediately and check your network and firewall logs for unusual activity, since attackers exploiting this flaw can hide their tracks on the device itself.

Cisco has warned that a critical vulnerability in its Secure Email Gateway software (AsyncOS) is being actively exploited by attackers. Tracked as CVE-2026-76461 and rated 9.8 out of 10 in severity, the flaw stems from insufficient validation in how the system parses incoming emails. An attacker can send a specially crafted email containing malicious SQL statements to an affected device, potentially gaining the ability to run arbitrary commands with full root privileges on the underlying system, no login credentials required.

The issue affects both physical and virtual versions of Cisco Secure Email Gateway regardless of configuration, though other Cisco products like Secure Web Appliance are not impacted. Cisco has released patched software versions and says there are no effective workarounds besides updating. Because successful exploitation grants attackers root-level access, Cisco warns that attackers may be able to erase or hide evidence of their activity on the compromised device itself, meaning organisations should also review external network and firewall logs for signs of unusual data uploads or connections to suspicious IP addresses.

Cisco confirmed it has directly contacted customers whose Secure Email Cloud devices showed signs of malicious activity, though it has not disclosed how widespread the attacks are. The vulnerability has been added to the US Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog, requiring US federal agencies to patch by September 17, 2026, a strong signal of how seriously security agencies are treating this threat.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.