Critical Cisco Email Gateway Flaw Under Active Attack: Patch Now
Cisco has warned that a critical vulnerability in its Secure Email Gateway software (AsyncOS) is being actively exploited by attackers. Tracked as CVE-2026-76461 and rated 9.8 out of 10 in severity, the flaw stems from insufficient validation in how the system parses incoming emails. An attacker can send a specially crafted email containing malicious SQL statements to an affected device, potentially gaining the ability to run arbitrary commands with full root privileges on the underlying system, no login credentials required.
The issue affects both physical and virtual versions of Cisco Secure Email Gateway regardless of configuration, though other Cisco products like Secure Web Appliance are not impacted. Cisco has released patched software versions and says there are no effective workarounds besides updating. Because successful exploitation grants attackers root-level access, Cisco warns that attackers may be able to erase or hide evidence of their activity on the compromised device itself, meaning organisations should also review external network and firewall logs for signs of unusual data uploads or connections to suspicious IP addresses.
Cisco confirmed it has directly contacted customers whose Secure Email Cloud devices showed signs of malicious activity, though it has not disclosed how widespread the attacks are. The vulnerability has been added to the US Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog, requiring US federal agencies to patch by September 17, 2026, a strong signal of how seriously security agencies are treating this threat.