Back to News
Vulnerabilities

Cisco Secure Email Gateway Flaw Exploited, Enables Root Command Execution

Cyber RTSeptember 15, 20263 min read
Cisco Secure Email Gateway Flaw Exploited, Enables Root Command Execution

Cisco has identified a critical vulnerability, CVE-2026-76461, in AsyncOS Software for Cisco Secure Email Gateway, actively exploited in the wild. With a CVSS score of 9.8, it allows remote attackers to execute commands with root privileges via crafted emails. Affected versions have fixes available, and no workarounds exist. CISA has added it to its Known Exploited Vulnerabilities catalog, urging updates by September 2026.

Cisco has issued a warning about a critical vulnerability in its AsyncOS Software for Cisco Secure Email Gateway, which is actively being exploited. The vulnerability, identified as CVE-2026-76461, has a high severity CVSS score of 9.8 out of 10. It is due to insufficient validation in the email parsing logic, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges on the operating system. The exploit involves sending a crafted email with malicious SQL statements through an affected device, potentially allowing attackers to execute arbitrary SQL commands. This vulnerability affects both physical and virtual Cisco Secure Email Gateways, irrespective of their configuration. However, other Cisco products like Secure Email and Web Manager and Secure Web Appliance are not affected. Cisco has released fixes for several versions of the affected software. Users of Cisco AsyncOS for Cisco Secure Email Gateway Software Release 15.5 and earlier should update to version 15.5.5-0141, version 16.0 should be updated to 16.0.4-302, and version 16.5 should be updated to 16.5.0-780. There are no workarounds other than updating to these latest versions. To detect potential exploitation, Cisco advises reviewing mail logs for suspicious SQL statements and checking logs of each device in a cluster. Administrators are encouraged to use specific commands to identify malicious activity, as the presence of certain entries in the logs may indicate compromise. Cisco has contacted customers with Cisco Secure Email Cloud devices where malicious activity was detected, though the scale of the attacks has not been disclosed. The company warns that attackers might hide evidence of exploitation due to the high level of access gained through this vulnerability. Administrators are urged to examine network and firewall logs for unusual activity, such as unexpected data transfers to or from external IP addresses. This proactive monitoring is crucial since threat actors may attempt to conceal their tracks. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-76461 to its Known Exploited Vulnerabilities catalog, mandating that Federal Civilian Executive Branch agencies apply the necessary patches by September 17, 2026, to mitigate the risk. This disclosure follows a report by Arctic Wolf about large-scale credential attacks on Fortinet VPN appliances, highlighting a broader trend of targeted cyberattacks. These attacks utilized organization-specific credentials, suggesting access to previously gathered identity information. The incidents underscore the importance of vigilance and timely updates to safeguard against evolving threats.