CISCO has confirmed active exploitation of a critical vulnerability in its Secure Email Gateway, tracked as CVE-2026-76461 and rated 9.8 (Critical) under CVSSv3. The flaw affects both physical and virtual appliances, regardless of configuration. It is caused by insufficient validation in AsyncOS email-parsing logic, allowing an unauthenticated attacker to send a specially crafted email containing malicious SQL statements.
Successful exploitation can result in command execution with root privileges on the underlying operating system, without user interaction. Cisco said it became aware of attacks in September 2026, while CISA has added the vulnerability to its Known Exploited Vulnerabilities catalogue.
Affected versions include 14.0.0-698, 13.5.1-277, 13.0.0-392, 14.2.0-620, 13.0.5-007 and 13.5.4-038, among others. Cisco says the issue does not affect Secure Web Appliance or Secure Email and Web Manager. It has been fixed in AsyncOS releases 15.5.5-014, 16.0.4-3021 and 16.5.0-780; the article’s table lists 16.0.4-302 as the first fixed release, so administrators should consult Cisco’s advisory when selecting an update. There is no workaround.
Administrators should upgrade promptly, review mail_logs for suspicious SQL statements, and compare them with external network and firewall logs because attackers with root access may alter local evidence.