Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
Cisco has disclosed active in-the-wild exploitation of CVE-2026-76461, a critical vulnerability in AsyncOS Software for Cisco Secure Email Gateway that enables unauthenticated remote attackers to execute arbitrary commands with root privileges. With a CVSS score of 9.8, the flaw stems from insufficient validation in email parsing logic, allowing malicious SQL statements to be injected via crafted messages. Patches have been released for affected releases, including fixes in versions 15.5.5-0141, 16.0.4-302, and 16.5.0-780, and CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog. Administrators are urged to update immediately and review mail logs for signs of compromise, as threat actors may attempt to hide their tracks due to the elevated access gained.