Exploited in the wild Cisco Secure Email Gateway zero-day Cisco Secure Email Cloud Cisco rce
Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)
CVE Tools coverage
Cisco has released fixes for CVE-2026-76461, an actively exploited SQL injection flaw affecting Cisco Secure Email Gateway appliances running Cisco AsyncOS Software versions 16.5, 16.0, and 15.5 and earlier. A remote, unauthenticated attacker can send a crafted email to execute SQL commands and potentially gain root-level command execution without user interaction; Cisco Secure Email Cloud was also affected, and its devices have been upgraded to Release 16.5.0-780. Administrators should update to 15.5.5-014, 16.0.4-302, or preferably 16.5.0-780, then review device, network, and firewall logs because attackers may remove evidence of compromise.