Cisco urges patches for exploited Secure Email Gateway flaw

Actively exploited flaw affects Cisco email gateways
Cisco has disclosed active exploitation of CVE-2026-76461, a critical vulnerability in AsyncOS Software for Cisco Secure Email Gateway. The flaw has a CVSS score of 9.8 and can allow an unauthenticated remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
The issue is an insufficient-validation weakness in email parsing logic. Cisco said an attacker can send a crafted email message containing malicious SQL statements through an affected device. Successful exploitation permits arbitrary SQL statements and can ultimately result in root-level command execution.
Both physical and virtual Cisco Secure Email Gateway appliances are affected regardless of their configuration. Cisco Secure Email and Web Manager and Secure Web Appliance are not affected. The scope and severity make prompt review important for organisations using the gateway as part of their inbound email security controls.
Fixed AsyncOS releases and detection guidance
Cisco has released fixes for AsyncOS release 15.5 and earlier in version 15.5.5-0141, release 16.0 in version 16.0.4-302, and release 16.5 in version 16.5.0-780. Cisco stated that there are no workarounds other than updating to the latest supported release.
Administrators should review mail_logs for suspicious SQL statements. For clustered deployments, Cisco recommends checking the logs on every cluster device. Its suggested detection command is grep -i "COPY.*TO PROGRAM" against the IronPort text mail logs; any matching entry may indicate malicious activity.
The urgency also reflects a wider pattern of Cisco-focused security exposure: Cisco vulnerability threat activity highlights how Cisco vulnerabilities have featured in recent threat activity, while this case involves a gateway flaw that is already under exploitation. CISA has added CVE-2026-76461 to its Known Exploited Vulnerabilities catalog and requires Federal Civilian Executive Branch agencies to apply patches by September 17, 2026.
Root access can complicate incident review
Cisco warned that attackers obtaining root command execution may remove or hide evidence of compromise. The company has directly contacted owners of Cisco Secure Email Cloud devices where malicious activity was detected, but it did not disclose the scale of the attacks.
Log inspection on the appliance alone may not be sufficient. Cisco recommends cross-checking network and firewall records held outside the affected device for anomalous traffic, including unexpected uploads from the gateway to external IP addresses or downloads from malicious addresses.
For security teams, the practical implication is to patch affected gateways without delay, review every relevant appliance and cluster log, and retain independent network evidence while investigating suspicious activity.

