A critical zero-day vulnerability in Cisco Secure Email Gateway has been actively exploited by attackers to execute commands with root privileges through crafted email messages. Cisco has patched the flaw and urges customers to upgrade to fixed versions.
Vulnerability Details
The vulnerability, tracked as CVE-2026-76461, has a CVSS score of 9.8 and affects Cisco AsyncOS software used by Secure Email Gateway appliances. An attacker does not need to log in before attempting exploitation. Cisco says the weakness exists in the way the product parses email and validates input.
Exploitation and Impact
Attackers can trigger the flaw by sending a specially crafted email containing malicious SQL statements through an affected device. Because the Secure Email Gateway automatically processes incoming email, the attack does not depend on an employee opening an attachment or clicking a link. Cisco says insufficient validation in the email parsing logic can allow the attacker to execute arbitrary SQL statements, which can then lead to command execution on the underlying operating system with root privileges.
Practical Response and Next Steps
Australian healthcare organisations and Melbourne businesses using Cisco Secure Email Gateway should upgrade to fixed versions, such as AsyncOS 15.5.5-014, 16.0.4-302, and 16.5.0-780, as soon as possible. They should also review logs and indicators around Secure Email Gateway systems for signs of unusual behaviour, especially unexpected administrative activity or command execution. Additionally, organisations should check firewall and network logs outside the device for any signs of suspicious activity, such as file uploads or downloads between the device and external IP addresses.
Talk to Podium IT
Need a clear next step?
Send a secure enquiry and tell us what you are planning. Please do not include passwords, patient information or other sensitive data.
General information only. It is not legal, privacy or compliance advice; requirements should be assessed for your organisation.
