Cisco Warns Email Gateways Are Being Hit by a Maximum-Severity Flaw
Published on 09/16/2026 at 01:20 | Editorial boerse-global.deCisco disclosed on 14 September 2026 that its Secure Email Gateway (SEG) is carrying a critical operating-system vulnerability, and the company says attackers are already using it in the wild.
Tracked as CVE-2026-76461, the flaw lets unauthenticated attackers reach the internet-facing gateway and walk away with full root control of the underlying system.
A mail-parsing bug that hands over the machine
Rated 9.8 on the CVSS scale, the defect sits in how AsyncOS processes incoming email. It is classified as an SQL injection (CWE-89): an attacker sends a crafted message containing malicious SQL statements to the gateway, and from there can run arbitrary commands with root privileges on the host operating system.
Every SEG configuration is exposed, Cisco says — physical appliances and virtual instances alike. The Secure Email Cloud is affected too. The company's Secure Email and Web Manager and its Secure Web Appliance do not carry this particular flaw.
No workaround, so patching is the only route
Because no manual workaround exists, according to a 15 September 2026 report, administrators have no choice but to install the fixes Cisco has published. The corrected AsyncOS builds are 15.5.5-014, 16.0.4-302 and 16.5.0-780.
Cisco has contacted Secure Email Cloud customers directly. For anyone checking whether a system was compromised earlier, the mail_logs files are the place to look. Technical analyses point to one concrete indicator of exploitation: the string 'COPY … TO PROGRAM' appearing in those logs.
Washington gives federal agencies three days
The active exploitation drew a response from CISA as well. On 14 September 2026 the agency added CVE-2026-76461 to its Known Exploited Vulnerabilities (KEV) catalog, which carries a binding instruction for US federal agencies to close the gap by 17 September 2026 at the latest.
Under directive BOD 26-04, affected agencies must also carry out a forensic examination of their systems. The flaw was abused as a zero-day, yet no reports so far link these attacks to ransomware deployment. Specialists nonetheless stress how serious the hole is: it can be triggered straight from the network, with no authentication required beforehand.
