Cisco Secure Email Gateway Vulnerability: Patch Now

A critical Cisco Secure Email Gateway vulnerability lets one crafted email grant root access, no login needed. Active exploitation confirmed.

A critical Cisco Secure Email Gateway vulnerability, CVE-2026-76461 (CVSS 9.8), lets an attacker gain root access to the appliance by sending a single crafted email, no login or admin access required. Cisco confirmed active exploitation and published its advisory September 14; CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day, and BSI issued its own Kritikalität 3 (Sehr hoch) warning on September 15.

What Happened

Cisco’s AsyncOS software, which runs Secure Email Gateway appliances (physical, virtual, and the cloud-delivered Secure Email Cloud), does not sufficiently validate certain data while parsing inbound email messages. An attacker can embed SQL statements inside a crafted email; when the gateway parses that message as part of its normal, automatic operation, the injected statements trigger command execution with root privileges on the underlying host. Because email parsing happens automatically for every message a gateway receives, exploitation needs no authentication and no administrative interface access, only a message reaching the appliance.

The Cisco Secure Email Gateway vulnerability affects AsyncOS releases 15.5 and earlier, 16.0, and 16.5. Fixed releases are 15.5.5-014, 16.0.4-302, and 16.5.0-780; Cisco recommends the last of these since it and 15.5.5-014 also bundle hardening fixes for several additional critical issues in the same advisory cycle. CISA’s federal remediation deadline is September 17.

Why It Matters

Email gateways sit at the network perimeter specifically to inspect untrusted, internet-sourced content before it reaches users, which makes “an attacker only has to send an email” an unusually uncomfortable exploitation model for a security appliance. For DACH Mittelstand organizations, email gateways are near-universal infrastructure regardless of sector; a root-level compromise at this layer gives an attacker a foothold that sits upstream of essentially every inbound communication channel the organization has, including the phishing and malware filtering the appliance is supposed to provide.

What You Should Do Now

  1. Upgrade to AsyncOS 16.5.0-780 (Cisco’s preferred fixed release), or 16.0.4-302 / 15.5.5-014 if 16.5 is not yet an option, today.
  2. Confirm your current AsyncOS version across every Secure Email Gateway appliance, physical and virtual, plus any Secure Email Cloud tenancy, since all are in scope.
  3. If immediate patching is not possible, review whether email flow can be temporarily routed through a secondary filtering layer while the upgrade is scheduled; there is no configuration workaround that closes this vulnerability on an unpatched appliance.
  4. Check appliance logs for signs of prior compromise before and after patching; a root-level flaw exploited before you patched will not be closed by patching alone if a backdoor was already planted.

DIESEC Perspective

Security appliances that automatically process untrusted external input, email gateways, web proxies, VPN concentrators, are a distinct risk category from general-purpose servers: they are designed to sit directly in the path of attacker-controlled data by definition. This is a pattern worth naming explicitly in a vendor-risk review rather than treating each appliance-layer CVE as an isolated event.

Not sure whether your email security layer has already been probed, or how quickly your team could apply this update across every affected appliance? Contact DIESEC for a rapid patch verification and exposure assessment.

Sources: The Hacker News | BleepingComputer
Published: 2026-09-17 | Category: Vulnerabilities & Patches | ~4 min read