Summary
- CVE-2026-76461 affects Cisco Secure Email Gateway and carries a CVSS 3.1 base score of 9.8.
- A crafted email can exploit SQL injection in AsyncOS email parsing and ultimately allow root-level command execution.
- Cisco confirmed active exploitation in September and provides no workaround, leaving fixed software as the remediation path.
Cisco has patched a critical Secure Email Gateway vulnerability that is being actively exploited, with successful attacks capable of executing operating-system commands with root privileges without authentication.
CVE-2026-76461 affects email parsing in Cisco AsyncOS Software for Secure Email Gateway. Cisco assigned the vulnerability a CVSS 3.1 base score of 9.8 and says there is no workaround.
The flaw results from insufficient validation during email parsing. An attacker can send a specially crafted message through an affected appliance containing malicious SQL statements. Successful exploitation can progress from arbitrary SQL execution to commands running as root on the underlying operating system.
That attack path is particularly consequential because it uses the gateway’s normal purpose — processing incoming email. An attacker does not need credentials for the management interface or an authenticated session before attempting exploitation.
Cisco says its Product Security Incident Response Team became aware of active exploitation during September. The company has released fixed software and says customers should upgrade affected appliances.
Cisco has also identified indicators that administrators can check in mail logs. It warns, however, that an attacker obtaining root-level command execution may be able to remove or conceal evidence on the affected system, making external network and firewall telemetry important when investigating suspected compromise.
The company says Cisco Secure Email Cloud devices have already been upgraded. It has contacted customers whose cloud devices showed indicators of possible compromise and says remediation and recovery work is under way.
Email gateways occupy a sensitive position in enterprise infrastructure because they process untrusted external content before it reaches users while enforcing security policy on a high-volume communications channel. Root-level compromise of that layer can therefore undermine equipment intended to reduce exposure elsewhere.
The disclosure adds another exploited infrastructure vulnerability to Cisco’s recent security workload. Cisco also confirmed exploitation of separate Secure Firewall Management Center vulnerabilities earlier in September.
The vulnerabilities affect different products and should not be treated as one campaign. Their proximity nevertheless demonstrates the operational pressure created when security appliances themselves require urgent remediation. Email and network controls are often difficult to interrupt because maintenance can affect communications or other essential services.
Confirmed exploitation also changes the response compared with a vulnerability disclosed before attacks have been observed. Organisations running an affected release have to consider not only installation of fixed software but whether the appliance may already have been targeted.
For compromised virtual appliances, Cisco recommends preserving forensic information where possible, deploying a new virtual machine on fixed software, rebuilding the product configuration, and renewing credentials and cryptographic material installed on the device. Customers using affected physical appliances are directed towards Cisco support where compromise is suspected.
Cisco has not publicly attributed the exploitation to a particular threat actor or disclosed an overall victim count. Those points remain unknown. What is established is that CVE-2026-76461 is exploitable remotely without authentication, can lead to root-level command execution, and has already been used in attacks.





