Overview
- Cisco disclosed Monday that CVE-2026-76461 is being actively exploited and stems from insufficient validation in AsyncOS email parsing that lets unauthenticated, remote SQL in an email trigger arbitrary command execution as root.
- Cisco published fixed AsyncOS releases for 15.5, 16.0, and 16.5 (15.5.5-0141, 16.0.4-302, 16.5.0-780), supplied indicators of compromise and detection steps, and upgraded its Secure Email Cloud instances while contacting affected cloud customers.
- The flaw affects physical, virtual, and cloud deployments of Cisco Secure Email Gateway regardless of configuration and has no effective workaround other than upgrading to the patched releases.
- CISA added CVE-2026-76461 to its Known Exploited Vulnerabilities list and set a September 17 federal remediation deadline because attackers who gain root can delete logs and maintain persistent access to intercept email or pivot inside networks.
- Researchers warn defenders to patch immediately, hunt for suspicious SQL entries in mail_logs and cross-check external network and firewall logs, and to rebuild or replace appliances and rotate credentials if compromise is detected.