Particle.news

Cisco Secure Email Gateway Zero-Day Lets Attackers Run Root Commands as Company Issues Emergency Patch

CISA has ordered federal agencies to patch by September 17 to force rapid remediation of a flaw that can be triggered by crafted email-borne SQL.

Overview

  • Cisco disclosed Monday that CVE-2026-76461 is being actively exploited and stems from insufficient validation in AsyncOS email parsing that lets unauthenticated, remote SQL in an email trigger arbitrary command execution as root.
  • Cisco published fixed AsyncOS releases for 15.5, 16.0, and 16.5 (15.5.5-0141, 16.0.4-302, 16.5.0-780), supplied indicators of compromise and detection steps, and upgraded its Secure Email Cloud instances while contacting affected cloud customers.
  • The flaw affects physical, virtual, and cloud deployments of Cisco Secure Email Gateway regardless of configuration and has no effective workaround other than upgrading to the patched releases.
  • CISA added CVE-2026-76461 to its Known Exploited Vulnerabilities list and set a September 17 federal remediation deadline because attackers who gain root can delete logs and maintain persistent access to intercept email or pivot inside networks.
  • Researchers warn defenders to patch immediately, hunt for suspicious SQL entries in mail_logs and cross-check external network and firewall logs, and to rebuild or replace appliances and rotate credentials if compromise is detected.