Overview
- Cisco warned Monday that a critical AsyncOS parsing flaw, tracked as CVE-2026-76461 with a 9.8 CVSS score, is being actively exploited to run arbitrary SQL and obtain root command execution on Secure Email Gateway appliances.
- The bug affects both physical and virtual SEG appliances regardless of configuration and can be triggered by a specially crafted email that delivers malicious SQL statements to the device's mail parser.
- Cisco published fixes for AsyncOS releases 15.5, 16.0 and 16.5 and said there are no practical workarounds, so administrators must apply vendor updates immediately.
- The company released indicators of compromise and log-search steps (for example, searching mail_logs for suspicious SQL like COPY.*TO PROGRAM) but warned that attackers with root can remove local traces, so teams should also check external network and firewall logs.
- CISA added CVE-2026-76461 to its Known Exploited Vulnerabilities list and ordered federal agencies to patch by September 17, and internet scanners such as Shadowserver currently track over 400 exposed SEG appliances though the true scale of compromise remains unknown.