Particle.news

Critical Cisco Email‑Gateway Zero‑Day Lets Attackers Gain Root

Unauthenticated SQL in crafted emails can give attackers root control of Cisco Secure Email Gateway, creating risks to mail flow and internal networks.

Overview

  • Cisco warned Monday that CVE-2026-76461 is being actively exploited to run arbitrary commands as root by sending specially crafted email messages with malicious SQL.
  • Cisco published fixed AsyncOS builds for affected releases (15.5.5-0141, 16.0.4-302, 16.5.0-780) and said there are no effective workarounds, urging immediate upgrades.
  • The U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog and ordered federal civilian agencies to remediate by September 17, 2026.
  • Cisco released indicators of compromise and hunting guidance but warned that attackers with root access can delete local evidence, so defenders must check mail_logs for SQL patterns and correlate external network and firewall logs.
  • The incident fits a wider pattern of threat actors targeting perimeter appliances and raises risks of email eavesdropping, credential theft and lateral movement, so teams should assume compromise may require rebuilding devices and rotating credentials and keys.