Cisco Patches Critical Email Gateway Flaw Enabling Root Access via Single Email
Cisco has confirmed active exploitation of CVE-2026-76461, a CVSS 9.8-rated SQL injection vulnerability in the AsyncOS email parsing logic of its Secure Email Gateway appliances. The flaw requires no authentication and can be triggered by a single crafted email, allowing remote attackers to execute commands as root on affected devices. Both physical and virtual appliances running AsyncOS 15.5 and earlier are affected, with fixed versions available across the 15.5, 16.0, and 16.5 release lines. Cisco disclosed the vulnerability on September 15, 2026, and CISA added it to its Known Exploited Vulnerabilities catalog, setting a federal patch deadline of September 17, 2026. No workaround exists, and administrators are advised to upgrade immediately while treating gateway logs as potentially compromised, cross-referencing firewall and network records for signs of intrusion.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in