Cisco Email Gateway Zero-Day Exploited for Root Access
Want more insights like this?
Cisco is warning of a zero-day in its Secure Email Gateway appliances, CVE-2026-76461, rated CVSS 9.8 (Critical) and under active exploitation. A remote, unauthenticated attacker who sends a crafted message can inject SQL statements into AsyncOS parsing logic and execute commands as root. Physical and virtual appliances are affected in any configuration.
Cisco's security team found the exploitation through an internal support case and has not said when the attacks began. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 14 and gave federal agencies until September 17 to patch. Secure Email and Web Manager and Secure Web Appliance are not affected.
No workarounds exist. Update to AsyncOS 16.5.0-780 on the 16.5 branch, 16.0.4-302 on 16.0, or 15.5.5-0141 on 15.5 and earlier. Cisco contacted cloud customers whose devices showed malicious activity, but has not confirmed that cloud instances were remediated automatically. On-premises admins must apply the update themselves.
Source: Cybersecurity News