Cisco released fixes on Sept. 14 for an actively exploited vulnerability in Secure Email Gateway that can let an unauthenticated remote attacker run commands with root privileges. The flaw, tracked as CVE-2026-76461, carries a 9.8 severity score and affects physical and virtual appliances regardless of configuration.

The company said insufficient validation in the product’s email-parsing logic lets a crafted message carry malicious SQL statements through an affected gateway. Successful exploitation can lead to command execution on the underlying operating system. Cisco has not identified the attackers or disclosed the number of affected organizations.

There is no workaround

Cisco said there is no workaround and urged customers to install a fixed release. The first repaired versions are AsyncOS 15.5.5-014, 16.0.4-302 and 16.5.0-780; Cisco recommends moving to 16.5.0-780. The company said it has already upgraded Secure Email Cloud devices and contacted customers whose cloud systems showed indicators of possible compromise.

Secure Email and Web Manager and Secure Web Appliance are not affected, according to the advisory. The U.S. Cybersecurity and Infrastructure Security Agency added the vulnerability to its Known Exploited Vulnerabilities catalog and set a Sept. 17 remediation deadline for federal civilian agencies, SecurityWeek and CyberScoop reported.

Security teams should treat patching as incident response

Cisco advised administrators to review mail logs for suspicious SQL statements and cross-check network and firewall logs outside the appliance. That second step matters because root access could allow an attacker to remove or hide evidence stored on the gateway itself.

For virtual appliances where exploitation is suspected, Cisco recommends preserving forensic information, deploying a new virtual machine on a fixed release, rebuilding the configuration, and renewing credentials and cryptographic material. Physical-appliance customers who suspect compromise should contact Cisco’s Technical Assistance Center.

Why it matters

Email gateways are designed to inspect hostile content before it reaches employees. In this case, the inspection layer itself can be compromised by a message without credentials or user interaction. That changes the executive risk calculation: a perimeter control can become a privileged foothold, and a clean patch alone may not establish that an organization was never breached.

Technology leaders should confirm who owns the affected appliance, which AsyncOS release is running, whether logs are preserved outside the device and whether compromise-response steps are ready. Cisco’s disclosure makes this an immediate operational issue, not a routine item for the next maintenance window.