Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
- ID
- 24567
- Status
- summarized
- Published
- 15 Sep 2026, 2:11 PM
- Fetched
- 15 Sep 2026, 3:13 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/cisco-secure-email-gateway-flaw.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.0
- Created
- 15 Sep 2026, 3:13 PM
- Tags
- Audience
- developerssaas_founders
What happened
Cisco disclosed active in-the-wild exploitation of CVE-2026-76461 (CVSS 9.8) in AsyncOS for Cisco Secure Email Gateway, where unauthenticated attackers can send crafted emails containing malicious SQL statements to achieve root-level command execution. Fixes are available in AsyncOS 15.5.5-0141, 16.0.4-302, and 16.5.0-780, with no workarounds. Cisco shared IoCs including grepping mail_logs for 'COPY.*TO PROGRAM' patterns.
Why it matters
If your organization runs Cisco Secure Email Gateway on an unfixed AsyncOS version, patch immediately—there is no workaround and exploitation leaves no reliable trace since root-level attackers can wipe logs. For everyone else not running this appliance, no action is needed; this is enterprise email infrastructure, not developer or AI tooling.
Discussion angle
Brief mention only: confirm nobody on the team manages Cisco Secure Email Gateway, then move on—this is a niche enterprise infra CVE with no direct relevance to AI/ML, agent, or SaaS builders.