Cisco Secure Email Gateway flaw rated 9.8 lets attackers run commands as root

September 17, 2026
1 min read
Wide-angle photograph of the Cisco Systems corporate headquarters campus and glass exterior office complex in San Jose, California.
Cisco Systems headquarters in San Jose, California, where engineers issue security patches for AsyncOS appliances. Routine email traffic can mask exploit payloads, forcing IT security administrators to weigh immediate patching against exposure to unauthenticated root execution. [Photo: Wikimedia Commons / Prayitno / CC BY 2.0]

If your organisation runs Cisco Secure Email Gateway, there is a patching decision to make now, not later. Cisco has confirmed a critical vulnerability that lets an unauthenticated attacker execute commands with root-level access — and says there is no workaround.

CVE-2026-76461 is a SQL injection flaw in the AsyncOS email-parsing function of Cisco Secure Email Gateway. Cisco classifies the vulnerability as Critical and assigns it a CVSS base score of 9.8. The attack path does not require credentials: an attacker can reach root-level command execution by sending a malicious email to an affected system.

Cisco's advisory confirms active exploitation in the wild. It provides fixed software and says customers should move to patched versions immediately. Cisco says no workaround is available and directs customers to fixed software.

What IT administrators need to do

Organisations running Cisco Secure Email Gateway should identify affected versions through Cisco's advisory and apply the available software fix. Given the email-based attack vector, security practitioners should not treat perimeter filtering as a substitute for applying Cisco's fixed software.

The Cisco advisory makes clear that this is an email-parsing issue, not a configuration problem. Affected Secure Email Gateway installations that process incoming email may be exposed, depending on the affected software version. Cisco's advisory identifies affected software and fixed releases.

Separate from CVE-2026-76461, Cisco issued a September 2026 hardening release for Identity Services Engine covering a different set of vulnerabilities, including authentication bypass and remote code execution. Administrators managing both products should treat these as separate patching exercises. The ISE vulnerabilities have their own CVEs and their own fixed-software requirements. Combining the two into a single remediation plan risks missing specific version requirements for each product.

The most important distinction for administrators is that CVE-2026-76461 affects Cisco Secure Email Gateway only. The ISE advisory does not apply to that product, and the email gateway advisory does not apply to ISE.

What is CVE-2026-76461?

CVE-2026-76461 is a critical SQL injection vulnerability in Cisco Secure Email Gateway's AsyncOS email-parsing functionality. Cisco assigns it a CVSS score of 9.8. An unauthenticated remote attacker can execute arbitrary commands with root privileges by sending a specially crafted email. Cisco states there is no workaround and directs customers to fixed software versions listed in the security advisory.

Cisco's security advisories are available directly through its security advisory portal. Organisations with active support contracts should consult their Cisco account team if they need assistance identifying their software version or planning the upgrade.

Rahul Somvanshi

Rahul, possessing a profound background in the creative industry, illuminates the unspoken, often confronting revelations and unpleasant subjects, navigating their complexities with a discerning eye. He perpetually questions, explores, and unveils the multifaceted impacts of change and transformation in our global landscape. As an experienced filmmaker and writer, he intricately delves into the realms of sustainability, design, flora and fauna, health, science and technology, mobility, and space, ceaselessly investigating the practical applications and transformative potentials of burgeoning developments.

Leave a Reply

Your email address will not be published.

Exterior view of the Great Hall of the People on Tiananmen Square in Beijing under an open sky, symbolizing international state negotiations.
Previous Story

US-China AI race faces a new test as experts push safeguards for military AI risks

Mount Majura solar farm, representing Australia's renewable energy infrastructure behind the ARENA $30 million grant program.
Next Story

Australia’s ARENA launches $30 million clean energy startup fund

Latest from Technology

Don't Miss

Prince Harry during a visit to Arlington National Cemetery, where he has faced security concerns affecting his children's school life.

Prince Harry’s Children Change School After Two Days Over Security Route Concerns

Prince Harry and Meghan’s children, Archie and Lilibet,