A single crafted email is enough to take root control of a Cisco Secure Email Gateway. Cisco disclosed CVE-2026-76461 on 14 September, an SQL injection flaw in the email parsing logic of AsyncOS rated 9.8 on CVSS v3.1 and confirmed it was already being exploited when the advisory went out. No credentials are needed, no user interaction, no particular configuration. The appliance only has to do what it was bought for and accept an incoming message.
CERT-SE issued its own advisory the next day, telling Swedish organisations to upgrade to a secure version as soon as possible and to examine their own systems. CISA added the flaw to its Known Exploited Vulnerabilities catalogue on the day Cisco published and ordered federal civilian agencies to remediate by 17 September. Three days, not the usual three weeks. That deadline says more about how CISA reads the exploitation than the CVSS score does.
Three Fixed Releases and No Way Around Them
Cisco lists three first fixed releases: 15.5.5-014 for the 15.5 train and earlier, 16.0.4-302 for 16.0 and 16.5.0-780 for 16.5. Customers on older trains are told to migrate to 16.5.0-780 rather than patch in place. There is no workaround. The vulnerability sits in the mail path rather than the management interface so restricting admin access, tightening the firewall in front of the appliance or disabling unused services changes nothing about the exposure. Cisco has already upgraded every Secure Email Cloud device to 16.5.0-780.
A Clean Log File Is Not a Clean Appliance
Cisco published indicators of compromise alongside the advisory, review mail_logs for suspicious SQL statements with a grep for COPY.*TO PROGRAM given as a non-exhaustive example and repeat the check on every device in a cluster. The company then undercuts its own detection guidance, correctly. Root access lets an attacker remove or hide the evidence so Cisco tells administrators to cross-check the network and firewall logs held outside the appliance for unexpected uploads to external addresses or downloads from malicious ones.
Version 1.1 of the advisory, published 17 September, adds the cluster problem. Appliances in a cluster authenticate to each other with SSH key pairs and those private keys sit on the box an attacker has just taken root on. Cisco’s instruction is to restore every member of a cluster that contains at least one compromised appliance, not only the one showing indicators.
For a virtual appliance where exploitation is suspected, Cisco’s recovery path is a rebuild, capture forensics first because deploying a new instance destroys the configuration and logs, then stand up a fresh VM on a fixed release, rebuild the configuration and renew every credential and cryptographic key held on the device. Physical appliances go to Cisco TAC with remote access enabled. On the cloud side, Cisco says it investigated its own fleet and contacted the customers whose devices showed indicators of possible compromise directly.
400 Exposed Appliances Is Not a Victim Count
The Shadowserver Foundation was tracking more than 400 internet-exposed Secure Email Gateway appliances on 14 September, a figure reported by Carly Page at The Register which also notes that nobody knows how many of those are honeypots or have since been patched. The number measures visibility, not compromise. Read it as neither a casualty list nor a reason to relax.
Cisco has not said who is behind the attacks, how long they have been running or how many organisations were hit, as The Register points out. That vacuum will be filled quickly and the first few attributions are worth ignoring. What is known about the origin of the bug is narrow and specific: Cisco found it while resolving a Technical Assistance Center support case. A customer ran into the consequences before anyone knew there was a vulnerability to look for.
The Second Exploited AsyncOS Flaw Inside a Year
BleepingComputer reported that Cisco patched CVE-2025-20393 in January, a maximum-severity AsyncOS flaw exploited against Secure Email Gateway and Secure Email and Web Manager appliances since November 2025. That one needed an internet-exposed Spam Quarantine to reach. CVE-2026-76461 needs the gateway to accept mail.
On the same day as the zero-day advisory, Cisco fixed four more critical flaws in the same product family: CVE-2026-76440, CVE-2026-76441, CVE-2026-20353 and CVE-2026-76443. Cisco said it had no evidence any of them had been exploited. CERT-SE then published a second advisory on 17 September covering further Cisco security updates released the day before, some of which it says are under active exploitation. Patching one appliance this week is the wrong scope.
A Compromised Gateway Starts a 24-Hour Clock
Luxembourg’s financial regulator moved faster than most. On 15 September the CSSF told supervised entities that unauthorised malicious access of this kind counts as a major ICT-related incident carrying a reporting obligation, under CSSF Circular 25/893 for entities in scope of DORA or Circular 24/847 for the rest.
Swedish organisations in scope of cybersäkerhetslagen (2025:1506), in force since 15 January 2026, face the same arithmetic by a different route: an early warning to the supervisory authority within 24 hours of becoming aware of a significant incident, a full notification within 72 hours and a final report within one month. The clock starts at awareness and awareness is exactly what a compromise assessment produces.
Confirm the AsyncOS release on every gateway and every node in every cluster. Retrieve the firewall and network logs covering the weeks before 14 September while retention still allows it, and run the analysis off the appliance rather than on it. If a gateway was reachable from the internet and unpatched last week, the upgrade answers what happens next, not what already happened.
References
- Kritisk Sårbarhet i Cisco Secure Email Gateway utnyttjas aktivt
- Cisco Secure Email Gateway SQL Injection Vulnerability
- CISA Adds One Known Exploited Vulnerability to Catalog
- Cisco Patches Secure Email Gateway Zero-day Exploited in Attacks
- Cisco Email Security Boxes Can be Rooted by… an Email
- Cisco Publicerar Säkerhetsuppdateringar för Flera Sårbarheter
- A Critical Vulnerability in Cisco is Causing Concern for the CSSF
This post is also available in:

