- Active exploitation reported by Cisco.
What changed
Cisco disclosed CVE-2026-76461, a SQL injection vulnerability in Secure Email Gateway, and said it was being actively exploited. A crafted email can lead to commands running with root privileges without authentication. Cisco lists fixes in AsyncOS 15.5.5-014, 16.0.4-302 and 16.5.0-780, with no workaround.
Why it matters
An email processing flaw creates an exposure that administrators cannot assess solely by checking management access. Cisco's investigation guidance also distinguishes patching from recovery: suspected compromise may require rebuilding a virtual appliance and renewing credentials after preserving evidence.
What remains unproven
The advisory does not quantify affected customers or attribute the attacks. Cisco warns that attackers with root access can hide evidence, so clean local logs cannot establish that a device escaped compromise.
Read beyond this page.
Recorded source-check date: 15 Sep 2026. A link is not, by itself, evidence that every claim has been independently verified.
Changes & version history
Version 3 · 15 Sep 2026
Scheduled release of checksum-bound AI-assisted editorial review
Version 2 · 15 Sep 2026
Checksum-bound editorial review scheduled for release
Version 1 · 15 Sep 2026
Source-linked private review edition
