THE ESSENTIALS
  • Active exploitation reported by Cisco.

What changed

Cisco disclosed CVE-2026-76461, a SQL injection vulnerability in Secure Email Gateway, and said it was being actively exploited. A crafted email can lead to commands running with root privileges without authentication. Cisco lists fixes in AsyncOS 15.5.5-014, 16.0.4-302 and 16.5.0-780, with no workaround.

Why it matters

An email processing flaw creates an exposure that administrators cannot assess solely by checking management access. Cisco's investigation guidance also distinguishes patching from recovery: suspected compromise may require rebuilding a virtual appliance and renewing credentials after preserving evidence.

What remains unproven

The advisory does not quantify affected customers or attribute the attacks. Cisco warns that attackers with root access can hide evidence, so clean local logs cannot establish that a device escaped compromise.

THE EVIDENCE RECORD

Read beyond this page.

Recorded source-check date: 15 Sep 2026. A link is not, by itself, evidence that every claim has been independently verified.

  1. Cisco ↗
Changes & version history

Version 3 · 15 Sep 2026
Scheduled release of checksum-bound AI-assisted editorial review

Version 2 · 15 Sep 2026
Checksum-bound editorial review scheduled for release

Version 1 · 15 Sep 2026
Source-linked private review edition

Request a correction ↗