Description:
Forwarded from TWCERT/CC Security Advisory TWCERTCC-200-202609-00000017
Cisco has issued a critical security advisory for its Secure Email Gateway (CVE-2026-76461, CVSS: 9.8). This vulnerability allows an unauthenticated remote attacker to execute arbitrary code with root privileges on the underlying operating system (RCE) by sending a specially crafted email containing malicious SQL commands. Note: Cisco has observed active exploitation of this vulnerability by attackers. It is recommended to promptly implement temporary mitigation measures to prevent potential attacks against this vulnerability.
Affected Platforms:
Cisco AsyncOS for Cisco Secure Email Gateway 15.5 and earlier
Cisco AsyncOS for Cisco Secure Email Gateway version 16.0
Cisco AsyncOS for Cisco Secure Email Gateway version 16.5
Recommended Actions:
Please update to the following versions: Cisco AsyncOS for Cisco Secure Email Gateway 15.5.5-014 and later, Cisco AsyncOS for Cisco Secure Email Gateway 16.0.4-302 and later, Cisco AsyncOS for Cisco Secure Email Gateway 16.5.0-780 and later
References:
-
Computer and Communication Center
Network System Division