Posting Date: 2026/09/17
【Vulnerability Alert】Cisco Secure Email Gateway Has a Critical Security Vulnerability (CVE-2026-76461)
- Subject:【Vulnerability Alert】Cisco Secure Email Gateway Has a Critical Security Vulnerability (CVE-2026-76461)
- Description:
- Forwarded from TWCERT/CC Security Advisory TWCERTCC-200-202609-00000017
- Cisco has issued a critical security advisory for its Secure Email Gateway (CVE-2026-76461, CVSS: 9.8). This vulnerability allows an unauthenticated remote attacker to execute arbitrary code with root privileges on the underlying operating system (RCE) by sending a specially crafted email containing malicious SQL commands. Note: Cisco has observed active exploitation of this vulnerability by attackers. It is recommended to promptly implement temporary mitigation measures to prevent potential attacks against this vulnerability.
- Affected Platforms:
- Cisco AsyncOS for Cisco Secure Email Gateway 15.5 and earlier
- Cisco AsyncOS for Cisco Secure Email Gateway version 16.0
- Cisco AsyncOS for Cisco Secure Email Gateway version 16.5
- Recommended Actions:
- Please update to the following versions: Cisco AsyncOS for Cisco Secure Email Gateway 15.5.5-014 and later, Cisco AsyncOS for Cisco Secure Email Gateway 16.0.4-302 and later, Cisco AsyncOS for Cisco Secure Email Gateway 16.5.0-780 and later
- References:
Computer and Communication Center
Network System Division