Posting Date: 2026/09/17

【Vulnerability Alert】Cisco Secure Email Gateway Has a Critical Security Vulnerability (CVE-2026-76461)

  • Subject:【Vulnerability Alert】Cisco Secure Email Gateway Has a Critical Security Vulnerability (CVE-2026-76461)


  • Description:
    • Forwarded from TWCERT/CC Security Advisory TWCERTCC-200-202609-00000017
    • Cisco has issued a critical security advisory for its Secure Email Gateway (CVE-2026-76461, CVSS: 9.8). This vulnerability allows an unauthenticated remote attacker to execute arbitrary code with root privileges on the underlying operating system (RCE) by sending a specially crafted email containing malicious SQL commands. Note: Cisco has observed active exploitation of this vulnerability by attackers. It is recommended to promptly implement temporary mitigation measures to prevent potential attacks against this vulnerability.
  • Affected Platforms:
    • Cisco AsyncOS for Cisco Secure Email Gateway 15.5 and earlier
    • Cisco AsyncOS for Cisco Secure Email Gateway version 16.0
    • Cisco AsyncOS for Cisco Secure Email Gateway version 16.5
  • Recommended Actions:
    • Please update to the following versions: Cisco AsyncOS for Cisco Secure Email Gateway 15.5.5-014 and later, Cisco AsyncOS for Cisco Secure Email Gateway 16.0.4-302 and later, Cisco AsyncOS for Cisco Secure Email Gateway 16.5.0-780 and later
  • References:

Computer and Communication Center
Network System Division