Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)
Reported exploitedCisco Secure Email GatewayCisco Secure Email CloudOur summary
Cisco has released fixes for CVE-2026-76461, an actively exploited SQL injection flaw affecting Cisco Secure Email Gateway appliances running Cisco AsyncOS Software versions 16.5, 16.0, and 15.5 and earlier. A remote, unauthenticated attacker can send a crafted email to execute SQL commands and potentially gain root-level command execution without user interaction; Cisco Secure Email Cloud was also affected, and its devices have been upgraded to Release 16.5.0-780. Administrators should update to 15.5.5-014, 16.0.4-302, or preferably 16.5.0-780, then review device, network, and firewall logs because attackers may remove evidence of compromise.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.