Cisco email security boxes can be rooted by… an email
Criminals are actively exploiting a critical flaw in Cisco Secure Email Gateway appliances that allows a malicious email to grant an attacker root access, without any login required. Cisco has confirmed active exploitation and warns there is no workaround, meaning patching is the only defence, while attackers who gain root access could also tamper with logs to hide their tracks. This matters because the affected devices are meant to filter out malicious email, and any compromise could give attackers a foothold deep inside a victim's network.
The vulnerability, CVE-2026-76461, scores 9.8 out of 10 on the CVSS scale and affects both physical and virtual gateway appliances regardless of configuration. Cisco discovered the bug while investigating a support case and found some of its own cloud customers had been affected, prompting direct outreach and a full upgrade of its Secure Email Cloud service to AsyncOS 16.5.0-780. Fixes are available in AsyncOS 15.5.5-014, 16.0.4-302 and 16.5.0-780, but over 400 vulnerable appliances remain exposed online according to Shadowserver, and the flaw has been added to CISA's Known Exploited Vulnerabilities catalogue with US federal agencies ordered to patch by 17 September. It follows a similarly critical AsyncOS flaw exploited last year that eventually scored a perfect 10.
- Cisco Secure Email Gateway flaw lets attackers gain root via email
- No workaround exists; patching to fixed AsyncOS versions is required
- Over 400 vulnerable appliances still exposed online, CISA deadline 17 September