Critical Cisco Email Gateway Flaw Exploited: Urgent Patches Required to Prevent Remote Command Execution

September 15, 2026
Critical Cisco Email Gateway Flaw Exploited: Urgent Patches Required to Prevent Remote Command Execution
  • Cisco has updated software to remediate the issue; temporary workarounds are ineffective; Secure Email and Web Manager and Secure Web Appliance are not affected.

  • The vulnerability affects both physical and virtual Secure Email Gateways regardless of configuration; other Cisco products like Secure Email and Web Manager and Secure Web Appliance are not affected.

  • As broader warning context, large-scale credential attacks against Fortinet VPNs around the same period illustrate widespread authentication targeting during this wave.

  • We’re facing a critical, actively exploited vulnerability in Cisco AsyncOS for Secure Email Gateway and Cloud—CVE-2026-76461 with a near-perfect CVSS score of 9.8, allowing unauthenticated remote command execution via crafted emails containing malicious SQL statements.

  • U.S. CISA added CVE-2026-76461 to the Known Exploited Vulnerabilities catalog on September 14, 2026, mandating federal agencies remediate by September 17, 2026.

  • Cisco has issued patches for the actively exploited zero-day, with exploitation observed since September 2025 across Secure Email Gateway appliances and Secure Email Cloud.

  • Post-upgrade actions include scanning logs for indicators of compromise, contacting Cisco TAC for physical devices, redeploying a fixed VM for virtual deployments, rebuilding configurations, rotating credentials, and monitoring for anomalies.

  • Affected versions include AsyncOS 16.5, 16.0, 15.5 and earlier, with remediation guidance extending to Cisco Cloud deployments as well.

  • The flaw affects both physical and virtual AsyncOS installations regardless of configuration, and there is no workaround beyond applying patches.

  • Cisco urges organizations to search for indicators of compromise to determine breach impact and to upgrade affected software immediately.

  • There are no workarounds; monitoring and log analysis are essential to confirm exploitation and track attacker activity.

  • Affected products include Cisco Secure Email Gateway hardware and virtual deployments, with no workaround currently available.

Summary based on 7 sources


Get a daily email with more Tech stories

More Stories