Skip to main content
Emerging ThreatsMalware & Ransomware

Cisco Email Gateways Exploited by Malicious Emails

Rows of equipment racks and Cisco Secure Email Gateway appliances in a brightly-lit server room with daylight from tall…

CVE-2026-76461, scored 9.8 on the CVSS scale, can turn a single malicious email into root access on Cisco Secure Email Gateway appliances.

CVE-2026-76461 and the attack vector

The vulnerability lies in how Cisco's AsyncOS handles incoming email, and it affects both physical and virtual Secure Email Gateway appliances regardless of configuration. Cisco's Product Security Incident Response Team said an attacker does not need to authenticate: a specially crafted message sent through a vulnerable gateway can, if the exploit succeeds, run commands as root. Cisco warns there are no workarounds — patching is the only fix.

Cisco Secure Email Cloud remediation and patched releases

Cisco discovered the bug while resolving a Technical Assistance Center support case and said it became aware of active exploitation in September. The company investigated devices belonging to its Secure Email Cloud service, directly contacted customers whose appliances showed indicators of possible compromise, and is carrying out remediation and recovery work. Cisco reported that all of its Secure Email Cloud devices have been upgraded to AsyncOS 16.5.0-780.

Cisco has released fixes in AsyncOS versions 15.5.5-014, 16.0.4-302 and 16.5.0-780, and it is “strongly encourag[ing]” customers to move to 16.5.0-780.

Guidance for appliance administrators

Administrators running their own Secure Email Gateway appliances face a more hands‑on recovery. Cisco recommends checking gateway logs for signs of suspicious activity but warns that the absence of log entries is not a reliable clean bill of health — attackers with root access could tamper with or erase logs. As a result, Cisco tells administrators to check network and firewall logs for unusual activity rather than relying solely on the gateway's own records.

For virtual appliances suspected of being compromised, Cisco's recovery guidance is explicit and consequential: preserve forensic evidence; deploy a fresh virtual machine running the fixed AsyncOS; rebuild the configuration from scratch; and rotate credentials and cryptographic material.

What this means for security teams, Secure Email Cloud customers, and U.S. federal civilian agencies

  • Security teams and on‑prem administrators: review gateway, network and firewall logs; treat a lack of local log evidence with caution; plan rebuilds or fresh VMs for any virtual appliances suspected of compromise; and rotate keys and credentials according to Cisco's guidance.
  • Secure Email Cloud customers: Cisco says it has investigated its cloud devices and directly contacted customers whose appliances showed indicators of possible compromise; Cisco also reports that its managed cloud devices are now upgraded to 16.5.0-780.
  • U.S. federal civilian agencies: CISA has included CVE-2026-76461 in its Known Exploited Vulnerabilities catalog and ordered remediation by September 17, giving agencies a specific, near-term deadline to apply Cisco's fixes.

Exposure scale and precedent

The Shadowserver Foundation was tracking more than 400 Cisco Secure Email Gateway appliances exposed to the internet as of Monday, a nontrivial set of potential targets for attackers seeking to exploit this flaw. CVE-2026-76461 also arrives less than a year after attackers exploited another critical AsyncOS vulnerability, CVE-2025-20393, to break into Secure Email Gateway appliances and install persistence mechanisms; that earlier bug ultimately scored a perfect 10.

Cisco has not disclosed who is behind the active exploitation, how long the attacks have been underway, or how many organizations have been compromised — details the company said it has not released.

The practical takeaway is stark and specific: the device responsible for inspecting and blocking hostile email can itself be compromised by a crafted message, attackers are already exploiting that weakness, and there is no temporary workaround to rely on. For organizations running affected appliances the next steps are concrete — move to one of the fixed AsyncOS releases (Cisco is pushing 16.5.0-780), follow Cisco's recovery checklist for suspected compromises, and inspect network-level logs where gateway logs may have been altered.

Original story: Cisco email security boxes can be rooted by... an email — The Register