Cisco Patches Actively Exploited Email Gateway Zero-Day (CVE-2026-76461)
Cisco confirmed active exploitation of a zero-day SQL injection, CVE-2026-76461, in Cisco Secure Email Gateway on AsyncOS 16.5, 16.0, and 15.5 and earlier. An unauthenticated attacker can execute arbitrary SQL code via an email and gain root access to the OS. CISA added the flaw to its exploited catalog and requires US federal agencies to fix it by September 17.
- Flaw affects AsyncOS 16.5, 16.0, 15.5 and earlier versions
- Exploitation requires no user action and grants root access
- Fixes: 15.5.5-014, 16.0.4-302, 16.5.0-780
- CISA requires remediation by September 17, 2026
Read next
Security