Cisco has disclosed a critical flaw in Secure Email Gateway, the appliance many organisations use to filter and scan inbound mail before it reaches staff inboxes. Tracked as CVE-2026-76461 and rated 9.8 out of 10, the bug lets an attacker take over the device without ever logging in — they just need to send it an email.
The problem sits in how AsyncOS, the software that runs both the physical and virtual versions of Secure Email Gateway, parses incoming messages. A specially crafted email containing malicious SQL statements can slip past that parsing logic and get executed as operating-system commands with full root privileges on the appliance itself. Cisco's product security team says it has already seen this exploited in the wild and has directly contacted cloud customers where it detected suspicious activity on their gateways. The U.S. Cybersecurity and Infrastructure Security Agency has added the flaw to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch by 17 September — a sign of how seriously it's being treated.
Cisco has released fixed AsyncOS versions and is urging an immediate update rather than any interim workaround, since the flaw is triggered by the mail-scanning process itself rather than a login screen that could simply be locked down.
What this means for your business
If your company or your IT provider runs a Cisco Secure Email Gateway appliance — on-premises or the cloud-hosted version, and regardless of whether it was previously sold under the IronPort name — get it onto a patched AsyncOS release this week; Cisco lists the fixed versions in its advisory. Because a successful attack grants root on the box, don't rely solely on logs stored on the appliance to check whether you were hit: Cisco's own guidance notes attackers can erase their tracks locally, so also review your external firewall and network logs for connections out of the gateway that you can't explain. If you don't manage your own email security, ask your provider directly whether they run this specific Cisco product and whether the patch is already applied — a mail-filtering appliance is exactly the kind of infrastructure that quietly sits unpatched because nobody logs into it day to day.