Cisco Secure Email Gateway vulnerability (CVE-2026-76461) in active exploitation

Imported from official source

Cybersecurity Classified by Officially

On September 14, 2026, Cisco disclosed a vulnerability in Cisco Secure Email Gateway. CVE-2026-76461 is a critical (CVSS score of 9.8) SQL injection flaw in the email parsing functionality of Cisco AsyncOS Software. Successful exploitation “could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.” Cisco confirmed exploitation of the vulnerability in the wild, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added it to the Known Exploited Vulnerabilities (KEV) catalog.

Counter Threat Unit™ (CTU) researchers recommend that organizations identify vulnerable versions of Cisco AsyncOS for Cisco Secure Email Gateway in their environments and upgrade as appropriate. 

SophosLabs continues to monitor the threat landscape for activity related to this vulnerability and will deliver detections and protections as available.

Sophos Counter Threat Unit Research Team

This is an extract. The publication continues at the source.

Read the original at the source: https://www.sophos.com/en-gb/blog/cisco-secure-email-gateway-vulnerability-cve-2026-76461-in-active-exploitation

Officially imported this from Sophos’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Sophos — imported from official source
Official source
https://news.sophos.com/feed/ RSS
Imported
September 20, 2026 19:52
Versions
1 recorded
Identity
blt7a9a5a595fbc6c7e

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.