Cyber Resilience
← All news

New critical CVE: CVE-2026-76461 — A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated…

Our takeCisco confirms active exploitation of CVE-2026-76461 in Secure Email Gateway (root command execution via crafted email). Patch immediately if you run it.
Sources (4)
What this means for you — Security leader:Cisco has confirmed active exploitation of CVE-2026-76461 (CVSS 9.8) in AsyncOS for Secure Email Gateway, allowing unauthenticated remote root command execution via crafted email. Apply the patch immediately and review Cisco's indicators of compromise for signs of prior compromise.
What this means for you — Lean IT orgs:If you run a Cisco Secure Email Gateway appliance yourself, install Cisco's patch for this actively exploited critical flaw right away. Most smaller teams use cloud email services instead and can ignore this one.
What this means for you — MSP:Check every client running on-premises Cisco Secure Email Gateway and ensure the CVE-2026-76461 patch is applied; Cisco has published IoCs for compromise hunting on exploited appliances.
What this means for you — Researcher:Cisco confirmed in-the-wild exploitation of CVE-2026-76461, a critical SQL injection in AsyncOS email parsing that yields unauthenticated root command execution. Review the advisory and IoCs.