2026-09-15: Cybercriminals take over Cisco's email security appliance with a single email
Cisco released a fix on 14 September for a critical vulnerability in Secure Email Gateway that cybercriminals are already exploiting. CVE-2026-76461 (9.8 of 10 CVSS) lets a cybercriminal take full control of the appliance by sending it a single email, no password required.
Read Cisco's security advisory (external link).
How the vulnerability works
Secure Email Gateway sits at the edge of a company's network and inspects every message arriving from the internet, filtering out spam, phishing, and malware before staff ever see it.
The flaw lies in how the appliance reads incoming mail. As it parses a message, it passes parts of the content into a database query without properly checking them first, a weakness known as SQL injection. In plain terms, the appliance cannot tell the difference between the text of an email and instructions meant for its own database, so an attacker can write commands into a message and have the machine obey them.
From there the problem escalates. Cisco states that the injected database commands lead to execution of arbitrary operating system commands with root privileges, the highest level of access a system has.
Why this is dangerous
A cybercriminal needs no password, no existing foothold on the network, and no help from an employee. They don’t have to trick anyone into clicking anything. They only need to send an email to an address the gateway handles, which is precisely what the device is built to accept from anyone on the internet.
Success gives them complete control of a machine that sees all of an organisation's mail. That means reading messages in transit, stealing the credentials stored on the appliance, installing hidden software to keep access, and using the device as a launching point deeper into the corporate network.
Cisco's security team says it became aware of attacks using the flaw in September 2026 but has not published details of the campaigns or named those responsible.
Affected software
The vulnerability affects Cisco Secure Email Gateway in both its physical and virtual forms. Cisco stresses that devices are vulnerable regardless of how they are configured, so no setting protects an unpatched appliance.
Mitigation & next steps
Cisco has released fixes in AsyncOS releases 15.5.5-0141, 16.0.4-302 and 16.5.0-780, and strongly recommends moving to 16.5.0-780. The company reports it has already upgraded all of its Secure Email Cloud devices. There are no workarounds, so patching is the only remedy.
CISA added the flaw to its KEV Catalog on 14 September 2026 and gave federal agencies until 17 September to patch, an unusually short deadline that reflects how quickly it's being abused.
Holm Security’s response
Holm Security will be releasing a test to check for this vulnerability in the coming days:
- HID-2-1-5405825 - Cisco Secure Email Gateway AsyncOS < 15.5.5-014 / 16.0 < 16.0.4-302 / 16.5 < 16.5.0-780 SQL Injection Vulnerability (CVE-2026-76461) (September 2026)
Scan for specific vulnerabilities
Read how you can include or exclude a specific vulnerability in a scan profile here.