Cisco Warns of Actively Exploited Flaw in Secure Email Gateway Devices
Cisco has issued an urgent advisory after discovering attackers exploiting a previously unknown flaw in its Secure Email Gateway product, tracked as CVE-2026-76461 and rated 9.8 out of 10 in severity. The vulnerability affects both physical and virtual gateways, regardless of configuration, and requires no login or management access to exploit. Attackers can embed malicious SQL statements inside emails, taking advantage of insufficient validation in the gateway's message parsing logic to run commands with root privileges on the underlying system.
Cisco's security team learned of active exploitation in September after investigating a support case, and the flaw has since been added to the US Cybersecurity and Infrastructure Security Agency's known exploited vulnerabilities catalogue. Cisco's cloud-hosted Secure Email Cloud service was also affected; the company has contacted customers showing signs of compromise and upgraded all cloud instances to a fixed software version. However, cloud customers without command-line access may be unable to check for compromise themselves.
For on-premises appliances, Cisco has provided a specific log search term to help administrators detect exploitation attempts, related to a PostgreSQL command that can send database output to system programs, effectively turning a database attack into full system access. Because successful attackers gain root privileges, they may be able to erase evidence of their activity, so Cisco recommends also checking external firewall and network logs for unusual data transfers.