Cisco Secure Email Gateway Unauthenticated Root Command Execution via Email Parsing Zero-Day (CVE-2026-76461)
Scope: Cisco Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) — Virtual and Physical Appliances Running Cisco AsyncOS Software (All Configurations)
Severity: Red
Cisco confirmed in its Monday September 15, 2026 advisory that CVE-2026-76461 is under active exploitation, with CISA adding it to the Known Exploited Vulnerabilities catalog and ordering federal agencies to patch by September 17, 2026. The flaw exists in the email parsing logic of Cisco AsyncOS and allows an unauthenticated remote attacker to send a crafted email containing malicious SQL statements through any affected Cisco Secure Email Gateway to execute arbitrary commands with root privileges on the underlying operating system, requiring no credentials, no administrative access, and no user interaction. Cisco also addressed four companion critical vulnerabilities — CVE-2026-76440, CVE-2026-76441, CVE-2026-20353, and CVE-2026-76443 — affecting the same appliances, though the company said it has no evidence those four have been exploited in the wild. Organizations running Cisco Secure Email Gateway or Secure Email and Web Manager must apply the Cisco AsyncOS security update immediately via the Cisco Software Download Centre, review inbound email logs for crafted messages containing SQL-like patterns, and treat any appliance that was internet-facing before patching as potentially compromised.
The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.