Cisco has warned that attackers are actively exploiting a critical vulnerability in AsyncOS, the software used by its Secure Email Gateway appliances. The company learned of the activity in September while handling a Technical Assistance Center support case.
The flaw, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of 10. An unauthenticated attacker can send malformed email-processing input and execute commands with root privileges, as first reported by The Register.
Every appliance configuration requires a software fix
Cisco said the issue affects physical and virtual Secure Email Gateway appliances regardless of configuration. There is no workaround. Customers need to install a fixed AsyncOS release: 15.5.5-014, 16.0.4-302, or 16.5.0-780.
Cisco has already upgraded its Secure Email Cloud devices to AsyncOS 16.5.0-780. The company said some cloud devices showed possible indicators of compromise and that it contacted affected customers.
The exposure matters because these appliances sit in the path of incoming email, a core security boundary for an organization. Root access gives an intruder control over the device that processes that traffic, and Cisco warned that attackers could alter local logs. Security teams investigating suspected breaches may therefore need network and firewall records to establish what happened.
CISA has listed the flaw as actively exploited
The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-76461 to its Known Exploited Vulnerabilities catalog. The Shadowserver Foundation counted more than 400 internet-exposed Secure Email Gateway appliances as of Monday, giving defenders a visible population to identify and patch.
For virtual appliances that may have been compromised, Cisco recommends preserving evidence, deploying a new virtual machine running a fixed release, rebuilding its configuration, and rotating credentials and cryptographic material. Rebuilding instead of trusting an existing system reflects the level of access the defect can provide.
Cisco has not disclosed who is behind the attacks, how long the campaign has operated, or how many organizations were compromised. The company also has not publicly confirmed the number of affected Secure Email Cloud customers, released the complete exploitation method, or detailed the full scope of attacker activity.
This article was produced with AI assistance from multi-source reporting and is published under our editorial standards.