Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

Ravie LakshmananSep 15, 2026Vulnerability / Network Security

Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild.

The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing logic that could allow an unauthenticated, remote attacker to run arbitrary commands with root privileges on the underlying operating system.

“An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device,” Cisco said in a Monday advisory. “A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.”

The shortcoming affects Cisco Secure Email Gateway, both physical and virtual, regardless of device configuration. However, the networking equipment maker said other products like Secure Email and Web Manager and Secure Web Appliance are not impacted.

Fixes are available for the following versions of Cisco AsyncOS for Cisco Secure Email Gateway Software Release –

  • 15.5 and earlier (Fixed in 15.5.5-0141)
  • 16.0 (Fixed in 16.0.4-302)
  • 16.5 (Fixed in 16.5.0-780)

There are no workarounds other than updating to the latest supported version. Cisco said it became aware of active exploitation of this vulnerability this month, sharing the following indicators of compromise (IoCs) –

  • Review mail_logs and look for suspicious SQL statements.
  • If the device is part of a cluster, review the logs of each cluster device.
  • To detect potentially malicious SQL statements, it’s advised to run the command: cisco-esa> grep -i “COPY.*TO PROGRAM” [IronPort Text Mail Logs Log name – Default: mail_logs]
  • The presence of any entry in the output may indicate malicious activity.

Cisco also said it has directly contacted customers who own Cisco Secure Email Cloud devices on which malicious activity was detected. It did not disclose the scale of the attacks.

“Upon successful exploitation of this vulnerability, threat actors may obtain command execution with root privileges,” the company warned. “Because of this level of access, evidence of exploitation and indicators of compromise may be removed or hidden by the threat actors.”

As a result, administrators are recommended to cross-check the network logs and the firewall logs outside of the impacted device to identify any potential anomalous activity, including unexpected uploads that were initiated from the affected device to external IP addresses or downloads from malicious IP addresses.

The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add CVE-2026-76461 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 17, 2026.

Large-Scale Credential Attacks Target Fortinet VPNs

The disclosure comes days after Arctic Wolf said it detected large-scale credential attacks targeting internet-facing Fortinet VPN appliances in late August 2026. The high-volume activity took place over two sustained waves across multiple U.S. customer environments from August 26 through August 28, 2026, generating tens of millions of authentication failures.

“The actor used organization-specific usernames, corporate email addresses, affiliate accounts, and common administrative identities, indicating access to previously collected or enumerated identity information,” security researcher Kyle Siddall said.

“The attempted usernames included employee names, corporate email addresses, affiliate identities, and common administrative accounts associated with the targeted organizations. This targeted identity selection, rather than generic username spraying, indicates access to previously collected or enumerated identity information.”

In one observed case, a successful Fortinet VPN authentication originating from the IP address “158.94.211[.]14” was followed by malicious activity in the affected environment.

Source link

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *