Cisco Patches a 9.8-Rated Bug Already Under Attack
Security / news
Cisco Patches a 9.8-Rated Bug Already Under Attack
The Secure Email Gateway flaw needs no credentials and has no workaround, and Cisco says its own support team found it while investigating a live intrusion.

Attackers are actively exploiting a flaw in Cisco's Secure Email Gateway that needs no credentials and no user interaction to reach root access on the underlying operating system, Cisco said in an advisory published Sept. 14. There is no workaround.
The vulnerability, CVE-2026-76461, scores 9.8 out of 10 on the CVSS 3.1 scale. It sits in how Cisco's AsyncOS software parses inbound email: insufficient validation lets an attacker embed SQL statements inside a crafted message, and once the appliance processes it, those statements execute unchecked and escalate into command execution as root. Cisco said its Product Security Incident Response Team learned of the flaw when its Technical Assistance Center was investigating an internal support case that turned out to involve a live intrusion, not through an outside researcher's report, and that the exploitation it has observed reaches both physical and virtual Secure Email Gateway appliances as well as instances running in Cisco's own Secure Email Cloud.
Which AsyncOS builds are exposed
The flaw affects every supported release branch, physical and virtual appliances alike.
| AsyncOS branch | Vulnerable versions | Fixed version |
|---|---|---|
| 15.5 and earlier | Earlier than 15.5.5-0141 | 15.5.5-0141 |
| 16.0 | Earlier than 16.0.4-3021 | 16.0.4-3021 |
| 16.5 | Earlier than 16.5.0-780 | 16.5.0-780 (Cisco's recommended target) |
The score is not inflated: the bug requires no authentication, no user interaction and no complex staging, and it hands an attacker root on a system that, by design, sits in the path of every inbound message an organization receives. Those are the same characteristics that made the Citrix NetScaler login bypass this site covered earlier in September a priority patch rather than a routine one.
CISA's deadline and what is still unknown
CISA added the flaw to its Known Exploited Vulnerabilities catalog on Sept. 14 and set a remediation due date of Sept. 17 for federal civilian agencies under Binding Operational Directive 26-04, a three-day window that reflects how the flaw is already being used rather than merely theoretical. Cisco has not said how many organizations were compromised before the patch shipped, who is behind the intrusions its support team found, or how long the flaw existed before this month's exploitation began. The company's advisory lists no interim mitigation beyond upgrading immediately, a contrast with some of the KEV catalog entries this site has covered, where a firewall rule or config change bought defenders time before a patch was available.
Organizations running Secure Email Gateway on 15.5 or earlier, 16.0 or 16.5 should move to the fixed builds Cisco lists in the advisory; the company recommends migrating to 16.5.0-780 specifically rather than staying on a patched 15.5 or 16.0 branch. Cisco has not set a date for when it will publish a follow-up on the scope of the intrusions its own investigation uncovered.
The advisory is the only fix available: Cisco's own text states plainly that there are no workarounds that address the vulnerability, which puts the full burden on patching rather than on firewall rules or configuration changes an administrator could apply while waiting. For a gateway appliance that every inbound email passes through by design, that leaves a narrow window between Sept. 14 and whenever an organization completes the upgrade in which the exposure Cisco described is unchanged.
Sources
More in Security
- 01Cisco and Acronis Share a CISA Deadline, Not a Severity ScoreOne flaw needs no password and no user interaction, the other needs an attacker already logged in, and CISA gave federal agencies the same three days to fix both.
- 02Bransys ELD App Shipped With Hardcoded Login CredentialsCISA disclosed three flaws Sept. 17 in the trucking compliance app, including a hardcoded password a researcher says exposed live location and engine data from every connected truck on a subset of fleets.
- 03MikroTik Patches RouterOS Flaws Attackers Exploited FirstPoland's national CERT says attackers began exploiting the chained flaws on Sept. 2, a day before MikroTik shipped a fix, and more than 122,500 routers were still reachable a week later.
- 04Attackers Exploit a JFrog Artifactory Bug in Four DayswatchTowr says attackers began minting administrator tokens by abusing a default empty join key, CVE-2026-82329, within days of JFrog's own patch shipping.