Skip to Content

Cisco Secure Email Gateway vulnerability (CVE-2026-76461) in active exploitation

On September 14, 2026, Cisco disclosed a vulnerability in Cisco Secure Email Gateway. CVE-2026-76461 is a critical (CVSS score of 9.8) SQL injection flaw in the email parsing functionality of Cisco AsyncOS Software. Successful exploitation “could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.” Cisco confirmed exploitation of the vulnerability in the wild, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added it to the Known Exploited Vulnerabilities (KEV) catalog.

Recommended actions

Counter Threat Unit™ (CTU) researchers recommend that organizations identify vulnerable versions of Cisco AsyncOS for Cisco Secure Email Gateway in their environments and upgrade as appropriate. 

Sophos countermeasures

SophosLabs continues to monitor the threat landscape for activity related to this vulnerability and will deliver detections and protections as available.