In plain language
What this advisory means
A serious security flaw exists in Cisco Secure Email Gateway devices that process emails. This flaw lets attackers send specially crafted emails containing harmful SQL commands, enabling them to take full control of the system with administrator privileges. Cisco has released software updates to fix this issue, but no other workarounds are available. Users should promptly apply these updates to protect their systems from potential attacks.
Technical explanation
How the issue affects the environment
Cisco Secure Email Gateway running AsyncOS software versions up to 15.5.x, 16.0.x, and 16.5.x suffer from an email parsing vulnerability due to insufficient input validation. Crafted email messages containing malicious SQL statements can exploit this flaw, allowing unauthenticated remote attackers to execute arbitrary SQL commands. Execution of these commands may escalate to arbitrary OS command execution with root privileges on the underlying system. The vulnerability is tracked as CVE-2026-76461 with a critical severity rating. Cisco has provided fixed AsyncOS releases (15.5.5-014, 16.0.4-302, and 16.5.0-780) to remediate this vulnerability. No workaround mitigations are known.
Operational impact
Why teams should care
If exploited, this vulnerability allows attackers to gain full root access on Cisco Secure Email Gateway devices. This could lead to unauthorized control over email traffic processing, data compromise, interruption of services, and possible further network infiltration. The severity of impact is critical, risking business data integrity and operational continuity. Immediate remediation is essential to maintain trust and compliance.
Immediate action
Administrators must upgrade affected Cisco Secure Email Gateway devices to one of the fixed AsyncOS software releases: 15.5.5-014, 16.0.4-302, or 16.5.0-780. The upgrade can be done via the web-based management interface or command-line interface following Cisco's documented procedures. Upgrading is required as no other workarounds exist to mitigate this vulnerability.
Affected and fixed releases
Temporary risk reduction
Cisco has stated that no workarounds are available for this vulnerability. The only effective remediation is to upgrade to the fixed software provided by Cisco.
Evidence and validation checklist
- Cisco official security advisory published 2026-09-14
- Cisco AsyncOS fixed releases 15.5.5-014, 16.0.4-302, 16.5.0-780
- Detected malicious SQL statements in device mail_logs indicating exploitation
- Direct Cisco customer notifications regarding detected malicious activity
- No workaround available; upgrade strongly recommended
Authoritative reference
Cisco PSIRT Advisories
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
