THEMETASEC

Cybersecurity News, Aggregated

Critical Cisco Secure Email Gateway zero-day gives attackers root access

CSO Online · 1 hour ago Breach

Cisco released emergency patches for a critical vulnerability in its Secure Email Gateway appliance that could allow attackers to take over the device by simply sending malicious crafted emails to users. The flaw was already being exploited in the wild when the fixes were released. Tracked as CVE-2026-76461, the vulnerability is described by Cisco as an SQL injection caused by insufficient validation in the product’s email parsing code. Parsing incoming email messages for threats is this appliance’s main job, which means the attack vector is trivial. “An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device,” Cisco said in its advisory. “A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.” The flaw affects both the physical and virtual versions of the product and was fixed in the AsyncOS firmware releases 15.5.5-0141, 16.0.4-3021, and 16.5.0-780 released Monday. The Cisco product security team became aware of active exploitation of this vulnerability earlier this month, and the US Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities (KEV) catalog. Indicators of compromise might be missing Because the vulnerability has been exploited as a zero-day, just upgrading to the patched firmware version is not enough. Organizations should also try to determine whether their own appliances have been compromised. One way is to review the mail_logs for suspicious SQL statements. However, because successful exploitation gives attackers root access on the device, they could use this access to alter the logs and hide their tracks. Cisco advises organizations to also check any network and firewall logs outside the device for any signs of suspicious activity, such as file uploads or downloads between the device and external IP addresses. If exploitation is suspected on physical devices, Cisco recommends contacting the Cisco Technical Assistance Center. For virtual devices, customers are advised to save all forensic information then deploy a new instance with rebuilt configuration and rotated credentials. Devices that are enrolled in Cisco Secure Email Cloud have already been reviewed by Cisco and the owners of the devices that showed potential signs of compromise were contacted. The company’s advisory also includes general recommendations for device security hardening. “A root-level, unauthenticated RCE in an email gateway is about as good a foothold as an attacker gets,” Josh Picolet, vice president of detection and analysis at security firm Team Cymru, tells CSO. “This is only the second Secure Email Gateway flaw ever added to CISA’s KEV catalog, after CVE-2025-20393, and that repetition fits actors who treat edge appliances as durable, reusable access rather than one-off targets.”

Read full story at CSO Online →