Skip to finding
§
High
Edge / Zero-click
Confirmed
CVE-2026-76461

One crafted email can give an unauthenticated attacker root command execution on Cisco Secure Email Gateway.

No management access or recipient action is required.

Affects

Cisco Secure Email Gateway, physical and virtual email-security appliances running AsyncOS.

What it enables

Unauthenticated root command execution through email delivery

Send an email containing crafted SQL through the target gateway.→↓The email parser passes the malicious statements into the appliance database.→↓Use database program execution to run operating-system commands.→↓Execute commands as root on the gateway and access appliance or cluster credentials.
Why this matters

The gateway processes the hostile object itself, and Cisco reports exploitation of the message-to-database-to-root path.

Detail and 4 sources
Required access

Ability to deliver a crafted email through an affected Secure Email Gateway; no management access or recipient action

Affected versions

AsyncOS 15.5 and earlier before 15.5.5-014, AsyncOS 16.0 before 16.0.4-302, AsyncOS 16.5 before 16.5.0-780, AsyncOS 15.5 releases before 15.5.5-014, AsyncOS 16.0 releases before 16.0.4-302, AsyncOS 16.5 releases before 16.5.0-780

Insufficient parser validation lets crafted SQL reach the appliance database; PostgreSQL program execution then reaches operating-system commands running as root.

Cisco reports exploitation and has published fixed AsyncOS releases. Pre-fix images remain accepted.

Evidence
Cisco advisory confirms crafted-email delivery, arbitrary SQL, root command execution, exploitation and fixesJPCERT/CC independently confirms that receipt by the gateway needs no recipient action and can execute commands as root
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 19, 2026