Threat Intel
Cisco Secure Email Gateway & AsyncOS: Multi‑Vulnerability Alert – RCE, DoS, SQLi
A wave of security flaws has been uncovered across Cisco’s Secure Email Gateway, Secure Email and Web Manager, and AsyncOS platforms. Several of the bugs enable attackers to execute arbitrary code remotely, crash the system, and inject malicious SQL statements. Cisco’s CVE‑2026‑76461 is already being actively exploited. Immediate patching is mandatory for all affected versions, and network operators should verify that hardening guidelines are in place.
A recent alert from the French CSIRT highlights a collection of critical vulnerabilities in Cisco’s Secure Email Gateway (SEG), Secure Email and Web Manager (SEWM), and AsyncOS firmware. The flaws span several attack vectors: remote code execution (RCE), remote denial‑of‑service (DoS), cross‑site scripting (XSS), and SQL injection (SQLi). Cisco’s own advisory notes that CVE‑2026‑76461 is currently being exploited in the wild.
Impact
- Remote Code Execution: An attacker can run arbitrary commands on the affected device, potentially taking full control.
- Remote Denial of Service: Legitimate traffic can be disrupted, leading to service outages.
- SQL Injection: Sensitive data may be exfiltrated or the database corrupted.
- Cross‑Site Scripting: Compromise of web‑based management interfaces.
Affected Products & Versions
- AsyncOS for Secure Email Gateway – 16.0.x prior to 16.0.4‑3021
- AsyncOS for Secure Email Gateway – 16.5.x prior to 16.5.0‑780
- AsyncOS for Secure Email Gateway – any version prior to 15.5.5‑0141
- Secure Email and Web Manager – 16.x prior to 16.5.0‑429
- Secure Email and Web Manager – any version prior to 15.5.5‑006
- Secure Email Gateway – 16.x prior to 16.5.0‑780
- Secure Email Gateway – any version prior to 15.5.5‑014
CVE Highlights
- CVE‑2026‑76461 – actively exploited RCE
- CVE‑2026‑76440, ‑76441, ‑76442, ‑76443 – DoS and XSS issues
- CVE‑2026‑20353 – additional remote code execution vector
Mitigation
- Apply the latest Cisco security patches immediately. Refer to the Cisco Security Advisories released on 14 September 2026 for detailed fix information.
- Verify that hardening recommendations (e.g., disabling unused services, enforcing strong authentication) are in place.
- Conduct a rapid vulnerability scan of all SEG, SEWM, and AsyncOS devices to confirm patch status.
- Monitor logs for unusual authentication attempts, SQL queries, or service crashes.
Failure to remediate these vulnerabilities exposes organizations to potential data breaches, service interruptions, and complete takeover of email infrastructure. Prompt action is essential to safeguard mission‑critical communications.