Urgent.News

What's breaking now, across thousands of outlets.

Tech

Cisco email security boxes can be rooted by... an email

Attackers already exploiting the critical flaw, and Cisco warns they may be able to cover their tracks once they're in

Cisco email security boxes can be rooted by... an email

A critical flaw in Cisco Secure Email Gateway software, identified as CVE-2026-76461, allows attackers to gain root access through a malicious email. This vulnerability, rated with a staggering 9.8 CVSS score, is present in both physical and virtual Secure Email Gateway appliances, regardless of their configuration. Cisco has issued no workarounds, making patching the sole solution.

The bug is rooted in how Cisco's AsyncOS software processes incoming emails; an attacker doesn't need to log in to exploit it. Instead, they can send a malicious message through a vulnerable gateway, potentially executing commands as root. Cisco's Product Security Incident Response Team learned of active exploitation in September, though they have not disclosed the perpetrators, duration of attacks, or the number of compromised organizations.

Cisco discovered the flaw while addressing a Technical Assistance Center support case. Signs indicate that at least some cloud customers were affected. Cisco investigated its Secure Email Cloud service devices and contacted affected customers. All Secure Email Cloud devices have been upgraded to AsyncOS 16.5.0-780. However, administrators running their own appliances must perform additional remediation.

Cisco advises checking logs for suspicious activity but warns that a lack of warnings doesn't guarantee safety. Once root access is achieved, attackers can manipulate logs to conceal their presence. For virtual appliances suspected of compromise, Cisco recommends preserving forensic evidence, deploying a fresh VM with fixed software, rebuilding configurations, and rotating credentials and cryptographic material.

Cisco has patched the flaw in AsyncOS versions 15.5.5-014, 16.0.4-302, and 16.5.0-780, strongly recommending all customers update to the latter. The vulnerability remains widespread, with over 400 Cisco Secure Email Gateway appliances exposed to the internet as of the report. The flaw has also been included in the US Computer Security Incident Response Team's Known Exploited Vulnerabilities catalog, mandating remediation by September 17.

This latest security hole follows a critical AsyncOS flaw, CVE-2025-20393, exploited last year to infiltrate Cisco Secure Email Gateway appliances and establish persistence mechanisms. The takeaway for affected users is clear: a security box designed to protect against malicious emails can itself be compromised, with attackers already exploiting the vulnerability.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Tech

More from Tuesday 15 September →