Urgent.News

What's breaking now, across thousands of outlets.

Tech

Cisco email security boxes can be rooted by... an email

Attackers already exploiting the critical flaw, and Cisco warns they may be able to cover their tracks once they're in

Cisco email security boxes can be rooted by... an email

A critical vulnerability in Cisco Secure Email Gateway software allows attackers to gain full control of affected systems through a malicious email. This flaw, identified as CVE-2026-76461, grants root access regardless of the gateway's configuration. Cisco's Product Security Incident Response Team discovered the issue while addressing a support case, and malicious exploitation was already underway by September.

Cisco has released patches for affected appliances running AsyncOS versions 15.5.5-014, 16.0.4-302, and the most recent 16.5.0-780. However, administrators must manually verify their systems, as no workaround exists to prevent attackers from covering their tracks once they gain root access. Cisco advises checking logs for suspicious activity and rotating credentials and cryptographic material following a compromise.

Over 400 Cisco Secure Email Gateway appliances remain exposed to the internet, and the US Computer Emergency Readiness Team has ordered federal civilian agencies to remediate the issue by September 17.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

More from Tuesday 15 September →