< Back to all clusters
[TECHNOLOGY] · 4 sources

started · updated

Cisco Secure Email Gateway faces critical zero-day RCE vulnerability

A critical unauthenticated zero-day vulnerability, identified as CVE-2026-76461, has been discovered in Cisco Secure Email Gateway’s AsyncOS. The flaw is currently being exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities catalog.

The vulnerability stems from insufficient input validation during email parsing, which allows an attacker to perform a SQL injection. By utilizing the Postgres COPY ... TO PROGRAM command, an unauthenticated attacker can achieve immediate root-level remote code execution (RCE) by sending a single crafted email to the appliance’s MX record.

Successful exploitation grants full system compromise, enabling attackers to steal LDAP credentials, intercept decrypted mail, and manipulate local logs to evade detection. Because the gateway typically resides in the DMZ, it can serve as a pivot point for lateral movement into internal networks. Cisco has stated that no workarounds exist, and immediate patching to fixed AsyncOS versions is required.

Entities

AsyncOS · CISA · Cisco