CVE-2026-76461 is an SQL injection in the mail parsing of Cisco AsyncOS. It needs no account, does not depend on configuration and is already being used in attacks. There is no workaround, only the upgrade.
- The attacker sends a crafted email, the gateway parses it, and during parsing it can run someone else's commands with root privileges.
- Physical and virtual Secure Email Gateway devices are affected regardless of configuration. The fix is in 15.5.5-014, 16.0.4-302 and 16.5.0-780.
- In a cluster, a breached gateway can hand over the keys to the others, so Cisco recommends restoring the whole cluster.
The mail gateway is the place everything you do not know passes through. Its job is to read strangers' letters before you have opened a single one of them.
That is exactly where the hole is. The attacker does not come in with a password and does not wait for an employee to click a link. They send an email. The gateway inspects it the way it inspects every other one, and while inspecting it, can run someone else's command with the highest privileges on the system.
What the advisory says further down
Two details weigh more than the 9.8 score. The first: after a successful attack the intruder may have root and can wipe their tracks. That is why Cisco itself advises not to trust only the device's own logs, but to check the firewall and the network around it for unexpected uploads going out.
The second is about clusters. Gateways in a cluster recognise each other with SSH keys, and if one is breached, the keys may already be with the attacker. The recommendation is to restore every member of a cluster that contains at least one compromised device, not only the infected one.
For checking, Cisco gives a concrete direction: search mail_logs for suspicious SQL statements of the COPY ... TO PROGRAM kind. An empty result is not yet a guarantee, because Cisco itself calls the example non-exhaustive. A full one means you leave the news and call Cisco support.
If you run such a gateway on your own hardware or in a virtual machine, you upgrade today, without waiting for a maintenance window. The three days are the US agencies' deadline, and the attacks are already running.