Cisco releases urgent patches for a critical root-access vulnerability in secure email gateways.

Cisco’s remediation guidance specifies that Secure Email Gateway releases 15.5 and earlier should be upgraded to version 15.5.5-014; the associated Secure Email and Web Manager should be upgraded to 15.5.5-006.
Administrators of clustered Secure Email Gateway deployments should inspect the mail_logs on every device in the cluster, rather than checking only a single appliance, when looking for indicators of exploitation.
Cisco said that customers using Cisco Secure Email Cloud may not have CLI access to independently check the listed indicators of compromise, and that it directly contacted customers whose cloud devices showed detected malicious activity.
The fixed software can be installed through the appliance’s web-based management interface or CLI, and the device reboots after the upgrade is completed. Cisco Secure Email Cloud customers can request an upgrade through Cisco Secure Email Cloud support.
A separate Cisco security update cited additional high-severity issues affecting the product family, including path traversal (CVE-2026-76440), improper access control (CVE-2026-76441), resource-lifetime control (CVE-2026-20353), improper neutralization or injection (CVE-2026-76443), and input-quantity validation (CVE-2026-76442).
Cisco has released emergency patches for a critical vulnerability in its Secure Email Gateway appliances that allows attackers to gain root access without any authentication. Tracked as CVE-2026-76461 with a severity rating of 9.8, the flaw exploits faulty email-parsing logic to inject malicious SQL commands, potentially leading to complete system control. HelpNetSecurity reports the vulnerability is already being exploited in active attacks, making immediate patching urgent for organizations running internet-facing gateways.
The vulnerability affects Cisco Secure Email Gateway versions 15.5 and earlier on both physical and virtual appliances. Cisco warns there is no workaround and administrators must upgrade immediately. Organizations should also review mail logs for suspicious SQL activity that may indicate prior exploitation.
Cisco Secure Email Gateway users running version 15.5 or earlier must upgrade to version 15.5.5-014. The associated Secure Email and Web Manager should also be upgraded to version 15.5.5-006. Bleeping Computer notes the patched software can be installed through the appliance's web-based management interface or command-line interface, with the device automatically rebooting after installation completes.
Administrators managing clustered Secure Email Gateway deployments face an extra step: they must inspect mail_logs on every device in the cluster, not just a single appliance, to check for exploitation signs. Cisco Secure Email Cloud customers lack direct CLI access and should request upgrades through Cisco support. Cisco has already contacted cloud customers whose devices showed detected malicious activity.
The flaw enables unauthenticated attackers to send specially crafted emails containing SQL injection payloads. Once the email parser processes the message, attackers can execute arbitrary commands with root-level privileges — the highest permission level on Unix and Linux systems. Cybernews reports this level of access allows threat actors to completely compromise affected gateways.
Email gateways are critical perimeter devices that process mail for entire organizations. Root access to a gateway can give attackers the ability to intercept, modify, or delete emails, inject malware into outbound communications, or pivot deeper into corporate networks. The active exploitation in the wild demonstrates attackers have weaponized this flaw.
Cisco's security update includes fixes for five more high-severity issues in the Secure Email Gateway product family beyond CVE-2026-76461. These include a path traversal flaw (CVE-2026-76440), improper access control weakness (CVE-2026-76441), resource-lifetime control issues (CVE-2026-20353), improper input neutralization (CVE-2026-76443), and input-quantity validation problems (CVE-2026-76442).
Security teams should treat this as a critical incident requiring immediate action. First, upgrade all Secure Email Gateway appliances to the patched versions immediately. Second, review mail logs dating back several months to identify any suspicious SQL injection attempts. Third, check for signs that attackers obtained root access, such as unauthorized user accounts or configuration changes.
Organizations with internet-facing email gateways are at highest risk since attackers need only send a crafted email to trigger the flaw. No user interaction is required. HiTechHub emphasizes that delay in patching dramatically increases the window for compromise, and many organizations may already be running vulnerable versions without realizing the active threat.
Publishers
14
Articles
6
Reach
20