Cisco Email Gateway Flaw CVE-2026-76461 Under Active Attack
The [Canadian Centre for Cyber Security](https://www.cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-921) independently confirmed the exploitation warning in its September 14 bulletin. It also reported that CISA added the vulnerability to its Known Exploited Vulnerabilities catalog that day.
According to Cisco, inadequate validation during email parsing lets an unauthenticated remote attacker send a specially constructed message containing SQL instructions. Successful exploitation can lead to operating-system commands running as root.
Cisco says physical and virtual gateways are affected regardless of configuration. Administrators should inspect mail_logs for suspicious SQL and compare external network and firewall logs, because attackers could conceal evidence on compromised appliances.
The Canadian bulletin lists corrected AsyncOS versions 15.5.5-014, 16.0.4-302 and 16.5.0-780, and urges administrators to apply necessary updates. Cisco reports that no workaround resolves this vulnerability.
For suspected compromise of virtual appliances, Cisco recommends preserving forensic evidence before rebuilding with fixed software and renewing credentials and cryptographic material. Suspected compromise of physical appliances should be referred to Cisco support.