Cisco published an advisory for CVE-2026-76461, a critical vulnerability in the email-parsing logic of Cisco Secure Email Gateway appliances running AsyncOS.

The flaw allows an unauthenticated remote attacker to send a specially crafted email containing malicious SQL statements. Successful exploitation can lead to arbitrary SQL execution and command execution with root privileges on the underlying operating system.

Cisco said its Product Security Incident Response Team became aware of active exploitation in September 2026. The company released software updates and said no workaround is available.

The vulnerability carries a CVSS base score of 9.8. Because the affected systems commonly sit at the boundary of enterprise email infrastructure and exploitation does not require user interaction, defenders were urged to prioritize the available fixes.