Attackers are actively targeting a maximum-severity vulnerability in AsyncOS.
Cisco announced on 15 September 2026 that attackers are actively exploiting a critical vulnerability in its Secure Email Gateway appliances. The flaw, tracked as CVE-2026-76461, received a 9.8 score on the Common Vulnerability Scoring System (CVSS) and impacts both physical and virtual appliances regardless of configuration, according to a report by The Register.
The vulnerability stems from how the AsyncOS operating system processes incoming messages. Attackers do not need credentials to exploit the bug: sending a specially crafted email allows them to execute commands with root privileges. The Cisco Product Security Incident Response Team learned of active exploitation in September 2026 after discovering the flaw during a Technical Assistance Center case. The company did not disclose the attackers' identities, how long the campaign lasted, or the total number of impacted organisations.
Cisco investigated its Secure Email Cloud service and contacted affected cloud customers directly. All cloud appliances have been updated to AsyncOS version 16.5.0-780, with recovery and remediation ongoing. For on-premises administrators, Cisco patched the bug in AsyncOS versions 15.5.5-014, 16.0.4-302, and 16.5.0-780, strongly urging an upgrade to 16.5.0-780. For compromised virtual machines, Cisco recommends deploying a new instance and replacing credentials and cryptographic keys, as root access allows attackers to modify gateway logs.
The Shadowserver Foundation tracked over 400 internet-exposed Cisco Secure Email Gateway appliances on 14 September. The US Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalog, ordering US civilian federal agencies to apply the remediation by 17 September. This incident follows another critical AsyncOS vulnerability from less than a year prior, CVE-2025-20393, which held a maximum 10 CVSS score.
Newsletter
Markets in your inbox, weekly
LATAM-focused analysis, investing ideas, and the week in finance.
Keep reading