Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Cisco Email Gateway Zero-Day Under Attack: Patch Now

If your business runs a Cisco Secure Email Gateway appliance, physical or virtual, there's a critical zero-day being actively exploited right now. A single crafted email is enough for an attacker to get root access, no clicks needed.

Cisco confirmed the flaw, tracked as CVE-2026-76461 and rated 9.8 out of 10, after BleepingComputer reported active exploitation on 15 September 2026. The bug sits in the appliance's email parsing logic: malicious SQL statements hidden in a message can trigger command execution with root privileges, no login required. Shadowserver is already tracking roughly 400 exposed devices being probed. In our experience, appliances like this one are usually set-and-forget, racked once and left alone until something breaks, which is exactly what attackers go looking for first.

Cisco has released fixes: 15.5.5-0141 for AsyncOS 15.5 and earlier, 16.0.4-302 for 16.0, and 16.5.0-780 for 16.5, through Cisco's own security advisory. There's no workaround, so patching is the only real fix. If you manage your own appliance, check mail_logs for suspicious SQL statements and review firewall logs for unusual outbound traffic. If All IT looks after your email security, we're already working through the patch schedule for affected clients, but if you're unsure whether your gateway is covered, get in touch today.

Written by Caleb Attard, Head of Business Operations, All IT Services. All IT is a Sydney-based managed IT provider supporting hospitality, not-for-profit and wealth management businesses across Australia.


Frequently Asked Questions

It's a critical flaw (CVSS 9.8) in Cisco Secure Email Gateway appliances that lets an attacker send a crafted email and gain root access to the device without a password.
Yes. Cisco and researchers confirmed active exploitation before a patch existed, and hundreds of internet-facing appliances are already being scanned by attackers.
If you run a physical or virtual Cisco Secure Email Gateway on AsyncOS 15.5 or earlier, 16.0, or 16.5, you're affected unless you've already applied September's patches.
There's no workaround, so patching is the priority. In the meantime, check mail logs for suspicious SQL statements and consider isolating the appliance from the internet.

Not sure if your email gateway is patched?

All IT Services helps Australian businesses find and close gaps like this one before attackers do. Get a free check of your exposure today.


Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →