An unauthenticated attacker can take root on the email gateway sitting in front of a hospital’s clinical correspondence by sending a single crafted message, and Cisco says the flaw is already being used in the wild.
The bug is CVE-2026-76461, a SQL injection rated 9.8 that lives in the email parsing logic of Cisco Secure Email Gateway. It affects AsyncOS 16.5, 16.0, and 15.5 and earlier on both physical and virtual appliances, and it also touched Cisco Secure Email Cloud, where the vendor says it contacted customers directly after detecting malicious activity. No user action is needed and no authentication is required: the payload rides inside the message itself.
Root is the prize. Executing the injected statements escalates an intruder to the operating system’s most privileged account, and at that level logs can simply be deleted. Cisco’s answer is to look elsewhere: compare traffic records gathered by other networking and security devices for signs that the appliance shipped data to unfamiliar addresses.
For healthcare, the gateway is where referrals, lab results, scheduling mail, and clinical threads enter the network, so an unauthenticated root foothold there is a foothold inside the perimeter. CISA added the flaw to its Known Exploited Vulnerabilities catalog and gave federal civilian agencies until Thursday to remediate and hunt for signs of compromise.
Fixes are available in one of three releases, 15.5.5-014, 16.0.4-302, or 16.5.0-780. Cisco also wants administrators searching mail logs for suspicious SQL statements. If indicators turn up, rebuild on a fixed release rather than cleaning the appliance in place.