Cisco Warns of Active Exploitation in Secure Email Gateway Vulnerability, Fortinet VPNs Under Attack
Cisco has issued a critical warning regarding a newly discovered vulnerability in its **AsyncOS Software for Cisco Secure Email Gateway**, which is already being actively exploited in the wild. Tracked as **CVE-2026-76461**, this flaw allows unauthenticated attackers to execute arbitrary commands with root privileges. Simultaneously, Fortinet VPN appliances are facing large-scale credential-stuffing attacks, highlighting a broader landscape of escalating threats.
Cisco has issued a urgent advisory concerning a critical vulnerability, **CVE-2026-76461**, affecting its **AsyncOS Software for Cisco Secure Email Gateway**. The flaw, boasting a **CVSS score of 9.8**, is actively being exploited, allowing unauthenticated, remote attackers to achieve root-level command execution.
### The Cisco Secure Email Gateway Vulnerability
The vulnerability stems from insufficient validation in the email parsing logic. Attackers can exploit this by sending specially crafted email messages containing malicious SQL statements through an affected device. A successful exploit grants the attacker the ability to execute arbitrary SQL statements, ultimately leading to command execution with root privileges on the underlying operating system.
"An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device," **Cisco** stated in its advisory. "A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system."
This critical flaw impacts both physical and virtual **Cisco Secure Email Gateway** devices, regardless of their configuration. However, **Cisco** confirmed that other products like **Secure Email and Web Manager** and **Secure Web Appliance** are not affected.
### Patching and Indicators of Compromise
Patches are now available for the following versions of **Cisco AsyncOS for Cisco Secure Email Gateway Software Release**:
* 15.5 and earlier (Fixed in 15.5.5-0141)
* 16.0 (Fixed in 16.0.4-302)
* 16.5 (Fixed in 16.5.0-780)
**Cisco** strongly advises immediate updates, as there are no known workarounds. The company became aware of active exploitation this month and has provided the following Indicators of Compromise (**IoCs**):
* Review `mail_logs` for suspicious SQL statements.
* If the device is part of a cluster, review the logs of each cluster device.
* Run the command: `cisco-esa> grep -i "COPY.*TO PROGRAM" [IronPort Text Mail Logs Log name - Default: mail_logs]` β any entry in the output may indicate malicious activity.
**Cisco** has proactively contacted customers with **Cisco Secure Email Cloud** devices where malicious activity was detected, though the scale of the attacks remains undisclosed.
"Upon successful exploitation of this vulnerability, threat actors may obtain command execution with root privileges," **Cisco** warned. "Because of this level of access, evidence of exploitation and indicators of compromise may be removed or hidden by the threat actors."
Administrators are advised to cross-reference network and firewall logs outside of the impacted device for anomalous activity, including unexpected uploads from the affected device to external IP addresses or downloads from malicious IP addresses.
In response to the active exploitation, the **U.S. Cybersecurity and Infrastructure Security Agency (CISA)** has added **CVE-2026-76461** to its **Known Exploited Vulnerabilities (KEV)** catalog. This mandates Federal Civilian Executive Branch (**FCEB**) agencies to apply the necessary patches by September 17, 2026.
### Large-Scale Credential Attacks Target Fortinet VPNs
This disclosure follows recent reports from **Arctic Wolf** detailing large-scale credential attacks against internet-facing **Fortinet VPN** appliances. These high-volume attacks occurred over two sustained waves from August 26 through August 28, 2026, generating tens of millions of authentication failures across multiple U.S. customer environments.
"The actor used organization-specific usernames, corporate email addresses, affiliate accounts, and common administrative identities, indicating access to previously collected or enumerated identity information," noted security researcher **Kyle Siddall**.
The attempted usernames were not generic, but targeted, including employee names, corporate email addresses, and affiliate identities. This suggests that the attackers had access to previously collected or enumerated identity information.
In one instance, a successful **Fortinet VPN** authentication originating from the IP address "158.94.211[.]14" was subsequently linked to malicious activity within the affected environment.