CVE-2026-76461: Cisco AsyncOS Root Remote Code Execution Under In-the-Wild Exploitation

Cisco AsyncOS CVE-2026-76461 Root RCE Technical Analysis
🛡️
Vulnerability Intelligence:

Cisco has published an urgent advisory warning of active in-the-wild exploitation targeting a critical vulnerability in Cisco AsyncOS Software for Cisco Secure Email Gateway. Tracked as CVE-2026-76461, this flaw allows unauthenticated remote adversaries to achieve root-level remote code execution by transmitting crafted email messages through standard SMTP listeners.

Vulnerability Mechanics & Root-Cause Analysis

The root cause lies within AsyncOS's internal mail filtering engine, which parses incoming RFC 5322 and MIME headers before evaluating anti-spam and content filter dictionaries. When handling multi-part encoded message structures with nested header fields, the parsing daemon extracts metadata values directly into dynamic SQL queries without adequate parameter binding or sanitization.

Incoming SMTP Packet (Port 25)
  └── MIME Parser Engine (AsyncOS)
        ├── Extracts Header: "X-Header-Metadata: [Injected SQL Statement]"
        ├── Flawed Concat: db_exec("SELECT * FROM msg_rules WHERE header = '" + raw_hdr + "'")
        └── SQL Breakout -> System Shell Invocation via SQLite/Postgres Extension -> ROOT Shell

Because the database process on AsyncOS runs with elevated OS permissions to manage appliance configurations and quarantine stores, successful SQL injection allows attackers to invoke operating system command execution wrappers (e.g., via backend system hooks), yielding an interactive root shell.

Observed Threat Actor Telemetry & IOCs

Telemetry indicates state-linked and cyber espionage groups have leveraged this vulnerability to establish persistent footholds on perimeter email appliances, enabling eavesdropping on unencrypted internal email traffic, credential harvesting, and lateral movement into core enterprise networks.

🔍
Detection Rule (Snort / Suricata):
alert tcp any any -> $MAIL_SERVERS 25 (msg:"COLIBRISEC - Cisco AsyncOS CVE-2026-76461 Header Injection Attempt"; content:"X-Header-"; nocase; pcre:"/X-Header-[^ ]*('|--|;|/*)/i"; classtype:attempted-admin; sid:202676461; rev:1;)

Remediation Checklist

  1. Apply Emergency AsyncOS Patches: Upgrade Cisco Secure Email Gateway to version 15.5.5-014, 16.0.4-302, or 16.5.0-780.
  2. Isolate Management Interfaces: Ensure appliance web administration interfaces (ports 80/443) and SSH listeners are strictly restricted to isolated out-of-band management subnets.
  3. Audit Appliance Integrity: Run Cisco AsyncOS CLI command diagnostic system integrity verify to detect unauthorized filesystem modifications or anomalous background processes.

Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther