Cisco disclosed five remotely reachable, unauthenticated vulnerability groupings in Cisco Secure Email Gateway (AsyncOS) and Cisco Secure Email and Web Manager: CVE-2026-76440, CVE-2026-76441, CVE-2026-20353, CVE-2026-76442, and CVE-2026-76443. The most severe issue, CVE-2026-76443, stems from improper neutralization of input and could enable remote execution of crafted input; CVE-2026-76441 and CVE-2026-20353 are each rated CVSS 9.8 and can affect confidentiality, integrity, and availability without authentication or user interaction.
The flaws affect appliances regardless of configuration, and Cisco has provided no workarounds; organizations must upgrade to fixed releases. Cisco reported no known public exploit code or exploitation for the five newly disclosed vulnerabilities, but defenders should prioritize patching because the related AsyncOS flaw CVE-2026-76461 is under active exploitation and has been added to CISA's Known Exploited Vulnerabilities catalog.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
CISA added CVE-2026-76461, an AsyncOS email-parsing SQL injection flaw reported to enable unauthenticated root-level command execution through a crafted email, to its Known Exploited Vulnerabilities catalog due to active exploitation.
Cisco published a security-hardening release and disclosed five internally discovered, remotely reachable unauthenticated vulnerability groupings in Cisco Secure Email Gateway and Secure Email and Web Manager: CVE-2026-76440, CVE-2026-76441, CVE-2026-20353, CVE-2026-76442, and CVE-2026-76443. Cisco said no workarounds were available and remediation required upgrading to a fixed release.
Cisco patched a maximum-severity AsyncOS vulnerability after the zero-day exploitation that began in November 2025.
Zero-day exploitation of a maximum-severity vulnerability in Cisco's AsyncOS appliance family began in November 2025.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
threataft.com
Open sourcelabs.beazley.security
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.