Active attacks put Cisco email security gateways at root-level risk
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Wednesday, September 16th, 2026.
A system designed to stop malicious email can now become an attacker’s privileged foothold. Attackers have exploited a weakness affecting on-premises Cisco Secure Email Gateway appliances running AsyncOS 16.5, 16.0, and 15.5 and earlier. A crafted email can trigger the issue without any user interaction and lead to command execution with root privileges. Cisco has also contacted cloud customers where malicious activity was detected and has released fixed versions.
Root access could allow an attacker to change security policies, hide evidence, or use the gateway to reach other systems. That means installing the update may not be enough for an appliance that was previously exposed. Leaders should plan for remediation and investigation. Defenders should upgrade, inspect mail logs, and compare the appliance’s activity with independent firewall and network records because attackers with root access may alter local evidence. CISA added the issue to its exploited-vulnerability catalog with a September 17th federal deadline. Upgrade now and perform compromise checks using both device and external network logs.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.