“An attacker doesn’t need to log in: they can send a booby-trapped message through a vulnerable gateway and, if the exploit works, run commands as root”

You bought the appliance to inspect hostile email. The hostile email now owns the appliance. CVE-2026-76461 scores a 9.8 and needs no credentials, which means the attack is literally just sending a message. This is the second critical AsyncOS break in under a year, so the pattern is the product, not the bug.