Back to feed

Cisco Warns Secure Email Gateway Zero-Day Exploited in Wild

2 min
Cisco Warns Secure Email Gateway Zero-Day Exploited in Wild

This digest was compiled by AI from multiple sources — links to the originals are below.

Cisco warned customers on Monday that a critical zero-day vulnerability in its Secure Email Gateway appliances is being actively exploited in the wild. The flaw, tracked as CVE-2026-76461 with a CVSS score of 9.8, allows unauthenticated remote attackers to execute arbitrary commands with root privileges. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and set a federal remediation deadline of September 17.

Key Facts

  • CVE-2026-76461 has a CVSS score of 9.8 and affects Cisco Secure Email Gateway physical and virtual appliances in any configuration.
  • Cisco released fixes for AsyncOS versions 15.5.5-0141, 16.0.4-302, and 16.5.0-780.
  • CISA added CVE-2026-76461 to its Known Exploited Vulnerabilities catalog on Monday and set a federal remediation deadline of September 17.
  • Secure Email and Web Manager and Secure Web Appliance are not affected by the vulnerability.
  • Cisco's PSIRT became aware of exploitation in September 2026 but has not disclosed details about the attacks or the threat actors involved.

Vulnerability Details

The vulnerability stems from insufficient validation in the email parsing logic of AsyncOS Software. An attacker can exploit the flaw by sending a crafted email containing malicious SQL statements to a targeted user. Successful exploitation leads to arbitrary SQL statement execution and command execution with root privileges on the underlying operating system. Cisco describes the issue as remotely exploitable without authentication, affecting both physical and virtual Secure Email Gateway appliances regardless of configuration.

Exploitation and Response

Cisco's Product Security Incident Response Team became aware of active exploitation in September 2026. The company has not shared details on the attacks or attributed them to a specific threat actor. Cisco released indicators of compromise but noted that attackers with root privileges can remove or hide IoCs to cover their tracks. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on Monday and instructed federal organizations to remediate by September 17.

Affected Products and Fixes

The vulnerability affects Cisco Secure Email Gateway, both physical and virtual, in any configuration. Secure Email and Web Manager and Secure Web Appliance are not impacted. Fixes are available in Cisco AsyncOS for Secure Email Gateway Software Release 15.5.5-0141, 16.0.4-302, and 16.5.0-780. Cisco states there are no workarounds other than updating to the latest supported version.