Cisco Secure Email Gateway zero-day allows root RCE

Cisco warned CVE-2026-76461 lets remote, unauthenticated attackers execute commands as root via a crafted email and is being exploited in the wild.

Cisco warned customers Monday that a zero-day vulnerability in Secure Email Gateway, tracked as CVE-2026-76461, is being exploited in the wild. The flaw has a CVSS score of 9.8 and stems from an email-parsing bug in AsyncOS. A specially crafted message can trigger execution of arbitrary commands on the appliance operating system with root privileges and can include malicious SQL statements.

Cisco’s Product Security Incident Response Team reported it became aware of active exploitation in September 2026 but did not publish technical details or name the attackers. Both physical and virtual Secure Email Gateway deployments are affected in any configuration. Cisco noted Secure Email and Web Manager and Secure Web Appliance are not impacted.

The vendor published indicators of compromise and guidance for detection and mitigation. Cisco also warned that an attacker with root access can remove or alter forensic traces on a compromised device, which can limit the usefulness of published indicators.

The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-76461 to its Known Exploited Vulnerabilities catalog and directed federal civilian agencies to apply mitigations or patches by September 17, 2026. Inclusion in the catalog requires agencies to prioritize remediation under federal policy.

CVE-2026-76461 is one of several vulnerabilities Cisco disclosed recently in Secure Email Gateway and Secure Email and Web Manager. The advisory follows warnings earlier this month about exploited flaws in Cisco’s Secure Firewall Management Center, tracked as CVE-2026-20079 and CVE-2026-20316, which Cisco and CISA attributed to Russian state-sponsored actors and financially motivated cybercriminals. A prior Secure Email Gateway flaw, CVE-2025-20393, was added to the KEV list after exploitation by China-linked groups.

Cisco did not disclose whether exploitation of CVE-2026-76461 resulted in data theft or ransomware. Operators of Secure Email Gateway appliances are advised to follow Cisco’s published guidance, apply available mitigations or patches, and investigate devices for signs of compromise.

Articles by this author