A Critical Zero-Day Vulnerability is Being Actively Exploited in Cisco Secure Email Gateway Appliances
A severe zero-day vulnerability has been discovered in Cisco’s Secure Email Gateway appliances, allowing attackers to execute arbitrary commands on the underlying operating system with root privileges. This critical flaw, identified as CVE-2026-76461, can be exploited remotely and without authentication by sending specially crafted emails to targeted users.
The vulnerability is present in both physical and virtual versions of the Secure Email Gateway appliance, regardless of configuration. According to Cisco, the issue arises from an email parsing problem in the AsyncOS software that allows malicious SQL statements to be executed on the device. This can be done without any authentication or user interaction, making it a particularly concerning threat.
Cisco has warned its customers about the vulnerability and has released indicators of compromise (IoCs) to help identify potential attacks. However, due to the severity of the flaw, attackers can easily remove or hide these IoCs to cover their tracks. The company’s Product Security Incident Response Team (PSIRT) became aware of the exploitation in September 2026 but has not provided details on the attackers behind this vulnerability.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76461 to its Known Exploited Vulnerabilities (KEV) catalog on Monday, instructing federal organizations to address the issue by September 17. This is only the second Cisco Secure Email Gateway vulnerability to be listed in the KEV catalog, following a similar flaw discovered last year.
The exploitation of CVE-2026-76461 comes on the heels of another critical vulnerability affecting Cisco’s Secure Firewall Management Center (FMC), which was warned about just days ago. The connection between these two vulnerabilities is unclear, but it highlights the ongoing need for organizations to prioritize patching and vulnerability management in their security strategies.
As always, users of Cisco’s Secure Email Gateway appliances should take immediate action to address this critical flaw. Organizations can do so by installing available patches or workarounds as soon as possible. It is also essential to be aware that attackers may attempt to exploit CVE-2026-76461, particularly in targeted attacks.
To mitigate the risk of exploitation, it is crucial for organizations to:
* Regularly review and apply security updates and patches
* Implement robust email filtering and scanning practices
* Monitor their systems for signs of unusual activity or suspicious emails
* Consider implementing additional security measures, such as intrusion detection and prevention systems
By taking these steps, organizations can minimize the risk of falling victim to this critical vulnerability and protect themselves from potential attacks.
Source: SecurityWeek — 2026-09-15