Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: secure-email-gateway (1 article)Clear

Exploited Cisco email gateway flaw lets a crafted email run commands as root

Cisco warned that attackers are exploiting a critical zero-day in its Secure Email Gateway appliances that lets them run commands as root just by sending a crafted email. Tracked as CVE-2026-76461 and scored 9.8, the flaw is a SQL injection in the appliance's email-parsing logic, so an unauthenticated attacker needs no access to the management interface at all. It affects physical and virtual gateways in any configuration, and Cisco confirmed it was exploited as a zero-day before disclosure. CISA added it to its exploited-vulnerabilities catalog with a three-day federal deadline. Because successful attacks grant root, intruders can erase their own tracks, so Cisco urges inspecting mail logs for suspicious activity.

Check
Patch Cisco Secure Email Gateway appliances immediately given active exploitation, and inspect mail and network logs for suspicious SQL statements and signs of compromise, despite the risk that root access erased indicators.
Affected
Organizations running physical or virtual Cisco Secure Email Gateway appliances in any configuration (CVE-2026-76461); an unauthenticated attacker can send a crafted email to run commands as root, exploited in the wild.
Fix
Apply the fixed AsyncOS releases now, hunt for compromise using Cisco's indicators while assuming a rooted device may hide them, and apply the four other critical email-gateway fixes shipped the same day.