Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Email Security

Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation

An unauthenticated attacker can exploit CVE-2026-76461 to execute arbitrary commands on the underlying OS with root privileges.

Cisco vulnerability exploited

Cisco warned customers on Monday that a zero-day vulnerability affecting Secure Email Gateway appliances has been exploited in the wild.

The vulnerability is identified as CVE-2026-76461 and has a CVSS score of 9.8. Cisco describes it as an email parsing issue in AsyncOS software that can be exploited remotely and without authentication to execute arbitrary commands on the underlying operating system with root privileges.

The tech giant explained that the critical flaw can be exploited to execute malicious SQL statements by sending them to the targeted user inside a specially crafted email. 

Cisco said its PSIRT became aware of the exploitation of CVE-2026-76461 in September 2026, but it has not shared details on attacks involving the zero-day. It’s also unclear who is behind the attacks.

The company has released indicators of compromise (IoCs), but noted that because threat actors can obtain root privileges on a device, they can remove or hide IoCs to cover their tracks.

The security hole affects both the physical and virtual versions of Secure Email Gateway in any configuration. Secure Email and Web Manager and Secure Web Appliance are not impacted.

Advertisement. Scroll to continue reading.

The cybersecurity agency CISA added CVE-2026-76461 to its KEV catalog on Monday and instructed federal organizations to address it by September 17.

This is only the second Cisco Secure Email Gateway vulnerability in the KEV list, after CVE-2025-20393, which China-linked threat actors started exploiting in late 2025.  

CVE-2026-76461 is one of several vulnerabilities Cisco discovered internally in its Secure Email Gateway and Secure Email and Web Manager products.

News of CVE-2026-76461’s exploitation comes just days after Cisco and CISA warned organizations about attacks leveraging CVE-2026-20079, a Secure Firewall Management Center (FMC) vulnerability disclosed earlier this year.

Cisco warned that CVE-2026-20079 and another FMC weakness tracked as CVE-2026-20316 have been exploited by both Russian state-sponsored hackers and profit-driven cybercriminals.

Related: Three JFrog Artifactory Flaws Exploited for Backdoor Deployment

Related: BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

Related: ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks

Related: Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

Zero Networks has named Yossi Dagan as Chief Financial Officer.

Manifold has appointed Joe Sullivan to its Board of Directors.

Patrick McKinney has joined Turing as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.