Skip to content
The Cybersecurity Focus
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
CVEexploitZero Day

Cisco Secure Email Gateway CVE Critical Zero-Day

By ogwatermelon
September 15, 2026 3 Min Read
0
September 15, 2026

Cisco has disclosed a critical zero-day vulnerability in its Secure Email Gateway that threat actors are actively exploiting to gain root-level command execution. The flaw, tracked as CVE-2026-76461, carries a CVSS score of 9.8 and was added to the CISA Known Exploited Vulnerabilities catalog on September 14, 2026. Federal agencies must patch by September 17, 2026.

What Happened: Cisco Secure Email Gateway Zero-Day Under Active Exploit

On September 14, 2026, Cisco warned customers that a critical flaw in the email parsing logic of AsyncOS Software for Cisco Secure Email Gateway was under active exploitation. The vulnerability allows an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) promptly added CVE-2026-76461 to its Known Exploited Vulnerabilities (KEV) catalog. Consequently, Federal Civilian Executive Branch agencies are required to apply patches by September 17, 2026.

Over 400 Cisco Secure Email Gateway appliances remain internet-exposed, according to data from the Shadowserver Foundation. Furthermore, Cisco has directly contacted customers who own Cisco Secure Email Cloud devices where malicious activity was detected.

Technical Details of the Cisco Secure Email Gateway Vulnerability

The vulnerability stems from insufficient validation in the email parsing logic of Cisco AsyncOS Software for Cisco Secure Email Gateway. An attacker can exploit this flaw by sending a crafted email message containing malicious SQL statements through an affected device.

A successful exploit enables the attacker to execute arbitrary SQL statements. This, in turn, leads to command execution with root privileges on the underlying operating system. The attack requires no authentication and can be launched remotely.

Affected Products

  • Cisco Secure Email Gateway (physical and virtual appliances)
  • All device configurations are affected

Products Not Affected

  • Cisco Secure Email and Web Manager
  • Cisco Secure Web Appliance

Fixed Versions

  • AsyncOS 15.5 and earlier — Fixed in 15.5.5-0141
  • AsyncOS 16.0 — Fixed in 16.0.4-302
  • AsyncOS 16.5 — Fixed in 16.5.0-780

Business and Operational Impact

Successful exploitation grants attackers full root access to the email gateway appliance. Moreover, because this level of access allows threat actors to remove or hide evidence of exploitation, detection becomes significantly more difficult.

  • Data exposure risk: Attackers can read, modify, or exfiltrate email content passing through the gateway.
  • Lateral movement: Compromised appliances can serve as pivot points into internal networks.
  • Service disruption: Attackers can disable email filtering or redirect traffic.
  • Compliance implications: Organizations in regulated industries may face audit failures and penalties.

Mitigation and Recommendations

Immediate Actions for Defenders

  1. Apply patches immediately. Cisco has released fixed versions for all supported AsyncOS releases. There are no workarounds.
  2. Review mail logs for indicators of compromise. Search for suspicious SQL statements in mail_logs on each cluster device.
  3. Cross-check network and firewall logs. Look for unexpected uploads to external IP addresses or downloads from suspicious sources.
  4. Verify appliance exposure. Determine if your Secure Email Gateway appliances are internet-facing and restrict access where possible.

Detection Guidance

Cisco recommends running the following command on affected appliances to detect potential exploitation:

grep -i "COPY.*TO PROGRAM" mail_logs

The presence of any matching entry may indicate malicious activity. Also review logs outside the impacted device, since attackers with root access can erase local evidence.

Additional Context

This disclosure follows a pattern of sustained targeting of Cisco security appliances. In January 2026, Cisco patched another maximum-severity AsyncOS flaw (CVE-2025-20393) that had been exploited since November 2025. More recently, three separate ransomware and state-sponsored groups were observed exploiting recently patched Cisco Secure Firewall Management Center flaws.

Bottom line: Organizations running Cisco Secure Email Gateway must patch immediately. With CISA mandating a three-day federal patch deadline and active exploitation confirmed, this vulnerability poses an immediate and severe risk to email infrastructure security.

Incident Summary

CVE ID: CVE-2026-76461
Affected Systems: Cisco Secure Email Gateway (physical and virtual), all configurations
CVSS Score: 9.8 (Critical)
Disclosure Date: September 14, 2026
Patch Status: Fixed versions available — no workarounds
CISA KEV Added: September 14, 2026 (patch deadline: September 17, 2026)

References

  1. Sergiu Gatlan, “Cisco patches Secure Email Gateway zero-day exploited in attacks,” BleepingComputer, September 15, 2026, https://www.bleepingcomputer.com/news/security/new-cisco-secure-email-zero-day-exploited-to-execute-commands-as-root/, accessed September 15, 2026.
  2. Cisco, “Cisco Secure Email Gateway Arbitrary Command Execution Vulnerability,” Cisco Security Advisory, September 14, 2026, https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX, accessed September 15, 2026.
  3. U.S. Cybersecurity and Infrastructure Security Agency (CISA), “CISA Adds One Known Exploited Vulnerability to Catalog,” CISA Alerts, September 14, 2026, https://www.cisa.gov/news-events/alerts/2026/09/14/cisa-adds-one-known-exploited-vulnerability-catalog, accessed September 15, 2026.
  4. Shadowserver Foundation, “Internet-exposed Cisco Secure Email Gateway appliances,” Shadowserver Dashboard, September 2026, https://dashboard.shadowserver.org/statistics/iot-devices/time-series/, accessed September 15, 2026.

Tags:

CVEExploitZero Day
Author

ogwatermelon

Follow Me
Other Articles
Previous

CISA Confirms Active Exploitation of Critical GitLab Path Traversal

Next

Google Patches Actively Exploited Android Zero-Day on Pixel Devices

AI Botnet Breach CVE Exploit Hack Incident Infostealer Linux Mac Malware Network Phishing Ransomware RCE supply chain Vishing Vulnerability Windows World Zero Day

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026

Categories

  • AI
  • BotNet
  • Breach
  • CVE
  • exploit
  • Hack
  • Incident
  • Infostealer
  • Linux
  • Mac
  • Malware
  • Phishing
  • Ransomware
  • RCE
  • supply-chain
  • Uncategorized
  • Vishing
  • Vulnerability
  • Windows
  • World
  • Zero Day
Copyright 2026 — The Cybersecurity Focus. All rights reserved.