Cisco has released patches for a critical Secure Email Gateway vulnerability that attackers have exploited as a zero-day. The flaw allows unauthenticated remote attackers to run commands with root privileges.

The company urged customers to install the security updates immediately. Meanwhile, US federal agencies must patch affected systems by September 17.

Attackers Exploit Cisco Email Flaw

Cisco disclosed the active exploitation of CVE-2026-76461 in a security advisory published on Monday. Its security response team learned about the attacks in September 2026.

The Cisco email flaw affects the email-processing functionality in AsyncOS Software. It impacts both virtual and physical Secure Email Gateway appliances.

Moreover, every device configuration remains vulnerable. Therefore, administrators cannot eliminate the risk by disabling an optional feature or changing a particular setting.

Attackers do not need valid credentials to exploit the weakness. They can launch an attack remotely by sending a specially crafted email through an affected gateway.

Successful exploitation gives the attacker root-level control over the underlying operating system.

Malicious Emails Trigger Command Execution

CVE-2026-76461 results from insufficient validation within the software’s email parsing logic.

An attacker can create an email message containing malicious SQL statements. The vulnerable gateway processes this content as the message passes through the device.

Consequently, the attacker can execute arbitrary SQL statements on the system. This access can then lead to operating system commands running with root privileges.

Root represents the highest privilege level on Unix-based systems. Therefore, a successful attacker could gain extensive control over the compromised appliance.

The intruder may modify its configuration, access sensitive data or install additional malicious tools. Furthermore, the attacker could potentially use the gateway as an entry point into the wider network.

Email gateways hold a sensitive position because organisations place them between external senders and internal mail systems.

Cisco Shares Signs of Compromise

Cisco has released indicators of compromise to help customers investigate their appliances.

The company recommends searching the mail_logs on every device within a cluster. Administrators should look for suspicious SQL statements that may indicate exploitation attempts.

However, attackers may delete local evidence after compromising a device. Therefore, checking the gateway logs alone may not reveal the full scope of an intrusion.

Security teams should also examine network and firewall records. They should search for unusual communication with unknown or malicious external IP addresses.

In particular, defenders should investigate unexpected uploads and downloads. Unusual outbound traffic may indicate data theft or communication with attacker-controlled infrastructure.

Organisations that find signs of exploitation should isolate the affected appliance. They should also investigate surrounding systems for evidence of further access.

Hundreds of Gateways Remain Online

Internet monitoring organisation Shadowserver currently tracks more than 400 publicly exposed Cisco Secure Email Gateway appliances.

However, the figure may include research honeypots. It also does not show how many internet-facing devices have already received the security update.

Exposing a gateway to the internet does not necessarily confirm vulnerability. Nevertheless, public accessibility gives attackers an opportunity to deliver malicious messages directly to the appliance.

Because Cisco has confirmed active exploitation, administrators should treat patching as an urgent priority.

US Agencies Receive Three-Day Deadline

The US Cybersecurity and Infrastructure Security Agency added CVE-2026-76461 to its Known Exploited Vulnerabilities catalogue on Monday.

The catalogue lists security flaws that attackers have demonstrably exploited in real-world incidents.

CISA ordered federal civilian agencies to patch affected systems within three days. The deadline falls on September 17.

Although the requirement applies directly to federal organisations, private companies often use the catalogue to prioritise urgent security work.

The short deadline reflects the vulnerability’s severity and confirmed exploitation.

Cisco Fixes Four Additional Critical Flaws

Cisco also addressed four other critical vulnerabilities affecting Secure Email Gateway and Secure Email and Web Manager appliances.

The flaws carry the identifiers CVE-2026-76440, CVE-2026-76441, CVE-2026-20353 and CVE-2026-76443. They affect appliances regardless of their configuration.

However, Cisco has found no evidence that attackers have exploited those four vulnerabilities in active campaigns.

The company previously fixed another serious AsyncOS weakness in January. Attackers had exploited CVE-2025-20393 against email security appliances since November 2025.

More recently, Cisco confirmed that ransomware operators and state-sponsored groups exploited two Secure Firewall Management Center vulnerabilities.

Since November 2021, CISA has marked 98 Cisco vulnerabilities as actively exploited. Ransomware gangs have used at least seven of them.

These incidents underline the importance of installing security patches quickly. Organisations should also inspect appliances for compromise because updating a previously breached device will not remove an attacker’s existing access.


0 responses to “Cisco Email Flaw Gives Attackers Root Access”