Cisco patches actively exploited zero-day in Secure Email Gateway allowing root access via a crafted email
Cisco confirmed active exploitation of CVE-2026-76461, a pre-authentication SQL injection in Secure Email Gateway that lets a crafted email execute commands as root, prompting a CISA remediation order.
- Victim
- Cisco Secure Email Gateway
On 15 September 2026, Cisco confirmed that attackers were actively exploiting a critical zero-day vulnerability in its Secure Email Gateway appliances, tracked as CVE-2026-76461, after its product security team observed exploitation in the wild.
The flaw is a pre-authentication SQL injection in the email-parsing logic of Cisco's AsyncOS software, rated 9.8 on the CVSS scale. Because affected gateways process externally delivered mail as part of normal operation, an unauthenticated attacker can trigger it simply by sending a crafted email containing malicious SQL statements โ no user interaction or valid credentials required. Successful exploitation lets the attacker execute arbitrary SQL and, ultimately, run commands with root privileges on the underlying operating system. Cisco said affected releases include AsyncOS 15.5, 16.0 and 16.5, with fixes shipped in version 16.5.0-780.
Federal patch order
The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-76461 to its Known Exploited Vulnerabilities catalog and directed federal civilian agencies to remediate the flaw by 17 September, an unusually short window that reflected the severity of a pre-auth, root-level bug on an internet-facing security appliance. Two days after the email-gateway alert, Cisco disclosed a separate authentication-bypass flaw in its Identity Services Engine, compounding a difficult week for the vendor.
Assessment
No public attribution named a specific threat actor behind the email-gateway exploitation, though security researchers noted that email security appliances have become a favored target for espionage-focused groups seeking a durable foothold in enterprise networks. With exploitation continuing against unpatched systems, the incident's status was recorded as ongoing.
Timeline
Cisco's product security team discloses CVE-2026-76461 after observing exploitation in the wild, and CISA adds the flaw to its Known Exploited Vulnerabilities catalog.
CISA's remediation deadline for U.S. federal civilian agencies; Cisco also discloses a separate authentication-bypass flaw in its Identity Services Engine.
Sources
- helpnetsecurity.comhttps://www.helpnetsecurity.com/2026/09/15/cve-2026-76461-cisco-email-gateway-zero-day-exploited/
- rapid7.comhttps://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild/
- socradar.iohttps://socradar.io/blog/cve-2026-76461-cisco-email-gateway-flaw/