Skip to content
Zero-dayOngoing

Cisco patches actively exploited zero-day in Secure Email Gateway allowing root access via a crafted email

Cisco confirmed active exploitation of CVE-2026-76461, a pre-authentication SQL injection in Secure Email Gateway that lets a crafted email execute commands as root, prompting a CISA remediation order.

Victim
Cisco Secure Email Gateway
CVECVE-2026-76461

On 15 September 2026, Cisco confirmed that attackers were actively exploiting a critical zero-day vulnerability in its Secure Email Gateway appliances, tracked as CVE-2026-76461, after its product security team observed exploitation in the wild.

The flaw is a pre-authentication SQL injection in the email-parsing logic of Cisco's AsyncOS software, rated 9.8 on the CVSS scale. Because affected gateways process externally delivered mail as part of normal operation, an unauthenticated attacker can trigger it simply by sending a crafted email containing malicious SQL statements โ€” no user interaction or valid credentials required. Successful exploitation lets the attacker execute arbitrary SQL and, ultimately, run commands with root privileges on the underlying operating system. Cisco said affected releases include AsyncOS 15.5, 16.0 and 16.5, with fixes shipped in version 16.5.0-780.

Federal patch order

The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-76461 to its Known Exploited Vulnerabilities catalog and directed federal civilian agencies to remediate the flaw by 17 September, an unusually short window that reflected the severity of a pre-auth, root-level bug on an internet-facing security appliance. Two days after the email-gateway alert, Cisco disclosed a separate authentication-bypass flaw in its Identity Services Engine, compounding a difficult week for the vendor.

Assessment

No public attribution named a specific threat actor behind the email-gateway exploitation, though security researchers noted that email security appliances have become a favored target for espionage-focused groups seeking a durable foothold in enterprise networks. With exploitation continuing against unpatched systems, the incident's status was recorded as ongoing.

Timeline

  1. Cisco's product security team discloses CVE-2026-76461 after observing exploitation in the wild, and CISA adds the flaw to its Known Exploited Vulnerabilities catalog.

  2. CISA's remediation deadline for U.S. federal civilian agencies; Cisco also discloses a separate authentication-bypass flaw in its Identity Services Engine.

Sources

  1. helpnetsecurity.comhttps://www.helpnetsecurity.com/2026/09/15/cve-2026-76461-cisco-email-gateway-zero-day-exploited/
  2. rapid7.comhttps://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild/
  3. socradar.iohttps://socradar.io/blog/cve-2026-76461-cisco-email-gateway-flaw/

Related incidents

Zero-dayOngoing

SonicWall warns of two SMA 1000 zero-days exploited in the wild (CVE-2026-15409, CVE-2026-15410)

SonicWall issued an urgent advisory after attackers were caught chaining two zero-day flaws in its SMA 1000 secure remote-access appliances โ€” an unauthenticated SSRF rated CVSS 10.0 and a post-authentication command-injection bug โ€” with Rapid7 having observed the pair exploited in tandem against internet-facing devices before any patch existed.

Victim
SonicWall SMA 1000