Cisco Patches Critical Secure Email Gateway Zero-Day Exploited in Attacks
Share
Cisco has released an emergency patch for a critical zero-day vulnerability in its Secure Email Gateway that is currently being exploited by threat actors. The flaw, tracked as CVE-2026-76461, allows unauthenticated, remote attackers to execute arbitrary commands with root privileges on the underlying operating system.
The vulnerability was discovered within the email parsing logic of Cisco AsyncOS Software. According to Cisco, attackers can exploit this weakness by sending specially crafted email messages containing malicious SQL statements to an affected device. Successful exploitation grants the attacker full control over the affected appliance, regardless of whether it is a virtual or physical implementation.
CISA Mandates Urgent Patching
The Cybersecurity and Infrastructure Security Agency (CISA) has added the flaw to its Known Exploited Vulnerabilities (KEV) catalogue. In response, CISA has ordered US federal agencies to remediate the vulnerability by 17 September 2026.
Internet security watchdog Shadowserver is currently tracking over 400 Cisco Secure Email Gateway appliances, although it remains unclear how many of these devices are targets or have already been successfully compromised.
Detection and Mitigation Guidance
To identify potential exploitation, Cisco has provided indicators of compromise (IoCs) and advised network defenders to monitor mail_logs on each cluster device for suspicious SQL statements. Security teams are also encouraged to cross-check network and firewall logs for signs of unauthorised activity, such as unusual uploads or downloads to and from external or malicious IP addresses, as attackers may attempt to remove evidence of exploitation from the local logs.
In addition to the zero-day flaw, Cisco addressed four other critical vulnerabilities affecting Secure Email Gateway and Secure Email and Web Manager (SEWM) appliances. These include CVE-2026-76440, CVE-2026-76441, CVE-2026-20353, and CVE-2026-76443. While these flaws are also considered critical, Cisco stated there is currently no evidence that they have been exploited in the wild.




Leave a Reply