Cisco Warns of Actively Exploited Root Zero-Day in Secure Email Gateway

Cisco warns that attackers are actively exploiting a critical zero-day vulnerability in its Secure Email Gateway products. The flaw, tracked as CVE-2026-76461, resides in the email parsing logic of Cisco AsyncOS Software and affects both virtual and physical appliances regardless of configuration. Successful exploitation allows unauthenticated, remote attackers to execute arbitrary commands with root privileges on the underlying operating system.

The vulnerability stems from insufficient validation in the email parsing logic. An attacker can exploit it by sending a crafted email containing malicious SQL statements through an affected device, enabling arbitrary SQL execution that escalates to root-level command execution. Cisco shares indicators of compromise and advises defenders to check mail_logs for suspicious SQL statements, while also cross-checking network and firewall logs for unusual traffic, since attackers may wipe evidence of their activity.

The Cybersecurity and Infrastructure Security Agency adds the flaw to its Known Exploited Vulnerabilities Catalog and orders federal agencies to patch by September 17. Cisco also patches four additional critical vulnerabilities affecting Secure Email Gateway and Secure Web Manager appliances, though it has no evidence those are being exploited. Shadowserver currently tracks more than 400 internet-exposed Cisco Secure Email Gateway appliances.

Read More at the original source →