BriefPulse Security · Security reporting tied to advisories, affected versions and action. RSS · BriefPulse network
BriefPulse Security

Exposures, incidents and defensive changes for people who have to act.

16 September 2026

Report

Cisco patches actively exploited Secure Email Gateway zero-day (CVE-2026-76461)

Cisco has patched a critical zero-day in Secure Email Gateway that attackers have been exploiting to execute commands with root privileges. The flaw affects virtual and physical appliances regardless of configuration, and federal agencies have been given a three-day patch deadline.

Cisco warned customers to patch a critical Secure Email Gateway zero-day that threat actors have been exploiting in attacks. The vulnerability, tracked as CVE-2026-76461, was found in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway. It affects virtual and physical appliances, regardless of the device configuration. Successful exploitation can allow unauthenticated, remote attackers to execute arbitrary commands with root privileges on the underlying operating system.

The flaw stems from insufficient validation in the email parsing logic. An attacker could exploit it by sending a crafted email message containing malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges. Because the attack arrives as email, any organization running an exposed or unpatched Secure Email Gateway is potentially in scope. Shadowserver currently tracks over 400 Cisco Secure Email Gateway appliances, though it provides no information on how many are honeypots or have already been secured.

The protective step is to patch. Cisco shared indicators of compromise and advised network defenders to look for suspicious SQL statements in each cluster device's mail_logs. Admins should also cross-check network and firewall logs for signs of suspicious activity, including uploads and downloads to and from external or malicious IP addresses, because attackers may remove evidence of exploitation. The Cybersecurity and Infrastructure Security Agency added CVE-2026-76461 to its Known Exploited Vulnerabilities Catalog and ordered federal agencies to patch within three days, by September 17. That deadline is specific to federal agencies; other operators should treat the active exploitation as the reason to prioritize patching.

Cisco also addressed four other critical vulnerabilities affecting Secure Email Gateway and Secure Email and Web Manager appliances regardless of configuration, but said it had no evidence they have been exploited in the wild. In January, Cisco patched a maximum-severity AsyncOS flaw exploited in zero-day attacks against SEG and SEWM devices since November 2025. Since November 2021, CISA has flagged 98 Cisco vulnerabilities as actively exploited in attacks, including seven abused by ransomware gangs.

Our reading

Our reading is that small teams running Cisco Secure Email Gateway should treat this as a priority patch, not because of the federal deadline but because the flaw is already being exploited and the protective steps are straightforward.

Source details and supporting facts

Each line is stated by the page named above it.

Stated by BleepingComputer

  • Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks.
  • The security flaw (tracked as CVE-2026-76461) was found in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway and affects virtual and physical appliances, regardless of the device configuration.
  • Successful exploitation can allow unauthenticated, remote attackers to execute arbitrary commands with root privileges on the underlying operating system.
  • Cisco shared indicators of compromise and advised network defenders to look for suspicious SQL statements in each cluster device's mail_logs.
  • The Cybersecurity and Infrastructure Security Agency (CISA) also added the CVE-2026-76461 flaw to its Known Exploited Vulnerabilities (KEV) Catalog on Monday, ordering federal agencies to patch their systems within three days, by September 17.
  • Shadowserver currently tracks over 400 Cisco Secure Email Gateway appliances, but it provides no information on how many are honeypots or have already been secured against attacks.

Sources

  1. BleepingComputerText stored 15 September 2026

How this story was checked. Written from the 1 page listed above, stored 15 September 2026; claims checked against that stored text on 15 September 2026.

What that means
  • 6 of 6 reported statements were confirmed against the page that carries them; the rest were removed rather than published.
  • Figures in the text were required to appear in the stored source text: yes. Identifiers: yes.
  • The check reads stored text only: no claim rests on a fresh look that did not happen.
  • Where the reporting was silent, the text says so instead of filling the gap.

More from Security