Cisco Warns of Ongoing Exploitation of Critical Email Gateway Zero-Day

Cisco Warns of Ongoing Exploitation of Critical Email Gateway Zero-Day

Cisco Warns of Ongoing Exploitation of Critical Email Gateway Zero-Day

Cisco Warns of Ongoing Exploitation of Critical Email Gateway Zero-Day

Cisco Warns of Ongoing Exploitation of Critical Email Gateway Zero-Day

Pierluigi Paganini
September 15, 2026

Cisco warns of a critical zero-day in Secure Email Gateway, exploited in the wild to gain root access through malicious emails.

Cisco disclosed a critical zero-day, tracked as CVE-2026-76461 (CVSS score of 9.8), affecting Secure Email Gateway appliances. The flaw can be exploited remotely without authentication. Attackers can send specially crafted emails containing malicious SQL statements, triggering arbitrary command execution on the underlying system with root privileges. Cisco confirmed the vulnerability is already being exploited in the wild.

“A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.” reads the report published by the networking giant.

“This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.”

According to the advisory, the vulnerability affects Cisco Secure Email Gateway, both physical and virtual, regardless of device configuration. The company states that there are no workarounds that address this issue.

Recently, the company’s PSIRT became aware of active exploitation of this vulnerability.

Check Secure Email Gateway logs for suspicious SQL statements to detect possible exploitation. If the device is part of a cluster, check every device. Cisco says customers using Secure Email Cloud may not be able to check these indicators themselves, but those with detected malicious activity were contacted directly.

“To confirm any attempted exploitation of this vulnerability, review the mail_logs and look for suspicious SQL statements. If the device is part of a cluster, review the logs of each cluster device.” states the advisory. “The following is a non-exhaustive example of how a malicious SQL statement could be detected in the logs:

cisco-esa> grep -i "COPY.*TO PROGRAM" [IronPort Text Mail Logs Log name - Default: mail_logs]

The presence of any entry in the output may indicate malicious activity.”

On September 14, US CISA added CVE-2026-76461 to its Known Exploited Vulnerability to Catalog (KEV) and ordered federal organizations to address it by September 17.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Secure Email Gateway)



About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.