Cisco has patched a critical zero-day vulnerability in Secure Email Gateway after confirming that attackers are actively exploiting the flaw to run commands with root privileges on affected systems.
The vulnerability, tracked as CVE-2026-76461, has a CVSS score of 9.8 and affects Cisco AsyncOS software used by Secure Email Gateway appliances. An attacker does not need to log in before attempting exploitation.
Cisco says the weakness exists in the way the product parses email and validates input.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
A malicious email can reach the system before anyone opens it
The flaw can be triggered when an attacker sends a specially crafted email containing malicious SQL statements through an affected device.
Because the Secure Email Gateway automatically processes incoming email, the attack does not depend on an employee opening an attachment or clicking a link.
Cisco says insufficient validation in the email parsing logic can allow the attacker to execute arbitrary SQL statements, which can then lead to command execution on the underlying operating system with root privileges.
That makes the vulnerability particularly dangerous.
A normal phishing attack usually requires some action from the recipient.
Here, the security appliance itself may process the malicious content as part of its normal job.
What does ‘root access’ actually mean?
Root is the highest level of administrative privilege on many Unix and Linux-based systems.
An attacker operating as root can potentially read or modify files, install malicious software, alter system settings and interfere with security controls.
In the context of an email security gateway, that level of access is especially sensitive because the appliance sits directly in the path of corporate email traffic.
A compromised gateway could potentially become a useful position for spying, stealing information or maintaining access to an organisation.
Cisco has not publicly detailed what attackers have done after exploiting CVE-2026-76461.
It has also not identified the threat actors behind the attacks or disclosed the number of organisations affected.
Cisco says the zero-day is already being exploited
Cisco’s Product Security Incident Response Team became aware of active exploitation in September 2026, according to the company’s advisory.
That means this is not simply a theoretical vulnerability discovered during testing.
Attackers were already using it before or around the time a patch became available, which is what makes it a zero-day.
The vulnerability was publicly disclosed on September 14.
Cisco simultaneously released fixed software and strongly recommended that affected customers upgrade.
There is no configuration workaround that fully addresses the flaw.
Secure Email products received a wider security hardening update
The zero-day was disclosed alongside a broader September security hardening release for Cisco Secure Email Gateway and Secure Email and Web Manager.
That release addressed several additional vulnerabilities, including flaws involving input validation, access controls, resource handling and injection-related weaknesses.
Cisco assigned one of those vulnerability classes, CVE-2026-76443, the same critical 9.8 score.
However, Cisco specifically identifies CVE-2026-76461 as the Secure Email Gateway SQL injection vulnerability being actively exploited in the wild.
The company has said there are no workarounds for the wider hardening issues either and recommends moving to fixed releases.
Why email gateways are high-value targets
Secure email gateways operate at an unusually sensitive point in corporate infrastructure.
They analyse incoming and outgoing messages, filter spam, inspect attachments and apply security rules before email reaches users.
That means they are intentionally exposed to large amounts of untrusted internet traffic.
If attackers compromise the gateway itself, they may gain access to infrastructure that security teams generally consider part of the defensive perimeter.
This is similar to the growing attacker focus on VPNs, firewalls and remote-access appliances.
Rather than breaking through several layers of protection, attackers try to compromise the device responsible for enforcing those layers.
Organisations should treat patching as urgent
Cisco has advised customers to upgrade to the fixed software versions listed in its advisory.
Because there is no workaround and exploitation has already been observed, delaying the upgrade leaves affected appliances exposed.
Security teams should also review logs and indicators around Secure Email Gateway systems for signs of unusual behaviour, especially unexpected administrative activity or command execution.
Organisations operating internet-facing security appliances should assume that once a critical vulnerability is public, scanning and exploitation attempts may increase quickly.
The fact that attackers were already exploiting this flaw before widespread disclosure raises the risk further.
What this means for you: This issue mainly affects organisations running Cisco Secure Email Gateway, not ordinary email users. IT and security teams should patch affected appliances immediately and investigate for signs of prior compromise rather than waiting for exploitation attempts to appear.
The420 Insight: The most troubling part of this zero-day is where it sits. A security gateway is supposed to inspect hostile email before it reaches employees, but here the email itself can attack the security system doing the inspection. That turns the defensive layer into the first point of compromise.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics