Cisco Secure Email Gateway zero-day confirmed: Experts advise immediate patching

Cisco has confirmed a vulnerability that could allow an unauthenticated, remote attacker to run arbitrary commands with root privileges on the operating system.

If that doesn’t make your security defender skin crawl, then I don’t know what does. Oh, hang on, yes I do! How about the fact that it’s a zero-day that is already being exploited in the wild?

Let’s dig into what the vulnerability is and why it matters.

The Cisco email parsing vulnerability

The vulnerability is in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway, now designated CVE-2026-76461. That may not sound dramatic, but trust me, it is.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added the critical Cisco vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on solid evidence of active exploitation. 

Want more? This is only the second Secure Email Gateway flaw ever added to CISA’s KEV catalog.

CVE-2026-76461 is a SQL injection vulnerability, “due to insufficient validation in the email parsing logic,” a Cisco security advisory stated.

To exploit this, all an attacker needs to do is send a maliciously crafted email message that has the necessary SQL statements through an affected device. Yes, you read that right.

“This type of vulnerability is a frequent attack vector for malicious cyber actors,” CISA warned in its KEV addition bulletin, adding that it therefore poses significant risks.

Cisco, meanwhile, has also warned that potential attackers, given that level of access, would be able to  erase their own indicators of compromise. Yikes.

Industry reaction

“Email gateways have to read untrusted content from anyone on the internet by design, then make trust decisions about it” said Gunter Ollmann, CTO of Cobalt.

That attackers exploiting this particular zero-day  can wipe their own indicators of compromise once they have root, Ollmann added, should worry defenders more than the exploit itself.

“If your detection strategy leans on matching known IoCs after the fact,” Ollmann explained, “you may have already missed the intrusion.”

Josh Picolet, VP of Detection & Analysis with Team Cymru told me that “the evidence that survives is not on the box, it is in the infrastructure the attacker stages from and communicates through, which is why external visibility into that activity matters more here than the artifacts left behind”.

This is why Picolet urges security teams that they should treat the September 17 deadline as a floor. And not just those at US Federal agencies affected by the CISA Binding Operational Directive (BOD) 26-04, giving them only 72 hours from disclosure to fix the issue.

“Patch, then watch for the staging and command activity the appliance’s own logs will never record.”

More from Davey

About The Author

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.