CISCO has warned that attackers are exploiting a zero-day vulnerability in its Secure Email Gateway appliances. Tracked as CVE-2026-76461 and rated 9.8 on the CVSS scale, the flaw is an email-parsing issue in AsyncOS software. It can reportedly be exploited remotely without authentication by sending a specially crafted email containing malicious SQL statements to a targeted user, allowing arbitrary commands to be executed on the underlying operating system with root privileges.
Cisco said its Product Security Incident Response Team became aware of exploitation in September 2026, but it has not disclosed details about the attacks or identified those responsible. The vulnerability affects both physical and virtual Secure Email Gateway appliances in any configuration. Secure Email and Web Manager and Secure Web Appliance products are not affected. Cisco has published indicators of compromise, while warning that attackers with root access could remove or conceal them.
Organisations using affected appliances should apply Cisco’s available remediation and investigate for compromise. CISA added CVE-2026-76461 to its Known Exploited Vulnerabilities catalogue and directed US federal agencies to address it by 17 September.