securityaffairs.com 15 Sept 2026, 13:00 UTC

Cisco Warns Attackers Are Exploiting Critical Email Gateway Zero Day

Cisco Warns Attackers Are Exploiting Critical Email Gateway Zero Day
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Status Unknown

CISCO has warned of active exploitation of a critical zero-day in its Secure Email Gateway appliances. Tracked as CVE-2026-76461 and rated 9.8 on the CVSS scale, the vulnerability affects physical and virtual appliances running Cisco AsyncOS Software, regardless of device configuration. It can be exploited remotely without authentication by sending a specially crafted email containing malicious SQL statements.

Insufficient validation in the email-parsing logic can allow attackers to run arbitrary SQL statements and execute commands with root privileges on the underlying operating system. Cisco’s PSIRT has confirmed exploitation in the wild.

Cisco says there is currently no workaround that addresses the issue. Customers should review the `mail_logs` on every device, including each appliance in a cluster, for suspicious SQL statements. The advisory gives `grep -i "COPY.*TO PROGRAM"` as an example search; any matching entry may indicate malicious activity. Customers using Secure Email Cloud may not be able to inspect these indicators themselves, although Cisco said it contacted customers where malicious activity was detected.

On 14 September 2026, the US Cybersecurity and Infrastructure Security Agency added CVE-2026-76461 to its Known Exploited Vulnerabilities catalogue and required federal organisations to address it by 17 September.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline