CISA Warns of Cisco Secure Email Gateway 0-Day Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

CISA has added a critical Cisco Secure Email Gateway vulnerability to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw in real-world attacks.

The issue, tracked as CVE-2026-76461, affects Cisco AsyncOS software used by Cisco Secure Email Gateway appliances. CVE-2026-76461 is an SQL injection vulnerability, categorized under CWE-89.

It could allow an unauthenticated remote attacker to send specially crafted requests to a vulnerable Cisco Secure Email Gateway device and execute arbitrary commands on the underlying operating system.

Successful exploitation may provide root-level privileges, giving an attacker full control of the affected appliance. Cisco Secure Email Gateway is commonly deployed at the edge of enterprise networks to inspect email traffic and block malicious messages, spam, phishing attempts, and malware.

Compromising such a system could create serious security risks because the appliance processes large volumes of inbound and outbound email, including messages containing sensitive business information.

An attacker with root access could potentially alter email security policies, access stored message data, create persistence mechanisms, turn off security logging, or use the compromised gateway as an entry point into the wider network.

Cisco Secure Email Gateway 0-Day Vulnerability Exploited

Security teams should also investigate whether the appliance has communicated with unfamiliar external infrastructure or shown unexpected administrative activity.

CISA added the vulnerability to the KEV catalog on September 14, 2026, and directed affected federal civilian executive branch agencies to apply vendor-provided mitigations by September 17, 2026.

The agency also marked the issue as requiring forensic triage under Binding Operational Directive 26-04, reflecting the elevated risk associated with confirmed exploitation.

The listing does not confirm whether the vulnerability has been used in ransomware operations. However, vulnerabilities that enable unauthenticated remote command execution with root privileges are highly valuable to threat actors, particularly when the affected product is internet-facing.

Organizations using Cisco Secure Email Gateway should identify all exposed AsyncOS instances, confirm their software versions, and apply Cisco’s recommended mitigation measures as soon as possible.

Where mitigations are unavailable, CISA advises organizations to follow applicable BOD 26-04 guidance for cloud services or discontinue use of the affected product. Security teams should prioritize incident-response checks alongside remediation.

Relevant triage actions include reviewing appliance logs for suspicious requests, checking for unauthorized configuration changes, examining privileged account activity, and looking for unexpected command execution or outbound network connections.

Because the flaw can be exploited remotely without authentication, organizations should treat any unpatched internet-accessible device as potentially compromised.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post CISA Warns of Cisco Secure Email Gateway 0-Day Vulnerability Actively Exploited in Attacks appeared first on Cyber Security News.