Summary
Cisco has disclosed and patched CVE-2026-76461, a critical zero-day vulnerability in Cisco Secure Email Gateway that allows unauthenticated remote attackers to execute arbitrary commands with root privileges on the underlying operating system. The vulnerability is being actively exploited in attacks. The flaw stems from insufficient validation in the AsyncOS email parsing logic: an attacker sends a crafted email containing malicious SQL statements to an affected device, which executes those statements and achieves root command execution. CISA added CVE-2026-76461 to its Known Exploited Vulnerabilities catalog on September 15 and set a federal agency remediation deadline of September 17, 2026 — a two-day window. Shadowserver is tracking more than 400 internet-exposed Cisco Secure Email Gateway appliances. No workarounds are available; patching is the only remediation.
Timeline
| Date | Event |
|---|---|
| Sep 15, 2026 | Cisco discloses CVE-2026-76461; releases patches for Secure Email Gateway; confirms active exploitation in September 2026 |
| Sep 15, 2026 | CISA adds CVE-2026-76461 to KEV catalog; sets federal agency remediation deadline of September 17 |
| Sep 15, 2026 | Shadowserver tracks 400+ internet-exposed Secure Email Gateway appliances; no workarounds available |
| Sep 15, 2026 | Cisco also patches four additional critical vulnerabilities: CVE-2026-76440, CVE-2026-76441, CVE-2026-20353, CVE-2026-76443 affecting SEG and SEWM appliances |
What Happened
CVE-2026-76461 exists in the email parsing component of Cisco AsyncOS Software. The parsing logic fails to properly validate email message content before processing it, allowing an attacker to embed malicious SQL statements inside a specially crafted email. When the email is processed by an affected gateway, those SQL statements execute against the underlying system and achieve arbitrary command execution with root privileges.
The attack requires no authentication, no existing access, and no user interaction beyond sending an email to a domain whose mail flows through an affected gateway. Both physical and virtual appliances in any configuration are affected. Cisco warned that because threat actors can obtain root privileges on the device, they may be able to remove or hide indicators of compromise to cover their tracks — making forensic investigation of potentially exposed systems unreliable without prior log archiving.
Cisco advises defenders to inspect mail_logs on each cluster device for suspicious SQL statements and review network and firewall logs for unusual uploads or downloads from gateway appliances. The company has not attributed active exploitation to a specific threat actor. This is the second Cisco Secure Email Gateway vulnerability added to the CISA KEV catalog in 2026.
Domain Intelligence
cisco.com — 61.91
Score unchanged from TTO-2026-0910-112. cisco.com scores in the low-trust range at 61.91. Cisco is the vendor of the affected Secure Email Gateway product and the party that patched CVE-2026-76461 and published remediation guidance.
The Trust Observatory · thetrustobservatory.com · September 15, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026