TTO-2026-0915-128 · September 15, 2026 Zero-DayActive ExploitationCritical

Cisco Secure Email Gateway CVE-2026-76461 CVSS 9.8 Zero-Day Exploited in Attacks — CISA Deadline September 17

cisco.comCVE-2026-76461 CVSS 9.8Unauthenticated root RCE via emailSQL injection via email parsingCISA KEV Sep 17 deadline400+ exposed appliancesNo workarounds available

Summary

Cisco has disclosed and patched CVE-2026-76461, a critical zero-day vulnerability in Cisco Secure Email Gateway that allows unauthenticated remote attackers to execute arbitrary commands with root privileges on the underlying operating system. The vulnerability is being actively exploited in attacks. The flaw stems from insufficient validation in the AsyncOS email parsing logic: an attacker sends a crafted email containing malicious SQL statements to an affected device, which executes those statements and achieves root command execution. CISA added CVE-2026-76461 to its Known Exploited Vulnerabilities catalog on September 15 and set a federal agency remediation deadline of September 17, 2026 — a two-day window. Shadowserver is tracking more than 400 internet-exposed Cisco Secure Email Gateway appliances. No workarounds are available; patching is the only remediation.

Timeline

DateEvent
Sep 15, 2026Cisco discloses CVE-2026-76461; releases patches for Secure Email Gateway; confirms active exploitation in September 2026
Sep 15, 2026CISA adds CVE-2026-76461 to KEV catalog; sets federal agency remediation deadline of September 17
Sep 15, 2026Shadowserver tracks 400+ internet-exposed Secure Email Gateway appliances; no workarounds available
Sep 15, 2026Cisco also patches four additional critical vulnerabilities: CVE-2026-76440, CVE-2026-76441, CVE-2026-20353, CVE-2026-76443 affecting SEG and SEWM appliances

What Happened

CVE-2026-76461 exists in the email parsing component of Cisco AsyncOS Software. The parsing logic fails to properly validate email message content before processing it, allowing an attacker to embed malicious SQL statements inside a specially crafted email. When the email is processed by an affected gateway, those SQL statements execute against the underlying system and achieve arbitrary command execution with root privileges.

The attack requires no authentication, no existing access, and no user interaction beyond sending an email to a domain whose mail flows through an affected gateway. Both physical and virtual appliances in any configuration are affected. Cisco warned that because threat actors can obtain root privileges on the device, they may be able to remove or hide indicators of compromise to cover their tracks — making forensic investigation of potentially exposed systems unreliable without prior log archiving.

Cisco advises defenders to inspect mail_logs on each cluster device for suspicious SQL statements and review network and firewall logs for unusual uploads or downloads from gateway appliances. The company has not attributed active exploitation to a specific threat actor. This is the second Cisco Secure Email Gateway vulnerability added to the CISA KEV catalog in 2026.

Domain Intelligence

cisco.com — 61.91

Score unchanged from TTO-2026-0910-112. cisco.com scores in the low-trust range at 61.91. Cisco is the vendor of the affected Secure Email Gateway product and the party that patched CVE-2026-76461 and published remediation guidance.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 15, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026