Cisco warned customers to patch a critical Secure Email Gateway zero-day that threat actors have been exploiting in attacks. The vulnerability, tracked as CVE-2026-76461, was found in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway. It affects virtual and physical appliances, regardless of the device configuration. Successful exploitation can allow unauthenticated, remote attackers to execute arbitrary commands with root privileges on the underlying operating system.

The flaw stems from insufficient validation in the email parsing logic. An attacker could exploit it by sending a crafted email message containing malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges. Because the attack arrives as email, any organization running an exposed or unpatched Secure Email Gateway is potentially in scope. Shadowserver currently tracks over 400 Cisco Secure Email Gateway appliances, though it provides no information on how many are honeypots or have already been secured.

The protective step is to patch. Cisco shared indicators of compromise and advised network defenders to look for suspicious SQL statements in each cluster device's mail_logs. Admins should also cross-check network and firewall logs for signs of suspicious activity, including uploads and downloads to and from external or malicious IP addresses, because attackers may remove evidence of exploitation. The Cybersecurity and Infrastructure Security Agency added CVE-2026-76461 to its Known Exploited Vulnerabilities Catalog and ordered federal agencies to patch within three days, by September 17. That deadline is specific to federal agencies; other operators should treat the active exploitation as the reason to prioritize patching.

Cisco also addressed four other critical vulnerabilities affecting Secure Email Gateway and Secure Email and Web Manager appliances regardless of configuration, but said it had no evidence they have been exploited in the wild. In January, Cisco patched a maximum-severity AsyncOS flaw exploited in zero-day attacks against SEG and SEWM devices since November 2025. Since November 2021, CISA has flagged 98 Cisco vulnerabilities as actively exploited in attacks, including seven abused by ransomware gangs.