Cisco warned customers on Monday that a zero-day vulnerability affecting Secure Email Gateway appliances has been exploited in the wild.
The vulnerability is identified as CVE-2026-76461 and has a CVSS score of 9.8. Cisco describes it as an email parsing issue in AsyncOS software that can be exploited remotely and without authentication to execute arbitrary commands on the underlying operating system with root privileges.
The tech giant explained that the critical flaw can be exploited to execute malicious SQL statements by sending them to the targeted user inside a specially crafted email.
Cisco said its PSIRT became aware of the exploitation of CVE-2026-76461 in September 2026, but it has not shared details on attacks involving the zero-day. It’s also unclear who is behind the attacks.
The company has released indicators of compromise (IoCs), but noted that because threat actors can obtain root privileges on a device, they can remove or hide IoCs to cover their tracks.
The security hole affects both the physical and virtual versions of Secure Email Gateway in any configuration. Secure Email and Web Manager and Secure Web Appliance are not impacted.
The cybersecurity agency CISA added CVE-2026-76461 to its KEV catalog on Monday and instructed federal organizations to address it by September 17.
This is only the second Cisco Secure Email Gateway vulnerability in the KEV list, after CVE-2025-20393, which China-linked threat actors started exploiting in late 2025.
CVE-2026-76461 is one of several vulnerabilities Cisco discovered internally in its Secure Email Gateway and Secure Email and Web Manager products.
News of CVE-2026-76461’s exploitation comes just days after Cisco and CISA warned organizations about attacks leveraging CVE-2026-20079, a Secure Firewall Management Center (FMC) vulnerability disclosed earlier this year.
Cisco warned that CVE-2026-20079 and another FMC weakness tracked as CVE-2026-20316 have been exploited by both Russian state-sponsored hackers and profit-driven cybercriminals.
Related: Three JFrog Artifactory Flaws Exploited for Backdoor Deployment
Related: BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
Related: ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks
Related: Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution


