Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Nottingham city centre balaclava ban comes into force

    September 15, 2026

    Thank goodness Labour’s ‘shambolic’ plan to reorganise local councils has been paused. What was it thinking? | Polly Toynbee

    September 15, 2026

    Volkswagen’s crazy-efficient EV borrows an idea from Slate

    September 15, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Nottingham city centre balaclava ban comes into force
    • Thank goodness Labour’s ‘shambolic’ plan to reorganise local councils has been paused. What was it thinking? | Polly Toynbee
    • Volkswagen’s crazy-efficient EV borrows an idea from Slate
    • The AI Talent Britain Fought to Hire May Be Recalculating Its Future
    • Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation
    • Bitcoin Climbs as AI Slowdown Calls Sink Nvidia, Intel and Other Chip Stocks
    • A coral reef thought dead for 60 years is teeming with life
    • U.S. Diplomacy Toward Russia Is Too Episodic
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 15
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 15, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cisco warned customers on Monday that a zero-day vulnerability affecting Secure Email Gateway appliances has been exploited in the wild.

    The vulnerability is identified as CVE-2026-76461 and has a CVSS score of 9.8. Cisco describes it as an email parsing issue in AsyncOS software that can be exploited remotely and without authentication to execute arbitrary commands on the underlying operating system with root privileges.

    The tech giant explained that the critical flaw can be exploited to execute malicious SQL statements by sending them to the targeted user inside a specially crafted email. 

    Cisco said its PSIRT became aware of the exploitation of CVE-2026-76461 in September 2026, but it has not shared details on attacks involving the zero-day. It’s also unclear who is behind the attacks.

    The company has released indicators of compromise (IoCs), but noted that because threat actors can obtain root privileges on a device, they can remove or hide IoCs to cover their tracks.

    The security hole affects both the physical and virtual versions of Secure Email Gateway in any configuration. Secure Email and Web Manager and Secure Web Appliance are not impacted.

    Advertisement. Scroll to continue reading.

    The cybersecurity agency CISA added CVE-2026-76461 to its KEV catalog on Monday and instructed federal organizations to address it by September 17.

    This is only the second Cisco Secure Email Gateway vulnerability in the KEV list, after CVE-2025-20393, which China-linked threat actors started exploiting in late 2025.  

    CVE-2026-76461 is one of several vulnerabilities Cisco discovered internally in its Secure Email Gateway and Secure Email and Web Manager products.

    News of CVE-2026-76461’s exploitation comes just days after Cisco and CISA warned organizations about attacks leveraging CVE-2026-20079, a Secure Firewall Management Center (FMC) vulnerability disclosed earlier this year.

    Cisco warned that CVE-2026-20079 and another FMC weakness tracked as CVE-2026-20316 have been exploited by both Russian state-sponsored hackers and profit-driven cybercriminals.

    Related: Three JFrog Artifactory Flaws Exploited for Backdoor Deployment

    Related: BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

    Related: ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks

    Related: Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

    active Cisco email exploitation gateway RCE Root secure ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

    Twitch extension with 30K installs exposes users’ OAuth tokens

    Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports

    Three JFrog Artifactory Flaws Exploited for Backdoor Deployment

    Telus Warns Customers of Account Breaches

    The Race to Control AI and Protect What Makes Us Human

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Nottingham city centre balaclava ban comes into force

    September 15, 2026

    Thank goodness Labour’s ‘shambolic’ plan to reorganise local councils has been paused. What was it thinking? | Polly Toynbee

    September 15, 2026

    Volkswagen’s crazy-efficient EV borrows an idea from Slate

    September 15, 2026

    The AI Talent Britain Fought to Hire May Be Recalculating Its Future

    September 15, 2026
    Latest Posts

    What Is an Air-Gapped Bitcoin Wallet? Why the Coldcard Exploit Changes the Conversation About Offline Security

    August 3, 2026

    18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

    August 3, 2026

    T-Mobile will give you the new Samsung Galaxy Z Flip for practically nothing if you preorder now

    August 3, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Nottingham city centre balaclava ban comes into force

    September 15, 2026

    Thank goodness Labour’s ‘shambolic’ plan to reorganise local councils has been paused. What was it thinking? | Polly Toynbee

    September 15, 2026

    Volkswagen’s crazy-efficient EV borrows an idea from Slate

    September 15, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.