Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Cisco patches Secure Email Gateway zero-day exploited in attacks

Cisco has patched a critical zero-day vulnerability in its Secure Email Gateway after confirming active exploitation in September 2026. The flaw, tracked as CVE-2026-76461, affects virtual and physical appliances running Cisco AsyncOS Software for Cisco Secure Email Gateway, regardless of configuration.

Unauthenticated remote attackers can exploit insufficient validation in the email-parsing logic by sending a crafted message containing malicious SQL statements. Successful exploitation can allow arbitrary SQL statements and command execution with root privileges on the underlying operating system.

Cisco shared indicators of compromise and told defenders to look for suspicious SQL statements in each cluster device’s mail_logs. It also said network and firewall logs should be checked for suspicious uploads and downloads involving external or malicious IP addresses, since attackers may remove evidence.

Shadowserver tracks over 400 Cisco Secure Email Gateway appliances, although it does not say how many are honeypots or have been secured. CISA added CVE-2026-76461 to its Known Exploited Vulnerabilities Catalog and ordered federal agencies to patch within 3 days, by September 17. Cisco also patched 4 other critical vulnerabilities affecting Secure Email Gateway and Secure Email and Web Manager appliances, but reported no evidence that they had been exploited.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.