Cisco Secure Email Gateway Appliances Hit by Zero-Day Exploit
Cisco has warned its customers that a zero-day vulnerability in its Secure Email Gateway appliances is being actively exploited by attackers. The flaw, identified as CVE-2026-76461, allows remote and unauthenticated execution of arbitrary commands on the underlying operating system with root privileges.
The company's PSIRT team became aware of the exploitation in September 2026, but has not disclosed any details about the attacks or who is behind them. The vulnerability affects both physical and virtual versions of Secure Email Gateway, regardless of configuration.
Cisco has released indicators of compromise (IoCs) to help customers detect potential threats, but notes that attackers can remove or hide IoCs due to their ability to obtain root privileges on the device. The company is urging customers to address the issue as soon as possible.