Cisco Secure Email Gateway Hit by Critical Zero-Day Exploit
Cisco Secure Email Gateway has been found vulnerable to a critical zero-day exploit, CVE-2026-76461. This vulnerability allows an attacker to execute root commands without authentication and can be triggered through a specially crafted email message.
The issue was first reported in September, with Cisco releasing the initial security update on the 14th and updating it three days later. The company notes that there is no workaround available, making immediate action necessary for affected organizations.
The vulnerability, a SQL injection flaw in the AsyncOS message parsing logic, has a CVSS score of 9.8 and is rated critical. An attacker can send a malicious email to a vulnerable device, embedding SQL commands that allow execution of arbitrary queries and ultimately root-level commands on the underlying operating system.
Cisco emphasizes that both physical and virtual devices are affected, regardless of configuration, and that the attack does not require access to the management interface or a valid account. Active exploitation has been detected on Secure Email Cloud devices, with Cisco contacting customers directly when signs of potential breaches were found.