Cisco Secure Email Gateway Hit by Critical Zero-Day Flaw Exploitation
Cisco's Secure Email Gateway has been exploited by attackers using a critical zero-day flaw. The bug, tracked as CVE-2026-76461, lets remote attackers gain root privileges without any authentication.
The vulnerability is nearly as bad as it gets, with a CVSS score of 9.8 out of 10. Cisco detected malicious activity and has secured its cloud infrastructure.
Cisco strongly recommends that administrators install the emergency software update for both virtual and physical Secure Email Gateway appliances. They also urge restricting access, implementing robust access control, and reviewing logs to detect indicators of possible compromise.