Cisco Warns Customers of Actively Exploited Zero-Day Vulnerability
Cisco has warned its customers about an actively exploited zero-day vulnerability in its email gateways. The vulnerability, identified as CVE-2026-76461, allows unauthenticated attackers to execute commands with root privileges on vulnerable systems.
The company's product security incident response team became aware of the active exploitation in September and has since taken steps to mitigate the issue. However, Cisco declined to disclose how many organizations are impacted by the vulnerability so far.
Rapid7's Douglas McKee noted that the combination of factors makes this a particularly concerning vulnerability: 'No authentication is required, an attacker can reach the vulnerable code by sending an email through the appliance, successful exploitation can result in root-level command execution, and Cisco has observed exploitation in the wild.'