Cisco Warns of Critical Zero-Day Vulnerability in Secure Email Gateway
Cisco has issued a security advisory warning customers about a critical zero-day vulnerability in its Secure Email Gateway software. The flaw, tracked as CVE-2026-76461, allows unauthenticated attackers to execute arbitrary commands with root privileges on the underlying operating system.
The vulnerability affects virtual and physical appliances running Cisco AsyncOS Software, regardless of device configuration. Successful exploitation can allow attackers to execute SQL statements, leading to command execution with root privileges.
Cisco has shared indicators of compromise and advised network defenders to look for suspicious SQL statements in each cluster device's mail_logs. The company also suggests cross-checking network and firewall logs for signs of suspicious activity, as attackers may remove evidence of exploitation.