Cisco Secure Email Gateway zero-day exploited for root access
Cisco has warned that a critical vulnerability in AsyncOS Software for Secure Email Gateway, tracked as CVE-2026-76461, is under active exploitation. The flaw allows unauthenticated remote code execution with root privileges, and no workaround exists. The US cybersecurity agency CISA has added it to its Known Exploited Vulnerabilities catalog.
Bottom line — CVE-2026-76461 scores a maximum CVSSv3.1 base of 10.0, with no workaround available.
Go deeper (6)
- Cisco said its PSIRT became aware of the exploitation in September 2026, but has not shared details on attacks involving the zero-day, per SecurityWeek.
- The vulnerability is classified under CWE-20 (Improper Input Validation) and scores a maximum CVSSv3.1 base of 10.0, highlighting its network accessibility and low complexity, per isecurify.
- Cisco has directly contacted customers who own Secure Email Cloud devices on which malicious activity was detected, the company said.
- CISA added CVE-2026-76461 to its Known Exploited Vulnerabilities catalog, per The Hacker News.
- Cisco published a broader Secure Email Gateway and Secure Email and Web Manager hardening release at the same time, and some vulnerability feeds group the product names together, per WindowsForum.
- Organisations should treat any internet-facing Secure Email Gateway appliance as potentially compromised until logs and other indicators are checked, per SecurityWeek.